DORA has been live since 17 January 2025. 2026 is the year the paperwork meets a supervisor. If your answer is still “we have ISO 22301,” that is a start, not a file.
We already mapped the stack last spring: DORA, CISA, ISO 22301. This is the exam-year cut of that piece.
What 2026 actually produced
On 3 June 2026 the European Supervisory Authorities published their first annual DORA report on major ICT-related incidents. Financial entities in the EU reported 3,383 major incidents. About a third had a cross-border impact. The main drivers were system failures and external events, not Hollywood hacks. Cyber was about 10%. The authorities pointed at third-party risk and shared infrastructure.
That is Article 22(2) doing what it said it would do: count the incidents, name the nature, look at client impact. If you sell continuity to an insurer or a bank with an EU passport, this is the dataset your client’s competent authority just read.
The other 2026 fact: the ESAs designated critical ICT third-party providers in November 2025. Those names now sit under Joint Examination Teams. Your cloud contract is no longer a private argument between you and the vendor.
ISO 22301 is not a DORA waiver
ISO 22301 is still a good continuity system: BIA, strategies, exercises, management review. DORA is a regulation. EIOPA’s DORA page lists the live pieces: ICT risk management, third-party policy, incident classification and reporting, testing (including threat-led penetration testing for the ones in scope), and oversight of critical providers.
Article 11 wants an ICT business continuity policy that locks to incident response and recovery — not a generic pandemic binder with “cyber” taped on page 40. Yearly tests of backup, failover, and the continuity plan are table stakes. The Register of Information is how supervisors see your ICT chain. If that register is empty or pretty, the exam already failed.
Keep the ISO certificate. Add the DORA artifacts the RTS actually name: incident classification, major-incident reporting clocks, third-party clauses, exit plans, and a test calendar you can show without a scavenger hunt.
What to put on the desk this quarter
- Open last year’s incident log. Re-class it the DORA way. If you cannot say which events would have been “major,” you cannot report one.
- Pull the Register of Information for every ICT service that touches a critical function. Concentration on one cloud region should scare you more than a red-team slide.
- If you are a US continuity shop writing for an EU financial client, stop delivering a CISA-only packet. Their examiner is reading EBA/EIOPA/ESMA, not your FEMA annex.
- Exercise the exit: one vendor, one afternoon, who runs the function if that vendor is dark. Write the names.
The first DORA year was “are you in scope.” This year is “show the incident, the vendor, and the test.” Bring those three folders.
Sources: Regulation (EU) 2022/2554 (DORA, in application 17 January 2025); EIOPA DORA overview; ESAs first annual major ICT-incident report (3 June 2026).