Norsk Lovtidend · 24 Aug 2026 · 5 vistas
Norway extends DORA digital resilience rules to more financial firms
Por FactBox Admin

Norway is widening the scope of the EU’s Digital Operational Resilience Act (DORA) to cover a broader set of financial firms, in a regulation adopted by the Ministry of Finance on 20 August 2026 and published in Norsk Lovtidend on 24 August 2026. The amendment extends the digital operational resilience framework to financing companies, real-estate brokerage firms, debt-collection firms and the Norsk naturskadepool, and assigns Norges Bank the role of TLPT cyber team. The rules enter into force on 1 September 2026.
The change amends the DORA regulation of 24 June 2025 (nr. 1296), issued under the DORA Act of 27 May 2025 (nr. 18). It implements the EU DORA Regulation (Regulation (EU) 2022/2554), incorporated into the EEA Agreement as Annex IX item 31q, and aligns Norwegian rules with the EU framework for digital operational resilience in the financial sector.
Extended scope and risk management
The new Chapter 2 applies the DORA Regulation to financing companies, real-estate brokerage firms, debt-collection firms and the Norsk naturskadepool, with the adaptations set out in the regulation. The definitions and proportionality provisions of Articles 3 and 4 apply correspondingly.
- Financing companies must follow the governance and risk-management framework in Articles 5 to 15.
- Real-estate brokerage firms, debt-collection firms and the Norsk naturskadepool apply the simplified risk-management framework in Article 16.
- ICT incident handling (Article 17) and classification and reporting (Articles 18–19) apply, with reporting for real-estate brokerage firms limited to incidents linked to the settlement function.
- ICT third-party risk management (Articles 28–30) applies, with the register of ICT service agreements kept at entity level only.
TLPT and the role of Norges Bank
A new Chapter 3 sets out the framework for threat-led penetration testing (TLPT). Finanstilsynet decides which firms must carry out TLPT under Article 26 and how often, after giving Norges Bank the opportunity to comment.
- Norges Bank approves the functions to be tested and acts as the TLPT cyber team (TCT), coordinating test execution.
- Norges Bank issues the attestation confirming completion of a TLPT test under Article 26(7).
- Finanstilsynet follows up on test findings and the remediation plan.
- Norges Bank’s TLPT costs are distributed among the firms required to test, based on its relative use of resources and rules it sets by regulation.
Related changes and entry into force
The amendment also updates the financial undertakings regulation of 9 December 2016 (nr. 1502) and the payment-services regulation of 15 February 2019 (nr. 152), aligning incident-notification duties with Regulation (EU) 2022/2554 Article 23. The ICT regulation of 21 May 2003 (nr. 630) is repealed. The regulation takes effect on 1 September 2026.
For the wider financial sector, the change means that firms outside the core banking and insurance perimeter now face the same digital resilience, incident-reporting and third-party risk obligations, with Norges Bank taking a central supervisory role in penetration testing.
Source: Norsk Lovtidend, Avd. I, 24 August 2026, nr. 1657 (official reference: 20.08.2026 nr. 1657).