The European Supervisory Authorities (EBA, EIOPA, ESMA) published a guide on oversight activities under the Digital Operational Resilience Act (DORA) on 15 July 2025. The guide aims to provide an overview of the processes used by the ESAs to oversee critical ICT third-party service providers.
The guide is not legally binding and does not replace the legal requirements in applicable EU law. It includes high-level explanations regarding the CTPP Oversight framework, governance structure, oversight processes, founding principles, and available tools for overseers.
The guide applies to all regulated entities, including financial entities and third-party providers. The ESAs invite these entities to use the document to prepare for oversight implementation.
Key compliance deadlines are set for 31 July 2026, 3 August 2026, and 23 September 2026. Entities affected by DORA should prepare for these upcoming deadlines related to compliance reporting and operational resilience requirements.