{"id":12949,"date":"2026-04-24T21:27:36","date_gmt":"2026-04-24T21:27:36","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/24\/tobias-ich-muss-dich-auf-etwas-aufmerksam-machen-deine\/"},"modified":"2026-06-10T11:19:51","modified_gmt":"2026-06-10T11:19:51","slug":"uk-fca-s-april-2026-rules-and-the-road-to-dora-2-0-what","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/04\/24\/uk-fca-s-april-2026-rules-and-the-road-to-dora-2-0-what\/","title":{"rendered":"FCA DORA 2.0: Financial Institutions Must Architect Now"},"content":{"rendered":"<p style=\"color:#69d8ed;font-size:0.9em;margin:0 0 16px;padding:0;\">8 min. read<\/p>\n<p><strong>On 16 April 2026, the UK&#8217;s Financial Conduct Authority published new Operational Incident and Third-Party Reporting rules, marking the first post-DORA regulatory wave across Europe. The FCA is requiring financial institutions and their ICT third-party providers to adopt new classification and notification timelines that go further than DORA in both depth and scrutiny. In Brussels, preparations are simultaneously underway for a DORA evaluation due to feed into a review report by the end of 2026 \u2014 one that makes a tightening of requirements in 2027 increasingly likely. Security teams should not wait for DORA 2.0: they need to stress-test their architecture against the known gaps right now.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">The UK FCA published new Operational Incident rules on 16 April 2026.<\/strong> Stricter classification and reporting timelines than DORA, with explicit third-party reporting obligations.<\/li>\n<li style=\"margin-bottom:12px;\"><strong style=\"color:#69d8ed;\">Brussels is preparing a DORA review by end of 2026.<\/strong> Early audits from 2025 reveal gaps in incident classification, TLPT scoping, and ICT supply chain visibility.<\/li>\n<li><strong style=\"color:#69d8ed;\">Financial institutions should act at the architecture level now.<\/strong> Unified incident taxonomy, continuous TLPT scoping, and active third-party monitoring are no longer optional.<\/li>\n<\/ul>\n<\/div>\n<p style=\"font-size:0.88em;color:#666;margin:20px 0 32px 0;border-top:1px solid #e5e5e5;border-bottom:1px solid #e5e5e5;padding:10px 0;\"><span style=\"color:#004a59;font-weight:700;text-transform:uppercase;font-size:0.72em;letter-spacing:0.14em;margin-right:14px;\">Related<\/span><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/23\/asp-net-core-cve-2026-40372-cvss-9-1-compliance-implications\/\" style=\"color:#333;text-decoration:underline;\">ASP.NET Core CVE: Compliance Implications under DORA and NIS2<\/a>&nbsp;&nbsp;<span style=\"color:#ccc;\">\/<\/span>&nbsp;&nbsp;<a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/20\/ot-security-2026-why-iec-62443-and-the-eu-cyber-resilience\/\" style=\"color:#333;text-decoration:underline;\">OT Security 2026: IEC 62443 and the Cyber Resilience Act<\/a><\/p>\n<h2 style=\"margin-top:40px;margin-bottom:20px;\">What the UK FCA Changed on 16 April \u2014 In Detail<\/h2>\n<p>The Financial Conduct Authority published its Policy Statement on Operational Incident and Third-Party Reporting Rules on 16 April 2026. The core tightening is a new two-tier reporting obligation: every operationally significant ICT disruption above a quantified impact threshold must be reported as an Initial Notification within six hours, followed by a detailed post-incident analysis within 30 days. Notably, the third-party reporting element extends this further \u2014 financial institutions must now report not only their own incidents but also material incidents at their ICT third-party providers, where those incidents affect UK financial services.<\/p>\n<p>DORA in its current form also requires incident reporting, but leaves the classification thresholds considerably more open to interpretation. The ESA RTS from 2024 define qualitative criteria, yet practice across the first 15 months shows that institutions in identical situations reach very different assessments. The UK has clearly taken note and quantified the classification catalogue in its successor framework.<\/p>\n<p>For DACH financial institutions, the UK wave matters for three reasons. First, most major banks and insurers operate significant UK businesses and must implement the rules regardless. Second, the UK text effectively serves as a blueprint for the DORA review the European Commission is due to complete by end of 2026. Third, the UK thresholds set a new benchmark against which supervisors in EU member states will calibrate their expectations \u2014 well before any formal DORA revision arrives.<\/p>\n<div style=\"background:#003340;color:#fff;text-align:center;padding:40px 24px;margin:32px 0;border-radius:8px;\">\n<div style=\"font-size:3.4em;font-weight:800;color:#69d8ed;letter-spacing:-0.03em;line-height:1;\">6 h<\/div>\n<div style=\"font-size:1em;color:rgba(255,255,255,0.88);margin-top:12px;max-width:520px;margin:12px auto 0;line-height:1.5;\">Initial Notification window for operationally significant ICT incidents under the new UK FCA rules of 16 April 2026. DORA currently requires reporting &#8220;without undue delay&#8221; with no hard hourly deadline.<\/div>\n<div style=\"font-size:0.78em;color:rgba(255,255,255,0.5);margin-top:12px;\">Source: FCA Policy Statement Operational Incident and Third-Party Reporting Rules, 16.04.2026<\/div>\n<\/div>\n<p><strong>What is DORA 2.0?<\/strong> DORA 2.0 is not a enacted legal act but the industry shorthand for the anticipated revision of EU Regulation 2022\/2554. The European Commission is legally required to submit an evaluation of the DORA implementation by 17 January 2028. However, early ESA working documents already point to a tightening of Technical Standards in 2026 \u2014 particularly around incident classification, TLPT scoping, and ICT third-party risk. Institutions should treat the term as a placeholder for a combination of revised RTS and potential amendments to the regulation itself.<\/p>\n<h2 style=\"margin-top:40px;margin-bottom:20px;\">The Three Weaknesses DORA Audits Consistently Uncover in 2025\/2026<\/h2>\n<p>Anyone reviewing the first supervisory feedback from Germany, France and the Netherlands will find the same three gaps every time. These are the most likely focus of any DORA tightening to come.<\/p>\n<p><strong>Incident classification without consistency.<\/strong> The RTS define impact criteria qualitatively: customer impact, duration, data protection dimension, reputational effect. That sounds clean, but in practice it produces inconsistent decisions. Two institutions experiencing the same cloud outage frequently arrive at different classifications. Incident reviews have repeatedly shown cases where an event was classified internally as &#8220;major&#8221; but reported to BaFin as &#8220;significant&#8221; \u2014 because the reporting obligation kicks in earlier at the &#8220;major&#8221; level. The UK approach with hard thresholds is a direct answer to exactly this problem.<\/p>\n<p><strong>TLPT scoping too narrow.<\/strong> Threat-Led Penetration Testing is mandatory under DORA for systemically relevant institutions, and the TIBER-EU framework is the de facto standard. In the first TLPT rounds of 2025, many institutions narrowed the scope to their own digital channels. ICT supply chains were frequently excluded. ESMA flagged this in a Q1 2026 quarterly report, noting that future examinations must cover the entire critical ICT chain. This is technically a significant leap: running red-team scenarios against managed service providers and their infrastructure requires contractual frameworks and a willingness to cooperate that is rarely documented today.<\/p>\n<p><strong>ICT third-party registers incomplete.<\/strong> The DORA ICT register is, in theory, a comprehensive picture of all critical ICT services. In practice, sub-processor relationships are often not captured. The Commvault push to Google Cloud on 22 April is a good illustration: anyone currently listing Commvault as a backup provider in their register may now need to add Google Cloud as a sub-processor following the integration. When these shifts are not reflected in real time, a gap opens between operational reality and the register \u2014 one that will surface at the next examination.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;background:linear-gradient(135deg,#e5f6fa 0%,#d0edf3 100%);padding:24px 28px;margin:32px 0;font-style:italic;font-size:1.1em;color:#003340;border-radius:4px;\"><p>\nAny institution maintaining an ICT register like an inventory list updated once a year has understood neither the UK rule nor the coming DORA tightening. Registers in 2026 are operational \u2014 or they are worthless.\n<\/p><\/blockquote>\n<h2 style=\"margin-top:40px;margin-bottom:20px;\">What the First ESA Assessments of 2025\/26 Soberly Reveal<\/h2>\n<p>The European supervisory authorities EBA, ESMA and EIOPA published a joint evaluation of the first DORA application phase in early 2026. Their core findings largely align with those of individual national supervisors such as BaFin and the Dutch DNB. Three conclusions run consistently through all the reports.<\/p>\n<p>First: reporting quality is uneven. For the same incident type, impact figures vary between institutions by a factor of three to five. This is less a problem of bad faith than one of methodology. The RTS define qualitative criteria without a concrete calculation model; incident managers at banks have no standardised template to work from. The result: supervisors struggle to draw cross-institutional comparisons, even though enabling exactly that is the point of a pan-European regulation.<\/p>\n<p>Second: visibility into third parties almost always stops at the first tier. An institution knows its direct ICT service providers, but rarely the second or third layer. This runs counter to DORA&#8217;s intent \u2014 the regulation demands chain transparency down to critical sub-processors. Compliance practice has not caught up with the regulatory expectation. When a major incident at a sub-processor hits the bank, retrospective reconstruction is laborious at best, impossible at worst.<\/p>\n<p>Third: TLPT findings are frequently treated internally as a one-off event. The RTS require that insights feed into ongoing risk analysis. In practice, they often end up in a thick report presented once to the board, without systematically informing architecture decisions thereafter. The learning effect falls well short of what the regulation envisioned.<\/p>\n<h2 style=\"margin-top:40px;margin-bottom:20px;\">Five Steps Security Teams Should Take Now<\/h2>\n<p>Further tightening is coming, but not today. The useful response is not to wait, but to do targeted groundwork that makes sense regardless of the exact wording of a DORA 2 RTS. Five priorities that should be addressed in the next 120 days.<\/p>\n<p><strong>First: Unified Incident Taxonomy.<\/strong> Align internal classification with FCA thresholds, even if the institution does not operate in the UK. Quantitative criteria reduce variance between different incident managers and provide a defensible line of argument with supervisors. The effort: one week of workshops plus tooling adjustments.<\/p>\n<p><strong>Second: Expand the TLPT scope.<\/strong> When the next TLPT window arrives in 2026 or 2027, the ICT supply chain should be included. Concretely, that means explicitly incorporating at least one central managed service provider into the red-team scenario, with contractual consent. Even if DORA 2.0 does not yet require it, the insight gained for your own architecture is substantial.<\/p>\n<p><strong>Third: Keep the ICT register operational.<\/strong> Treat the register not as a compliance document but as a live database with automated integrations to contract management and CMDB. Every new ICT service provider onboarding should trigger a register update automatically. A quarterly review whenever changes occur in the sub-processor chain.<\/p>\n<p><strong>Fourth: Third-party monitoring.<\/strong> The UK rule requires reporting on incidents at third-party providers. That only works if the institution has active monitoring in place for its critical service providers \u2014 specifically: incident APIs, status-page scraping, and regular SOC coordination calls. Many institutions have this for their core systems, but not for sub-processors.<\/p>\n<p><strong>Fifth: Revise runbooks.<\/strong> The FCA&#8217;s six-hour reporting deadline is only realistically achievable if the internal runbook strictly defines the first 90 minutes. Any institution still debating who calls the BaFin hotline in the middle of a major incident will miss the deadline.<\/p>\n<p>One detail that often gets lost in the debate: both DORA and the UK rule require no simultaneous public disclosure. The notification goes to the supervisor; communications with customers and press remain the institution&#8217;s own business. Confusing the two creates unnecessary reputational risk. For the three lines of defence, this means compliance, communications, and IT security must have clearly defined, non-overlapping roles in the incident response playbook. That sounds trivial \u2014 in practice, it is one of the most common sources of failure.<\/p>\n<p>The discipline gap between DORA&#8217;s ambitions and actual implementation also explains why some institutions suddenly face disproportionately high remediation costs after a single incident. Those who write clean runbooks in advance and run tabletop exercises three or four times a year stay in the mid-five-figure range. Those who react only after a major incident has been documented can quickly find themselves paying several hundred thousand euros in external consulting fees, because every adjustment happens under time pressure.<\/p>\n<p>Experience also shows that coordination with critical ICT service providers goes better when your own house has clean internal processes. A provider receiving three contradictory requests from a bank client about the same incident will become defensive and share minimal information. A bank client with a clear single point of contact and an unambiguous escalation path receives significantly more comprehensive cooperation. That is not a regulatory argument \u2014 it is operational experience, and it is frequently confirmed in informal conversations with supervisors.<\/p>\n<p>For 2027 budget planning, a straightforward reality check is worthwhile. Institutions that have so far viewed their DORA architecture as a cost centre should use the next twelve months to make its operational value visible. A well-maintained ICT register integrated with CMDB and contract management is not just compliance work \u2014 it is the foundation for sound vendor management. An operationalised incident taxonomy accelerates post-mortems and reduces mean time to resolution. Frame that case compellingly, and phase-two budgets become considerably easier to secure.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<h3>When is DORA 2.0 coming?<\/h3>\n<p>There is no confirmed date. The European Commission must submit an evaluation by 17 January 2028. Initial RTS adjustments are likely between 2026 and 2027. The term DORA 2.0 is widely used in the industry to describe these refinements, but it is not an official legal act.<\/p>\n<h3>Are UK rules binding for EU institutions?<\/h3>\n<p>Only if an institution operates within the UK perimeter \u2014 in that case, yes. For purely EU-based institutions, they carry signal value. Supervisors on the continent align their expectations with the neighbourhood; FCA thresholds will likely be used as a benchmark for future RTS revisions.<\/p>\n<h3>What exactly is TLPT?<\/h3>\n<p>Threat-Led Penetration Testing is a comprehensive red-team exercise conducted under real-world attacker conditions. The ECB&#8217;s TIBER-EU framework is the European standard. Scope, ruleset and execution are significantly more rigorous than conventional penetration tests. For systemically important institutions, TLPT is mandatory under DORA.<\/p>\n<h3>How often should the ICT register be updated?<\/h3>\n<p>At minimum quarterly, and immediately whenever there are changes in the critical service provider chain. As a rule of thumb: when a new sub-processor is added, or an existing one migrates its infrastructure, the register must be updated in sync. Tools such as OneTrust or Archer offer dedicated workflows for this.<\/p>\n<h3>What are realistic costs for the five steps?<\/h3>\n<p>For a mid-sized financial institution, additional costs in the first year range from \u20ac150,000 to \u20ac400,000, depending on the maturity of existing ICT risk management. The bulk of the effort lies in extending the TLPT scope; taxonomy alignment accounts for the smallest share.<\/p>\n<div style=\"margin:40px 0;padding:0;border-top:2px solid #004a59;\">\n<p style=\"margin:0;padding:16px 0 8px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#004a59;\">Editor&#8217;s Reading Tips<\/p>\n<ul style=\"list-style:none;margin:0;padding:0;\">\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/23\/asp-net-core-cve-2026-40372-cvss-9-1-compliance-implications\/\" style=\"color:#1a1a1a;text-decoration:none;\">ASP.NET Core CVE-2026-40372: Compliance Implications under DORA and NIS2<\/a><\/li>\n<li style=\"padding:10px 0;border-bottom:1px solid #eee;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/20\/ot-security-2026-why-iec-62443-and-the-eu-cyber-resilience\/\" style=\"color:#1a1a1a;text-decoration:none;\">OT Security 2026: IEC 62443 and the EU Cyber Resilience Act<\/a><\/li>\n<li style=\"padding:10px 0;\"><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/21\/apache-activemq-under-fire-what-security-teams-must-learn\/\" style=\"color:#1a1a1a;text-decoration:none;\">Apache ActiveMQ Under Active Attack: What Security Teams Need to Learn<\/a><\/li>\n<\/ul>\n<\/div>\n<div style=\"margin:40px 0 24px 0;\">\n<p style=\"margin:0 0 12px 0;font-size:0.78em;font-weight:700;text-transform:uppercase;letter-spacing:0.18em;color:#666;\">More from the MBF Media Network<\/p>\n<div style=\"padding:14px 18px;border-left:3px solid #0bb7fd;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#0bb7fd;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">cloudmagazin<\/div>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/2026\/04\/24\/commvault-clumio-google-cloud-storage-cloud-next-dach-backup-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">Commvault Brings Clumio to Google Cloud Storage<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #202528;background:#fafafa;margin-bottom:6px;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#202528;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">mybusinessfuture<\/div>\n<p><a href=\"https:\/\/mybusinessfuture.com\/ai-failure-rate-80-prozent-rand-gartner-mittelstand-2026\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">80 Percent AI Failure Rate: RAND and Gartner Expose the AI Gap<\/a>\n<\/div>\n<div style=\"padding:14px 18px;border-left:3px solid #d65663;background:#fafafa;\">\n<div style=\"font-size:0.7em;font-weight:700;color:#d65663;text-transform:uppercase;letter-spacing:0.12em;margin-bottom:4px;\">digital-chiefs<\/div>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/tpu-8i-agent-inference-google-cloud-next-2026-vorstand-ki-infrastruktur\/\" style=\"font-weight:600;line-height:1.4;color:#1a1a1a;text-decoration:none;\">TPU 8i and Agent Inference Pods: What Google Cloud Next 2026 Means for the C-Suite<\/a>\n<\/div>\n<\/div>\n<p style=\"text-align:right;\"><em>Cover image source: Pexels \/ Sora Shimazaki (px:5669619)<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"FCA rules from 16 April 2026 tighten incident reporting and third-party obligations. ESA audits 2025 reveal three DORA vulnerabilities. Five steps for financial security teams.","protected":false},"author":10,"featured_media":12944,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"DORA 2.0 FCA","_yoast_wpseo_title":"UK FCA's April 2026 Rules and the Road to DORA 2.0: What Financial Institutions","_yoast_wpseo_metadesc":"New FCA Rules tighten incident and third-party reporting. What financial institutions must prepare at architecture level now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["tobias-ich-muss-dich-auf-etwas-aufmerksam-machen-deine"],"footnotes":""},"categories":[217],"tags":[],"class_list":["post-12949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-innovation"],"evm_reading_time_minutes":12,"wpml_language":"en","wpml_translation_of":12945,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=12949"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12949\/revisions"}],"predecessor-version":[{"id":15459,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/12949\/revisions\/15459"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/12944"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=12949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=12949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=12949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}