A New Phase of DORA Reporting: What Financial Firms Need to Fix Now

Monday, 21/09/2026 | 13:00 GMT by Sylwester Majewski
  • Clarifications from EU supervisors address 14 frequent compliance mistakes, ranging from inconsistent monetary reporting to missing follow-up reports during major technology outages.
  • Firms face immediate regulatory friction if these operational reporting gaps remain unaddressed, directly exposing their digital governance to heightened supervisory scrutiny.
DORA instructions
source: shutterstock.com

Europe’s financial supervisors have introduced a new set of operational instructions for reporting major information and communication technology incidents under the Digital Operational Resilience Act, known as DORA.

London's trading industry is coming home!

Published on 16 September 2026, the five-page document is short, but important. It addresses 14 practical issues identified in the reporting process, from the treatment of monetary values and incident identifiers to third-party provider details, service downtime and economic impact. Its stated purpose is to improve data quality and make reporting more consistent across EU jurisdictions.

Why DORA Was So Important

DORA became applicable on 17 January 2025, creating a common EU framework for ICT risk management, incident reporting, resilience testing and third-party technology risk. It covers more than 20 categories of financial entity, including investment firms, trading venues, payment and electronic money institutions, crypto-asset service providers, banks, insurers and fund managers.

DORA was important because it made digital resilience a direct regulatory responsibility. Technology failures were no longer treated mainly as internal IT or cybersecurity matters. They became financial stability, business continuity and conduct issues requiring board-level oversight and a documented regulatory response.

What the New Instructions Change, and What They Do Not

The September instructions do not alter the legal perimeter of DORA. They do not expand the list of regulated companies, change the meaning of a major incident or impose new sanctions. They also leave the formal reporting route unchanged: firms continue to submit reports through the channels and formats established by their national competent authority.

What changes is the degree of operational clarity. The document identifies specific practices that have made reports difficult to compare, process or analyse. It therefore narrows the room for interpretation when firms complete the existing templates.

This marks a new stage in the operation of the established reporting framework. Supervisory attention is moving from the introduction of policies and templates to the quality of the information submitted. A report may arrive on time and still create problems if identifiers change between filings, monetary figures use different units, a field contains unnecessary text or the same third-party provider is described differently by several firms.

AreaSeptember 2026 operational expectation
Legal obligationsNo change to existing DORA obligations
Incident identityKeep key identifiers unchanged throughout the reporting cycle
Monetary informationReport specified fields in thousands, using the currency in Field 1.15
Ongoing incidentsSubmit at least one intermediate update each month until the final report
CorrectionsCorrect the latest report version and retain all previously reported information
Third-party originUse the required order for provider name, identifier and code type
Empty fieldsLeave non-mandatory fields blank when they do not apply

Find the full analysis, including a detailed breakdown of the reporting instructions, in our latest report from Finance Magnates Intelligence.

Europe’s financial supervisors have introduced a new set of operational instructions for reporting major information and communication technology incidents under the Digital Operational Resilience Act, known as DORA.

London's trading industry is coming home!

Published on 16 September 2026, the five-page document is short, but important. It addresses 14 practical issues identified in the reporting process, from the treatment of monetary values and incident identifiers to third-party provider details, service downtime and economic impact. Its stated purpose is to improve data quality and make reporting more consistent across EU jurisdictions.

Why DORA Was So Important

DORA became applicable on 17 January 2025, creating a common EU framework for ICT risk management, incident reporting, resilience testing and third-party technology risk. It covers more than 20 categories of financial entity, including investment firms, trading venues, payment and electronic money institutions, crypto-asset service providers, banks, insurers and fund managers.

DORA was important because it made digital resilience a direct regulatory responsibility. Technology failures were no longer treated mainly as internal IT or cybersecurity matters. They became financial stability, business continuity and conduct issues requiring board-level oversight and a documented regulatory response.

What the New Instructions Change, and What They Do Not

The September instructions do not alter the legal perimeter of DORA. They do not expand the list of regulated companies, change the meaning of a major incident or impose new sanctions. They also leave the formal reporting route unchanged: firms continue to submit reports through the channels and formats established by their national competent authority.

What changes is the degree of operational clarity. The document identifies specific practices that have made reports difficult to compare, process or analyse. It therefore narrows the room for interpretation when firms complete the existing templates.

This marks a new stage in the operation of the established reporting framework. Supervisory attention is moving from the introduction of policies and templates to the quality of the information submitted. A report may arrive on time and still create problems if identifiers change between filings, monetary figures use different units, a field contains unnecessary text or the same third-party provider is described differently by several firms.

AreaSeptember 2026 operational expectation
Legal obligationsNo change to existing DORA obligations
Incident identityKeep key identifiers unchanged throughout the reporting cycle
Monetary informationReport specified fields in thousands, using the currency in Field 1.15
Ongoing incidentsSubmit at least one intermediate update each month until the final report
CorrectionsCorrect the latest report version and retain all previously reported information
Third-party originUse the required order for provider name, identifier and code type
Empty fieldsLeave non-mandatory fields blank when they do not apply

Find the full analysis, including a detailed breakdown of the reporting instructions, in our latest report from Finance Magnates Intelligence.

About the Author: Sylwester Majewski
Sylwester Majewski
  • 169 Articles
  • 21 Followers
About the Author: Sylwester Majewski
Sylwester is a graduate of the Warsaw School of Economics, holding an MA in Finance and Banking. He currently serves as Head of the Insights & Reporting Hub at Finance Magnates. He is also a former minority partner in an NFA-registered US forex broker and has been involved in numerous forex and trading industry projects since 2003. Privately, Sylwester is a husband and father to a 7-year-old daughter, as well as an enthusiast of trading and Formula 1.
  • 169 Articles
  • 21 Followers

More from the Author

Retail FX

!"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|} !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}