Skip to main content
Authority

European Banking Authority (EBA)

The EBA writes the technical rules that national supervisors apply. It does not supervise your bank, your payment institution or your e-money institution, with two exceptions: significant token issuers under MiCA, and critical ICT third-party providers under DORA, which it oversees jointly with ESMA and EIOPA. Its deadlines reach you through reporting frameworks and technical standards.

Checked by Remmert
5 min read

What is the EBA responsible for?

The EBA is an independent EU agency established by Regulation (EU) No 1093/2010 and operational since 2011. Its role is harmonised rules and supervisory convergence: it drafts regulatory and implementing technical standards for the European Commission to adopt, issues guidelines and opinions, answers questions through a public Q&A tool, and coordinates the EU-wide stress test. François-Louis Michaud became Chair on 16 April 2026, having previously been the EBA's Executive Director; the Executive Director post is vacant, with Jonathan Overett Somnier acting.

Last updated: 17 August 2026. First version of this page, written after the EBA's AML/CFT mandate transferred to AMLA and while the PSD3/PSR file is still in the legislative pipeline.

Key facts

Does the EBA supervise anyone directly?

Yes, in two narrow places. Under MiCA, the EBA takes over supervision of issuers of significant asset-referenced tokens from the home national authority, and supervises significant e-money token issuers jointly with national authorities, chairing a supervisory college for each. Under DORA, the EBA is one of three Lead Overseers of critical ICT third-party providers; the three authorities jointly designated the first list of critical providers on 18 November 2025.

Everything else runs through national competent authorities and, for euro-area banks that meet the SSM significance threshold, the ECB.

Which regulations does the EBA develop?

RegulationWhat the EBA producesStatus as at 17 Aug 2026

The AML handover is the change most often missed: if you are working from EBA AML guidance, it is still valid, but its author has changed and its successor will come from Frankfurt.

What does the EBA publish, and how often?

Consultation papers, final draft technical standards, guidelines, opinions and Q&As appear continuously. The Risk Dashboard is quarterly: the Q1 2026 edition was published in June 2026, with the Q2 2026 edition due 17 September 2026, and an ESG Risk Dashboard runs alongside it (latest 6 August 2026). The Work Programme and Annual Report are annual. Reporting frameworks are released in numbered versions, each with its own application date. The EU-wide stress test is biennial; the next is 2027, with draft methodology and templates already published on 11 June 2026.

Two searchable tools carry most of the practical value: the Single Rulebook Q&A, showing more than two thousand published answers, and the Interactive Single Rulebook, indexing 3,561 documents across thirteen legal acts (both counted on 17 August 2026).

Which deadlines does the EBA set?

2026

  1. 17 September 2026Upcoming

    Q2 2026 Risk Dashboard published

  2. 24 September 2026Upcoming

    Public hearing on the DGSD3 consultations

  3. 28 September 2026Upcoming

    MiCA fines-methodology consultation closes

  4. 23 October 2026Upcoming

    Four DGSD3 consultations close

No fixed date

  1. Q4 2026Expected

    Reporting Framework 4.3 expected to apply

  2. December 2026Expected

    First reference date for the AMLA risk-assessment reporting component

  3. March 2027Expected

    First reference date for third-country branch reporting

  4. 14 Dec 2026 (indicative)Expected

    European Parliament first-reading vote on PSD3 / PSR

  5. 2027Expected

    Next EU-wide stress test

Can the EBA fine anyone?

Not banks. The EBA has no power to fine a credit institution, payment institution or e-money institution. Its instrument against supervisors is the breach of Union law procedure under Article 17 of Regulation 1093/2010: it investigates whether a national authority or the ECB has failed to apply EU law, issues a recommendation, and can escalate to the European Commission. It can also impose binding mediation between national authorities. The one exception is DORA, where as Lead Overseer it can impose periodic penalty payments directly on designated critical ICT third-party providers.

This distinction is practically important when reading EBA output: a guideline is not enforced by the EBA, it is enforced by DNB, BaFin or the FMA, and how strictly can differ between them.

What changes for a mid-sized institution?

Proportionality in EBA output runs through the CRR category of small and non-complex institutions, defined in Article 4(1)(145) of Regulation 575/2013. EBA guidelines routinely scale requirements to that category, and the 2026 reporting-simplification consultation is explicitly aimed at reducing the reporting burden on smaller firms. The 2025 EU-wide stress test covered 64 banks, about three quarters of EU banking assets, which is to say, if you are mid-sized, you are outside the exercise but inside the standards it produces.

What we do with this

The EBA's output is where a lot of obligations begin, months or years before they appear in a national supervisor's letter. We track consultations, final standards, reporting framework versions and Q&As, and date each change, so that a rule can be traced from EBA draft to national application.

For an institution, the useful cut is not "what did the EBA publish this week" but "which of these will apply to us, and when", which is what our calendar and scope check answer.

Regulations

  • Markets in Crypto-Assets (MiCA)

    MiCA is Regulation (EU) 2023/1114. Full application began on 30 December 2024 and the EU-wide transitional period expired on 1 July 2026, so there is now no grandfathering anywhere in the EEA. Around 325 crypto-asset service providers are authorised. Not one asset-referenced token issuer appears on ESMA's register.

    NextMiCA review consultation closes

    Checked

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    NextNext register of information cycle, reference date expected 31 December 2026

    Checked

  • Anti-Money Laundering Regulation (AMLR)

    The AMLR is Regulation (EU) 2024/1624. It applies from 10 July 2027 and is directly applicable, so from that date customer due diligence, beneficial ownership, reporting and internal controls come from EU law rather than national statute. Cash payments for goods and services are capped at €10,000. Football clubs and agents follow on 10 July 2029.

    NextAMLR applies (Art. 90) and the AMLD6 transposition deadline. References to Directive (EU) 2015/849 are construed as references to the AMLR and AMLD6, per the correlation table in Annex VI (Art. 89); the repeal itself sits in AMLD6

    Checked