From the journal

ESAs publish guide on DORA oversight activities

The European Supervisory Authorities have published a guide on oversight activities under DORA, aimed at helping entities prepare for upcoming requirements.

1 min read

The European Supervisory Authorities published a guide on oversight activities under the Digital Operational Resilience Act (DORA) on 15 July 2025. The guide outlines the processes used by the ESAs through Joint Examination Teams to oversee critical Information and Communication Technology third-party service providers.

The guide is not legally binding and does not replace existing EU legal requirements. It provides an overview of the CTPP Oversight framework, including governance structure, oversight processes, and available tools.

The guide applies to public entities, financial institutions, and third-party providers. These entities should review the guide to prepare for the upcoming oversight requirements.

Entities must align their operational practices with the outlined oversight processes by 15 July 2025. Compliance teams should begin this alignment as the DORA implementation progresses.

Source: ESMA, official publication, retrieved 2026-07-21