Search
Dropdown options DORA V4.0
Preparing Plain csv reporting package for DORA
EBA guidelines on preparing plain CSV reporting packages for DORA (Digital Operational Resilience Act) – outlining file structure, naming conventions, and content requirements for financial institutions' regulatory submissions under release 4.0.
Joint Report on the feasibility for further Centralisation of reporting of major ICT incidents
EBA and joint committee assess the feasibility of centralising major ICT incident reporting under DORA (Regulation (EU) 2022/2554), analysing current frameworks, stakeholder input, and potential options for streamlined EU-level reporting.
Single Programming Document 2025-2027 (final)
European Banking Authority’s 2025-2027 Single Programming Document outlines strategic priorities, resource allocation, and annual work plans focusing on finalizing the Single Rulebook, financial stability, DORA and MiCAR implementation, data infrastructure, and AML/CFT framework transition.
Terms of Reference (ToR) – EU-SCICF Forum
European Banking Authority (EBA) and ESAs outline the Terms of Reference for the EU-SCICF Forum, establishing its role in coordinating systemic cyber incident response under DORA. Covers membership, tasks, crisis preparedness, and governance for EU financial sector resilience.
EBA 2025 Work programme – final (republished to align with final SPD 2025-2027)
European Banking Authority (EBA) 2025-2027 work programme outlining key priorities, including implementing the EU banking package, enhancing financial stability, launching a data portal, supervising DORA and MiCAR, and advancing AML/CFT and consumer protection frameworks.
JC_24_93_Mandate Oversight Forum
European Supervisory Authorities establish the Oversight Forum under DORA to coordinate ICT third-party risk monitoring, draft joint positions, and promote digital operational resilience across financial sectors, including critical ICT service providers oversight and cross-sector risk mitigation.
ESAs Decision on reporting of information for CTPP designation (corrigendum)
European Supervisory Authorities (EBA, ESMA, EIOPA) correct reporting requirements for competent authorities to designate critical ICT third-party service providers under DORA (Regulation (EU) 2022/2554), aligning data points with Commission Implementing Regulation (EU) 2024/2956.
Single Programming Document 2026-2028 (initial)
European Banking Authority (EBA) outlines its 2026–2028 strategic priorities, work programme, and resource allocation—focusing on rulebook development, risk assessment, innovation, and financial stability amid digital and green transitions, while supporting new EU mandates like DORA, MICAR, and AMLA.
Article 2
ScopeEBA MB 2024 118 rev. 1 (Final Minutes MB meeting on 19 November 2024)
European Banking Authority (EBA) Management Board meeting minutes from November 2024 covering operational updates, Basel III roadmap progress, HR and budget execution, IT projects under DORA and MICAR, and a proposed 12-month pause on CRD/CRR Q&As due to regulatory transposition.
Article 3
DefinitionsESAs Decision on reporting of information for CTPP designation (corrigendum consolidated)
EBA, ESMA, and EIOPA joint decision establishing annual reporting requirements for EU competent authorities to provide data on ICT third-party service providers, supporting designation of critical providers under DORA (Regulation (EU) 2022/2554) and Delegated Regulation (EU) 2024/1502, with first submission due by 30 April 2025.