Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

AFM update on DORA

By Floortje Nagelkerke (NL) & Julia van der Grint on August 7, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

On 6 August 2026, the Dutch Authority for the Financial Markets (Autoriteit Financiële Markten, AFM) published an update on the Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA). This update focuses on the progress of the financial sector since the introduction of DORA.

The AFM has noticed strong improvement in the number of information registers approved by the European Banking Authority (EBA) as part of its annual exercise, during which the EBA requests all national competent authorities to collect the registers of information of DORA-regulated entities and submit them to the EBA. To provide further guidance in this area, the AFM published a Q&A on the information register (available here).

The AFM’s supervision of compliance with the DORA requirements in 2025 focused on ICT risk management. The AFM’s observations are as follows:

  • Policies and procedures: financial entities do not always have all the policies and procedures in place that are required under DORA. In addition, not all submitted policies and procedures met the requirements under DORA. The AFM recommends firms to periodically conduct a self-assessment to determine whether their existing policies and procedures comply with DORA requirements and to ensure that their policies and procedures are aligned with their current risks and the actual operating practices of the organisation.
  • Group entities: for group entities, the AFM stresses that financial entities that are part of a larger group must verify independently whether all relevant DORA requirements have been fully incorporated into their policies and procedures, as the licensed financial entity remains fully responsible for their compliance with the DORA requirements.
  • Disruptions: while most financial entities have implemented sufficient measures to detect (potential) disruptions, these entities have often not yet established adequate preventive measures to avoid such disruptions. Particularly, room for improvement exists in the areas of logical access management and patch and vulnerability management.

Separately, the AFM notices a lower number of incident reports than expected. The AFM recommends that financial entities review their incident management processes to ensure they are properly designed and implemented and to enable incidents to be detected, recorded, managed, classified, and, where required, reported within the statutory time limits.

Finally, the AFM highlights the clarification provided by the European Supervisory Authorities (ESAs) on how to determine whether insurance intermediaries fall within the scope of DORA when only a part of their business relates to insurance mediation. As follows from the ESAs guidance, in general, the figures for the undertaking as a whole should be considered. However, in accordance with the principle of proportionality, entities whose insurance mediation activities are only of limited significance should consider solely the activities and resources dedicated to those insurance-related activities.

The DORA update is available here.

Photo of Floortje Nagelkerke (NL) Floortje Nagelkerke (NL)
Read more about Floortje Nagelkerke (NL)Email
Photo of Julia van der Grint Julia van der Grint

Julia van der Grint is a financial services lawyer based in Amsterdam.

She advises clients on a wide range of regulatory and compliance aspects relevant to financial institutions, such as investment firms, trading platforms, payment institutions, insurers, fund managers and clearing and settlement…

Julia van der Grint is a financial services lawyer based in Amsterdam.

She advises clients on a wide range of regulatory and compliance aspects relevant to financial institutions, such as investment firms, trading platforms, payment institutions, insurers, fund managers and clearing and settlement institutions. Julia has developed particular knowledge of blockchain and cryptocurrencies, and advises crypto-asset services providers, crypto exchanges, payments providers and financial institutions on the regulatory issues related to the deployment of these technologies. She also advises on Dutch licence application and notification requirements and assists companies in their licence or notification processes with the Dutch Authority for Financial Markets and the Dutch Central Bank. Additionally, she assists companies in their contacts with these supervisory authorities and represents companies in enforcement procedures.

In addition, she has previously advised banks, other financial institutions and corporates in an array of transactions, both domestic and cross-border. This includes, among others, advising lenders and lender-groups in corporate restructurings and other insolvency related matters.

Prior to joining the team as an associate, Julia gained experience with the Amsterdam office as a student worker.

Read more about Julia van der GrintEmail
Show more Show less
  • Posted in:
    Administrative and Regulatory, Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    Global Regulation Tomorrow
  • Organization:
    Norton Rose Fulbright
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo