From the journal

EIOPA issues operational instructions for incident reporting under DORA

EIOPA has published operational instructions detailing incident reporting requirements under the Digital Operational Resilience Act (DORA) for regulated entities.

1 min read

EIOPA published operational instructions on 17 July 2026 regarding incident reporting under the Digital Operational Resilience Act (DORA). The instructions require regulated entities to report incidents affecting their operational resilience, including specific timelines and information needed for compliance.

The operational instructions are part of the Digital Operational Resilience Act (DORA), specifically addressing incident reporting requirements.

The instructions apply to all regulated entities, including banks, insurance companies, investment firms, and ICT third-party service providers.

No specific deadline for compliance is stated in the material, but entities must familiarize themselves with the instructions to avoid regulatory scrutiny or penalties.

The instructions emphasize the importance of updating incident reporting processes to align with EIOPA's requirements, ensuring that entities can withstand and recover from ICT disruptions.

Source: EIOPA, official publication, retrieved 2026-09-17