2026: oversight moves from designation to examination. Joint examination teams were established through end-2025, annual oversight plans were drawn up per provider, initial examination activities are running during 2026, and oversight fee collection has begun.
March 2026: the register of information becomes a real annual report. The reference date moved from 31 March 2025, which was a one-off designation-driven collection, to 31 December 2025 with fixed national windows. In April 2026 the EBA layered additional data-quality checks on the consolidation-structure and ICT-provider forms, on top of the standard validation rules, a direct response to first-cycle data quality.
13 April 2026: DNB changes how incident reports are processed. Reports are now technically validated on submission and return either warnings, correctable in a later report, or errors, which require correction and resubmission through MijnDNB.
11 June 2026: the first published Dutch supervisory findings. The AFM examined ICT risk management at trading venues and found gap analyses were "often too global", leaving requirements unaddressed; that security monitoring, access control, logging, emergency changes and continuity management needed work; that policies and procedures were not clearly distinguished; and that DORA policies were applied inconsistently to intragroup ICT services. The AFM's position: the foundation is generally present, but assessments must be more detailed and periodic, and controls must be demonstrated in operation, not only in documents.
DORA was not touched by the Digital Omnibus. The November 2025 package and the Commission's proposal of 20 January 2026, COM(2026) 13 final, amend the NIS2 Directive, not DORA. As at 17 August 2026 no legislative proposal amending Regulation (EU) 2022/2554 had been tabled. The only live review is the narrow Article 58(3) question of whether statutory auditors should be brought into a strengthened resilience regime, consulted from 7 November 2025 to 17 January 2026.