ESMA, the European Securities and Markets Authority, emphasized that mitigation of cyber risks and assurance of digital resilience remain focus topics of supervisory efforts in 2026.
With the application of the Digital Operational Resilience Act (DORA) in January 2025, ESMA had identified cyber and digital resilience as a Union Strategic Supervisory Priority (USSP) for 2025.
Now, ESMA re-emphasizes this USSP for 2026.
ESMA as well as National Competent Authorities shall intensify their already strong collaboration and supervision for ensuring that proper risk management regarding Information and Communication Technology (ICT) is applied equivalently at credit and financial institutions across the entire EU. According to ESMA, a coordinated oversight of DORA requirements is mandatory to realize secure and resilient financial markets in the EU.
This will characterize what market both participants subject to financial supervision as well as their providers of ICT services should (remain to) prepare for in 2026.
Please find ESMA’s full press release here.