AFM DORA Update 7: Progress Made, Gaps Remain
The Dutch Authority for the Financial Markets (AFM) published DORA Update 7 on 6 August 2026, and the picture it paints is mixed. Registry approval rates have surged dramatically, which signals that the sector has gotten to grips with the technical formatting requirements. At the same time, the AFM is explicit that several compliance fundamentals are still falling short, including mandatory policy documentation, incident classification, and the timely filing of incident reports. For accounting firms, auditors, and CFOs serving Dutch-supervised entities that hold or transact in digital assets, this update is a direct call to review current DORA readiness and close any remaining gaps before supervisory attention intensifies.
What DORA Requires and Why It Matters for Digital Asset Firms
The Digital Operational Resilience Act (DORA), which applies across the EU, establishes binding requirements for ICT risk management, incident reporting, third-party risk oversight, and digital operational resilience testing. It entered into force in January 2025 and applies to a wide range of regulated financial entities, including crypto asset service providers (CASPs) licensed under MiCA.
For firms operating in the digital asset space, DORA is not a peripheral concern. ICT systems underpin every function: custody, trading, settlement, client onboarding, and transaction monitoring. A failure in any of these systems can simultaneously trigger a DORA incident report, a potential AML breach if monitoring is disrupted, and a financial reporting issue if asset valuations or ledger records are affected. The intersection is direct, and the AFM's latest supervisory observations make clear that regulators are now actively checking whether firms have connected those dots.
The MiCA-DORA overlap for CASPs
CASPs authorised under MiCA in the Netherlands are subject to both regulatory regimes. MiCA sets the licensing and conduct requirements; DORA sets the operational resilience floor. A CASP that holds a MiCA licence but has not embedded DORA-compliant ICT risk management into its operating procedures is simultaneously non-compliant with both frameworks, because MiCA requires firms to have adequate internal controls and DORA specifies what "adequate" means in the ICT context. CFOs and compliance leads at CASPs should treat these as a unified compliance workstream rather than two separate projects.
The Registry Approval Jump: What Changed and What It Means
The AFM's most striking data point in Update 7 is the increase in EBA-approved ICT third-party service provider registers. In 2025, only 40% of submitted registers received approval. By 2026, that figure had risen to 94%. The AFM attributes the improvement to firms gaining a clearer understanding of how to complete the register and of the required format, a practical observation that suggests early failures were largely procedural rather than substantive.
Why quality still needs attention
A 94% approval rate is not a clean bill of health. The AFM explicitly reminds firms that achieving the correct format is not the same as ensuring the underlying data is accurate, complete, and current. The register records the firm's material dependencies on external ICT providers, and its value to supervisors is only as good as the data it contains. For digital asset businesses, this is especially relevant: the ICT supply chain often includes blockchain node operators, custodial infrastructure providers, smart contract auditors, and cloud services, any or all of which may qualify as material third parties under DORA's criteria.
Firms should treat the register not as a one-time submission but as a live document, reviewed at least annually or whenever a material ICT relationship changes. For audit teams, this creates a new verification point: confirming that the register reflects the firm's actual operational dependencies, not just those that were in place at the time of the original submission.
Policy and Procedure Gaps: The AFM's Core Concern
Beyond the registry, the AFM's supervisory examinations have found that not all firms hold every mandatory policy document required by DORA, and that some policies which do exist do not fully align with the regulation's requirements. The AFM calls this out directly, asking firms to check whether their ICT risk management framework, policies, and procedures are both current and reflective of actual practice.
Group-level policies are not a substitute for individual compliance
One specific scenario the AFM highlights is firms that rely on policies drafted at group level, typically by a parent company or holding structure. The AFM is clear that this practice is permissible, but it does not transfer or dilute the licensed entity's own compliance responsibility. The Dutch-authorised entity remains fully accountable for ensuring that every DORA requirement is covered in whichever policy documents it relies on. If a group policy was drafted for a different jurisdiction or a broader entity type, it may contain gaps that are not obvious without a deliberate line-by-line comparison against the DORA text.
For accounting firms advising group structures with Dutch-regulated subsidiaries, this is a material advisory point. The audit or compliance review cannot simply confirm that a group policy exists; it must confirm that the group policy is sufficient for the Dutch entity's specific obligations. Keeping structured records of that review, with version control and sign-off trails, is precisely the kind of documentation that supervisors expect to see during an examination. Robust crypto bookkeeping software and document management systems are part of the infrastructure that supports that trail for digital asset entities specifically.
Incident Reporting: Still Below Expectations
The AFM notes that the volume of DORA incident reports received remains lower than anticipated given the number of firms in scope. This is a significant observation. Under DORA, firms must detect, classify, and report major ICT-related incidents within defined legal timeframes. A low filing rate is not necessarily evidence of a resilient sector; it may reflect under-detection, misclassification, or a lack of internal processes for escalating incidents to the point where a regulatory filing is triggered.
What counts as a reportable incident
DORA's incident classification criteria cover a range of factors including the number of clients affected, the duration of the disruption, the geographic spread, and the economic impact. For digital asset firms, incidents that might seem like routine technical outages can meet these thresholds quickly, particularly if they affect transaction execution, custody access, or client-facing reporting systems. A trading platform going offline for several hours during a high-volatility market period, for example, could simultaneously affect a large number of clients, have material economic impact, and disrupt services that are not easily substituted, all DORA classification factors.
The practical implication is that firms need documented, tested incident classification procedures that are actually used by first-line operational staff, not just drafted and filed. The AFM's observation about low filing volumes suggests that in at least some cases, the classification step is not happening correctly or at all. For CFOs, this is also a financial reporting consideration: an unreported DORA incident that later comes to light in a supervisory review can give rise to regulatory sanctions, which must be disclosed and may affect the firm's financial statements. Reliable digital asset accounting software that captures operational event logs can help firms establish the evidence trail needed for accurate and timely classification.
For further context on how undetected operational or financial crime incidents can have cascading compliance consequences, our earlier analysis of the AML and sanctions implications of the Lazarus Group Ronin Bridge theft illustrates what happens when ICT vulnerabilities and compliance monitoring gaps coincide.
Threshold Calculations: New Clarity for Insurance Intermediaries
The AFM's update also addresses a specific technical question that has arisen for insurance intermediaries for which insurance mediation is a minor part of total business activity. Updated guidance now clarifies how DORA's threshold calculations should be applied in those cases, as well as how thresholds should be calculated within group structures. The AFM asks all firms in scope to check whether the recently published Q&As affect their own threshold determinations.
Relevance for multi-activity digital asset groups
While this guidance is framed around insurance intermediaries, the underlying principle is relevant to any group structure where the regulated Dutch entity represents only part of a wider business. Digital asset groups that hold a Dutch MiCA or other financial licence alongside unregulated activities need to apply DORA's thresholds to the licensed entity specifically, and the new Q&A clarifications may affect how that calculation is structured. Legal and compliance advisers should review the updated AFM Q&As and document any changes to the firm's threshold assessment.
Practical Steps for Firms and Their Advisers
The AFM's DORA Update 7 effectively provides a supervisory checklist. Accounting firms, auditors, and in-house compliance teams advising Dutch-regulated entities, including those in the digital asset space, should work through the following actions based directly on the AFM's stated concerns.
Registry review
Confirm the ICT third-party register is current, that all material providers are included, and that the data quality is sufficient to support a supervisory inquiry. This is not a one-and-done task; assign a periodic review cycle and document it.
Policy gap analysis
Map every DORA requirement against the firm's existing policy documents. Where a group-level policy is relied upon, document explicitly which DORA articles it covers and which, if any, require a local supplement. Engage with how the EU's broader regulatory environment intersects with these obligations: our coverage of how the EU's 21st Russia sanctions package affects crypto firms shows how layered EU obligations can compound for firms that are not monitoring developments across multiple regulatory workstreams.
Incident management process test
Run a tabletop exercise or structured walkthrough of the incident detection, classification, and notification process. Confirm that operational staff know what triggers a DORA classification review and that the escalation path to regulatory filing is documented, assigned, and tested.
Threshold recalculation
Review the AFM's updated Q&As on threshold calculations, particularly if the firm operates within a group structure or if insurance mediation (or any other regulated activity) is a secondary part of its business. Update the threshold assessment documentation accordingly.
Frequently Asked Questions
Does DORA apply to crypto asset service providers in the Netherlands?
Yes. CASPs authorised under MiCA in the Netherlands fall within DORA's scope as regulated financial entities. They must meet DORA's requirements on ICT risk management, incident reporting, third-party oversight, and resilience testing alongside their MiCA obligations.
What does the AFM's 94% registry approval rate actually mean for my firm?
It means the sector has improved its ability to submit registers in the correct format, but the AFM is clear that format compliance is not the same as data quality. Firms should verify that the underlying information in their register is accurate and complete, not just that the submission was accepted.
Our firm uses group-level DORA policies. Is that acceptable?
Group-level policies are permitted, but the Dutch-licensed entity remains solely responsible for ensuring that every DORA requirement is fully addressed. If a group policy has gaps relative to DORA's requirements for the Dutch entity specifically, the firm is non-compliant regardless of what the group document says. A gap analysis against the regulation is essential.
What are the consequences of failing to report a DORA incident on time?
Failure to detect, classify, or report a major ICT incident within DORA's legal timeframes is a regulatory breach. The AFM can take supervisory measures, which may include public enforcement action. Such sanctions must typically be disclosed and can affect the firm's financial statements and licence standing.
How often should a firm review its DORA compliance status?
The AFM recommends periodic self-assessments to check whether the firm continues to meet all DORA requirements. There is no single mandated frequency, but given the rate at which ICT environments and regulatory Q&As are evolving, a quarterly review cycle aligned with the firm's risk management calendar is a reasonable minimum. Any material change to ICT infrastructure or third-party relationships should also trigger an immediate review.
