DORA

  • UK Critical Third Parties Regime: 13 July 2026 Go-Live

    On 13 July 2026 the Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority begin overseeing the first firms brought inside the UK Critical Third Parties regime. HM Treasury announced the designations three days earlier, on 10 July 2026, but the designations themselves take legal effect only from 13 July 2026, the…

  • SS2/21 Outsourcing: The PRA Register and Notification Guide

    SS2/21 is the PRA’s supervisory statement on outsourcing and third-party risk management. Its main scope covers UK banks, building societies and PRA-designated investment firms; insurance and reinsurance firms and groups in scope of Solvency II, including Lloyd’s and managing agents; and UK branches of overseas banks and insurers. It has been the working reference for…

  • CASP Digital Operational Resilience: ESMA’s Custody CSA

    On 8 July 2026 the European Securities and Markets Authority launched a Common Supervisory Action on crypto-asset service providers, aimed squarely at one activity: custody. The exercise assesses the maturity of CASP digital operational resilience frameworks for custody services, and national competent authorities will run it on a risk-based sample of authorised CASPs from the…

  • ECB AI Cybersecurity Letter: The 31 October 2026 JST Action Plan

    On 7 July 2026, the Chair of the ECB Supervisory Board, Claudia Buch, wrote to the CEO of every significant institution under a letter numbered SSM-2026-0301 and titled “Addressing AI-enabled cybersecurity threats”. The ECB AI cybersecurity letter does one operationally concrete thing behind its strategic language: it gives each directly supervised bank until 31 October…

  • EBA Revised SREP Guidelines: What EU Banks Must Review in ICAAP, ILAAP and Pillar 2 Capital

    The rulebook your ICAAP package, your ILAAP submission and your Pillar 2 reconciliation were written against is being repealed. On 26 June 2026 the European Banking Authority published its revised SREP guidelines (EBA/GL/2026/06), and from 1 January 2027 they replace both the existing SREP guidelines (EBA/GL/2022/03) and the standalone guidelines on ICT risk assessment under…

  • DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals

    If your firm filed a major incident under DORA in 2025, that report has now been counted. On 3 June 2026 the three European Supervisory Authorities published their first annual report on major ICT-related incidents, putting a hard number on what used to be guesswork: how many major incidents the EU financial sector reports, where…

  • DORA Compliance Checklist for Luxembourg Fund Administrators

    DORA (Regulation (EU) 2022/2554) has been live since 17 January 2025. For Luxembourg fund administrators, UCITS management companies, and AIFMs, the question is no longer whether it applies to you. It does. The question is whether your implementation actually covers what the CSSF expects, or whether you have gaps disguised as compliance. Treating DORA as…