SecBriefs
← Industry Reports
European Banking Authority (EBA)European Banking Authority (EBA)
INDUSTRY REPORTRegulation & Policy6 min read

EBA 2026: DORA Is Reshaping ICT Risk Supervision Across EU Banking

The EBA’s 2026 follow-up review finds meaningful progress in how EU supervisors assess ICT risk, with DORA accelerating supervisory capacity, horizontal analysis and more consistent use of ICT risk categories and tools.

European Banking Authority (EBA)
2026

Follow-up to the Peer Review Report on ICT Risk Assessment under the SREP

REGULATION & POLICY · SECBRIEFS ANALYSIS
THE SHORT VERSION

Executive Takeaway

The EBA finds that EU competent authorities have strengthened ICT supervisory capacity since its 2022 peer review, while DORA has materially changed the supervisory landscape since becoming applicable in January 2025. Authorities are making greater use of horizontal analysis, supervisory tools and common ICT risk categories. ICT risk is becoming more deeply embedded in mainstream prudential supervision.

Key Findings

  1. 01

    Competent authorities have made notable progress in strengthening ICT risk assessment since the EBA’s 2022 peer review.

  2. 02

    DORA, applicable since January 2025, is a major driver of change in ICT risk supervision across the EU financial sector.

  3. 03

    Supervisors are strengthening ICT expertise and capacity and increasing their use of horizontal analyses and supervisory tools.

  4. 04

    ICT risk sub-categories and risk scenarios are more broadly implemented, though some gaps remain.

  5. 05

    Standalone ICT SREP guidance is being integrated into revised SREP guidelines to improve consistency and simplify supervision.

What the Data Says

What It Doesn’t Say / Limitations

The report evaluates supervisory authorities and convergence rather than individual banks. It indicates the direction of supervisory expectations but does not replace institution-specific SREP findings, DORA testing results or competent-authority guidance.

Why It Matters

For EU banks, DORA implementation is no longer only a specialist compliance programme. The findings show ICT resilience becoming part of the broader prudential supervisory process, increasing the importance of consistent evidence, governance and risk taxonomy across frameworks.

Who Should Care

  • EU and EEA banks
  • Bank CISOs and CIOs
  • Operational resilience teams
  • DORA programme owners
  • Risk and compliance functions
  • Internal audit and supervisory liaison teams
SECBRIEFS VIEW

SecBriefs Assessment

The strongest signal is convergence. Banks should avoid maintaining separate ICT-risk narratives for DORA, SREP, internal risk management and board reporting. A common evidence model will reduce inconsistency and supervisory friction.

What To Do Now

  1. Cross-map DORA controls and evidence to ICT risk categories used in SREP and internal risk management.
  2. Keep ICT risk metrics consistent across board reporting, risk appetite, incidents and resilience testing.
  3. Use horizontal benchmarking to identify outliers before supervisory review.
  4. Invest in specialist ICT risk expertise across first, second and third lines.
  5. Track revised SREP guidance as ICT risk assessment becomes more integrated into the wider supervisory methodology.
ORIGINAL REPORT

Follow-up to the Peer Review Report on ICT Risk Assessment under the SREP

Publisher
European Banking Authority (EBA)
Published
URL
https://www.eba.europa.eu/sites/default/files/2026-02/57ba5573-eb1a-413c-8fbb-ca3d3a2eb0b2/Follow%20up%20Peer%20Review%20Report%20on%20ICT%20Risk%20Assessment%20under%20SREP.pdf
View on publisher site(opens in a new tab)

Get the next SecBriefs report analysis

Clear analysis of major cybersecurity reports, delivered by SecBriefs.