EBA consolidated amending Guidelines on ICT and security risk management (EBA/GL/2025/02)
Tag: S-2026-05-19-eba-ict-security-guidelines Type: report (guidelines — consolidated version) Author(s): European Banking Authority Date of source: 2026-05-19 (consolidated version published; EBA/GL/2025/02 amending EBA/GL/2019/04) Date ingested: 2026-06-03 Authority weight: high — primary EU prudential supervisor; binding-by-comply-or-explain guidelines. Raw file: S-2026-05-19-eba-ict-security-guidelines.md. External URL: https://www.eba.europa.eu/publications-and-media/press-releases/eba-amends-its-guidelines-ict-and-security-risk-management-measures-context-dora-application
What it claims
The EBA published a consolidated version of its amending Guidelines on ICT and security risk management measures (consolidated PDF dated 19 May 2026; EBA/GL/2025/02 amending the original EBA/GL/2019/04). The EBA narrowed the scope of these existing Guidelines because harmonised ICT risk-management requirements under the Digital Operational Resilience Act (DORA) have applied since 17 January 2025. The stated aim is to simplify the ICT risk-management framework and provide legal clarity to the market by removing overlap with DORA. The Guidelines continue to require that financial institutions integrate ICT and security risk management into their governance and risk-management frameworks, with clearly assigned roles and responsibilities and board-level oversight of ICT and security risk.
This is presented as a simplification / alignment exercise rather than the introduction of new substantive obligations: the binding ICT requirements now sit primarily in DORA and its Regulatory Technical Standards, with the residual EBA Guidelines covering institutions and areas not fully absorbed by the DORA regime.
Notable quotes
“The EBA narrowed down the scope of its existing Guidelines on ICT and security risk management measures, due to the application of harmonised ICT risk management requirements under the Digital Operational Resilience Act (DORA) from 17 January 2025.” — EBA, as reported in search-derived press-release excerpt (full press release not retrieved verbatim this run)
What’s speculative vs. asserted
- Asserted: the consolidated version is dated 19 May 2026; the reference EBA/GL/2025/02 amends EBA/GL/2019/04; the scope narrowing is driven by DORA’s 17 January 2025 application; the stated aims are simplification and legal clarity; the retained governance-integration and board-oversight expectations.
- Speculative / not confirmed this run: the precise list of provisions retained vs. removed; the exact application/transition date of the amended Guidelines; how national competent authorities will treat the residual scope.
Topics this feeds
Open questions raised
- Which specific provisions of EBA/GL/2019/04 are retained versus superseded by DORA, and for which institution types.
- The application date and any transition arrangements for the amended Guidelines.
Ingestion note
Search-derived stub. The EBA publications listing was fetched directly (WebFetch) and surfaced the consolidated PDF (dated 19 May 2026); the substantive detail was confirmed via WebSearch on eba.europa.eu and the EBA press release, but the consolidated guideline PDF itself was not retrieved and parsed this run. Confirm provision-level detail against the published consolidated text before relying on this page for client deliverables.