Europe’s financial supervisors have introduced a new set of operational instructions for reporting major information and communication technology incidents under the Digital Operational Resilience Act, known as DORA.
London's trading industry is coming home!
Published on 16 September 2026, the five-page document is short, but important. It addresses 14 practical issues identified in the reporting process, from the treatment of monetary values and incident identifiers to third-party provider details, service downtime and economic impact. Its stated purpose is to improve data quality and make reporting more consistent across EU jurisdictions.
Why DORA Was So Important
DORA became applicable on 17 January 2025, creating a common EU framework for ICT risk management, incident reporting, resilience testing and third-party technology risk. It covers more than 20 categories of financial entity, including investment firms, trading venues, payment and electronic money institutions, crypto-asset service providers, banks, insurers and fund managers.
DORA was important because it made digital resilience a direct regulatory responsibility. Technology failures were no longer treated mainly as internal IT or cybersecurity matters. They became financial stability, business continuity and conduct issues requiring board-level oversight and a documented regulatory response.
- DORA Review: How Resilient Is Europe’s Financial Sector?
- EU’s First DORA Review Finds One-Third of Financial ICT Incidents Spread Across Borders
- One Year After DORA, Brokers Are Playing Catch-Up
What the New Instructions Change, and What They Do Not
The September instructions do not alter the legal perimeter of DORA. They do not expand the list of regulated companies, change the meaning of a major incident or impose new sanctions. They also leave the formal reporting route unchanged: firms continue to submit reports through the channels and formats established by their national competent authority.
What changes is the degree of operational clarity. The document identifies specific practices that have made reports difficult to compare, process or analyse. It therefore narrows the room for interpretation when firms complete the existing templates.
This marks a new stage in the operation of the established reporting framework. Supervisory attention is moving from the introduction of policies and templates to the quality of the information submitted. A report may arrive on time and still create problems if identifiers change between filings, monetary figures use different units, a field contains unnecessary text or the same third-party provider is described differently by several firms.
| Area | September 2026 operational expectation |
|---|---|
| Legal obligations | No change to existing DORA obligations |
| Incident identity | Keep key identifiers unchanged throughout the reporting cycle |
| Monetary information | Report specified fields in thousands, using the currency in Field 1.15 |
| Ongoing incidents | Submit at least one intermediate update each month until the final report |
| Corrections | Correct the latest report version and retain all previously reported information |
| Third-party origin | Use the required order for provider name, identifier and code type |
| Empty fields | Leave non-mandatory fields blank when they do not apply |
Find the full analysis, including a detailed breakdown of the reporting instructions, in our latest report from Finance Magnates Intelligence.