The European Banking Authority’s (EBA) revised Supervisory Review and Evaluation Process (SREP) Guidance for 2026 introduces a paradigm shift: ICT risk is no longer a standalone compliance exercise but a direct input into capital and liquidity requirements. For CTOs, CISOs, and risk officers in financial entities, this means that every incident report, third-party audit, and resilience test now carries weight in supervisory efficiency metrics. The message is clear—DORA compliance is not just abo
The European Banking Authority’s (EBA) revised Supervisory Review and Evaluation Process (SREP) Guidance for 2026 introduces a paradigm shift: ICT risk is no longer a standalone compliance exercise but a direct input into capital and liquidity requirements. For CTOs, CISOs, and risk officers in financial entities, this means that every incident report, third-party audit, and resilience test now carries weight in supervisory efficiency metrics. The message is clear—DORA compliance is not just about ticking boxes; it is about measurable operational resilience that influences your institution’s financial health.
Why SREP 2026 Changes Everything for DORA Compliance
The EBA’s SREP has long been the mechanism through which supervisors assess the risks of financial institutions and determine capital add-ons. Historically, ICT risk was a peripheral consideration, often folded into broader operational risk categories. However, with the Digital Operational Resilience Act (DORA) now in force (applicable from 17 January 2025), ICT risk has been elevated to a first-order concern. The EBA’s 2026 SREP Guidance formalises this shift by embedding DORA’s requirements into the supervisory review process.
Under the new framework, ICT risk is no longer an abstract concept but a quantifiable factor in the SREP scoring methodology. This means that financial entities—banks, investment firms, payment institutions, and others in scope—must now demonstrate not just compliance with DORA’s technical standards but also the *effectiveness* of their ICT risk management. Supervisors will use this data to adjust capital requirements, making ICT resilience a direct driver of financial stability.
The implications are significant. A poorly managed ICT incident or a failed third-party audit could result in higher capital buffers, increased liquidity requirements, or even supervisory intervention. Conversely, robust resilience testing and proactive incident management could mitigate these risks, providing a competitive advantage in capital efficiency.
The New ICT Risk Scoring Methodology: What EBA Actually Measures
The EBA’s ICT risk scoring methodology is designed to be both granular and holistic, assessing four key dimensions of operational resilience:
- 1ICT Governance and Strategy
- 2ICT Risk Management Framework
- 3Incident Management and Reporting
- 4Third-Party Risk Management and Resilience Testing
Each dimension is scored on a scale from 1 (low risk) to 4 (high risk), with intermediate scores reflecting varying degrees of maturity. The aggregate ICT risk score then feeds into the broader SREP assessment, influencing the institution’s overall risk profile and capital requirements.
ICT Governance and Strategy
Supervisors will evaluate whether the institution’s ICT strategy aligns with its business objectives and risk appetite. This includes assessing the clarity of roles and responsibilities, the effectiveness of the board’s oversight, and the integration of ICT risk into the institution’s enterprise risk management framework. DORA’s emphasis on board-level accountability (Article 5) is directly reflected here—entities must demonstrate that their leadership is actively engaged in ICT risk oversight.
ICT Risk Management Framework
This dimension focuses on the institution’s ability to identify, assess, and mitigate ICT risks. Supervisors will scrutinise the robustness of risk identification processes, the adequacy of risk assessment methodologies, and the effectiveness of controls. The EBA expects institutions to adopt a risk-based approach, prioritising resources based on the criticality of systems and data. DORA’s requirements for ICT risk management (Article 6) and the associated regulatory technical standards (RTS) on risk management frameworks will serve as the baseline for this assessment.
Incident Management and Reporting
The EBA’s methodology places significant weight on the institution’s ability to detect, respond to, and recover from ICT incidents. This includes evaluating the effectiveness of incident classification, escalation procedures, and post-incident reviews. DORA’s incident reporting requirements (Article 19) and the RTS on incident classification will be critical here—supervisors will assess whether institutions are not only reporting incidents but also learning from them to improve resilience.
Third-Party Risk Management and Resilience Testing
Financial entities increasingly rely on third-party ICT service providers, making this a critical area of focus. Supervisors will evaluate the institution’s due diligence processes, contractual safeguards, and monitoring of third-party risks. Additionally, the EBA will assess the results of resilience testing, including penetration tests, scenario analyses, and business continuity exercises. DORA’s third-party risk management requirements (Article 28) and the RTS on contractual arrangements will be key reference points.
How Incident Classification Feeds Into Your SREP Score
Incident classification is no longer a bureaucratic exercise—it is a direct input into your SREP score. Under DORA, financial entities must classify ICT-related incidents based on their impact and severity, using criteria defined in the EBA’s RTS on incident classification. The EBA’s 2026 SREP Guidance builds on this by linking incident classification to supervisory assessments of operational resilience.
The Link Between Incident Severity and SREP Scoring
Supervisors will evaluate two aspects of incident management:
- 1The accuracy of incident classification: Are incidents being classified correctly based on their impact on services, data integrity, and financial stability? Misclassification—whether over- or under-reporting—can lead to penalties in the SREP score.
- 2The effectiveness of incident response: How quickly and effectively does the institution detect, contain, and recover from incidents? Delays in response or inadequate remediation will negatively impact the SREP score.
For example, a "major" incident (as defined in DORA’s RTS) that results in significant service disruption or data loss will trigger a higher risk score if the institution’s response is deemed inadequate. Conversely, a well-managed incident—even if severe—can mitigate negative scoring if the institution demonstrates robust detection, containment, and recovery processes.
Post-Incident Reviews and Continuous Improvement
The EBA expects institutions to conduct thorough post-incident reviews and implement corrective actions. Supervisors will assess whether these reviews lead to tangible improvements in resilience. Institutions that fail to learn from incidents or repeat the same mistakes will face higher SREP scores, reflecting increased operational risk.
Third-Party Audit Quality and Supervisory Capital Adjustments
Third-party ICT service providers are a critical dependency for financial entities, and the EBA’s 2026 SREP Guidance reflects this by making third-party risk management a key determinant of ICT risk scoring. The quality of third-party audits—whether conducted by the institution or an external assessor—will directly influence supervisory capital adjustments.
Due Diligence and Contractual Safeguards
Supervisors will evaluate the institution’s due diligence processes for selecting and monitoring third-party providers. This includes assessing the adequacy of contractual safeguards, such as:
- Service level agreements (SLAs): Are SLAs aligned with the institution’s resilience requirements?
- Exit strategies: Does the institution have a viable plan to transition services in the event of a provider failure?
- Audit rights: Does the institution have the right to conduct or commission audits of the provider’s ICT controls?
DORA’s RTS on contractual arrangements (Article 28(5)) provides the baseline for these requirements. Institutions that fail to include these safeguards in their contracts will face higher SREP scores, reflecting increased third-party risk.
Audit Quality and Supervisory Scrutiny
The EBA will assess the quality of third-party audits, whether conducted by the institution or an external assessor. Key considerations include:
- Scope of the audit: Does the audit cover all critical ICT services and controls?
- Independence of the auditor: Is the auditor sufficiently independent to provide an objective assessment?
- Remediation of findings: Does the institution take prompt and effective action to address audit findings?
Institutions that rely on superficial or incomplete audits will face higher SREP scores, as supervisors will view this as a failure to adequately manage third-party risk. Conversely, institutions that demonstrate robust audit practices and proactive remediation will benefit from lower risk scores and potentially reduced capital requirements.
Resilience Testing Results as SREP Evidence
Resilience testing is a cornerstone of DORA’s operational resilience framework, and the EBA’s 2026 SREP Guidance places significant weight on the results of these tests. Supervisors will use resilience testing as evidence of the institution’s ability to withstand and recover from ICT disruptions.
Types of Resilience Testing
The EBA expects institutions to conduct a range of resilience tests, including:
- Penetration testing: Simulating cyberattacks to identify vulnerabilities in ICT systems.
- Scenario analysis: Assessing the institution’s ability to respond to hypothetical disruptions, such as a ransomware attack or a third-party failure.
- Business continuity exercises: Testing the institution’s ability to maintain critical functions during a disruption.
DORA’s requirements for resilience testing (Article 24) and the associated RTS will serve as the baseline for these assessments. Institutions must demonstrate that their testing is comprehensive, realistic, and aligned with their risk profile.
Supervisory Assessment of Testing Results
Supervisors will evaluate resilience testing based on three criteria:
- 1Coverage: Does the testing cover all critical ICT systems and services?
- 2Realism: Are the tests sufficiently realistic to identify genuine vulnerabilities?
- 3Remediation: Does the institution take prompt and effective action to address test findings?
Institutions that conduct superficial or infrequent testing will face higher SREP scores, as supervisors will view this as a failure to adequately prepare for disruptions. Conversely, institutions that demonstrate robust testing practices and proactive remediation will benefit from lower risk scores and potentially reduced capital requirements.
Practical Roadmap: Aligning Your DORA Register with SREP Expectations
To align with the EBA’s 2026 SREP Guidance, financial entities must take a proactive approach to ICT risk management. Below is a practical roadmap to ensure your DORA compliance efforts meet supervisory expectations:
Step 1: Review and Enhance ICT Governance
- Ensure that the board and senior management are actively engaged in ICT risk oversight.
- Align your ICT strategy with your business objectives and risk appetite.
- Document