Europe’s financial supervisors have introduced a new set of operational instructions for reporting major information and communication technology incidents under the Digital Operational Resilience Act, known as DORA.

London’s trading industry is coming home!

Published on 16 September 2026, the five-page document is short, but important. It addresses 14 practical issues identified in the reporting process, from the treatment of monetary values and incident identifiers to third-party provider details, service downtime and economic impact. Its stated purpose is to improve data quality and make reporting more consistent across EU jurisdictions.

Why DORA Was So Important

DORA became applicable on 17 January 2025, creating a common EU framework for ICT risk management, incident reporting, resilience testing and third-party technology risk. It covers more than 20 categories of financial entity, including investment firms, trading venues, payment and electronic money institutions, crypto-asset service providers, banks, insurers and fund managers.

DORA was important because it made digital resilience a direct regulatory responsibility. Technology failures were no longer treated mainly as internal IT or cybersecurity matters. They became financial stability, business continuity and conduct issues requiring board-level oversight and a documented regulatory response.

What the New Instructions Change, and What They Do Not

The September instructions do not alter the legal perimeter of DORA. They do not expand the list of regulated companies, change the meaning of a major incident or impose new sanctions. They also leave the formal reporting route unchanged: firms continue to submit reports through the channels and formats established by their national competent authority.

What changes is the degree of operational clarity. The document identifies specific practices that have made reports difficult to compare, process or analyse. It therefore narrows the room for interpretation when firms complete the existing templates.

This marks a new stage in the operation of the established reporting framework. Supervisory attention is moving from the introduction of policies and templates to the quality of the information submitted. A report may arrive on time and still create problems if identifiers change between filings, monetary figures use different units, a field contains unnecessary text or the same third-party provider is described differently by several firms.

Find the full analysis, including a detailed breakdown of the reporting instructions, in our latest report from Finance Magnates Intelligence.

This article was written by Sylwester Majewski at www.financemagnates.com.RegulationRead More

You might also be interested in reading Bitget confirms $351M security breach, suspends withdrawals.