EBA Publishes Final Guidelines on ICT and Security Risk Management for EU Banks
The European Banking Authority (EBA) has issued final guidelines on ICT and security risk management, setting out requirements for banks to strengthen their resilience against cyber threats and operational disruptions. The guidelines, effective from 1 January 2027, mandate enhanced governance, risk assessment, and incident reporting frameworks.
Related updates
EBA E-mail Alert 16 July 2026: Key Regulatory Updates
The European Banking Authority (EBA) issued its e-mail alert on 16 July 2026, summarizing recent regulatory developments. The alert covers new guidelines, consultations, and other updates relevant to compliance officers in the financial sector.
16 Jul 2026
The EBA consults on revised technical standards for the reclassification of investment firms as credit institutions
EBA consults on revised rules for reclassifying investment firms: The EBA has launched a consultation on revised RTS governing when investment firms should be reclassified as credit institutions. The proposals align the framework with CRR3 and CRD6 and aim to ensure a consistent application of reclassification criteria across the EU.
25 Aug 2026
The EBA consults on draft technical standards on institutions’ operational risk management
EBA consults on new operational risk management standards: The EBA has launched a consultation on draft RTS establishing harmonised requirements for institutions' operational risk governance, processes, data and assessment systems under CRR3. The proposals include proportionality measures for smaller institutions, with the consultation open until 31 December 2026
26 Aug 2026

