DORA incident reporting has become more specific

New joint instructions from the European supervisory authorities say that when a major ICT incident originates with a third-party provider, the report should identify that provider by full legal name, LEI or EUID, and code type, separated by semicolons.

I would treat this as a supplier-readiness requirement. A SaaS vendor serving European financial firms should keep those identifiers, a named incident contact and defensible downtime estimates ready. Your customer's regulator-facing clock will not wait for procurement to find them.

Next
Next

Sweden’s standard employer contribution in 2026 is 31.42% of gross salary and benefits for most employees.