The Portuguese Securities Commission has launched a consultation on draft rules that would operationalize Digital Operational Resilience Act reporting for entities under its prudential supervision. The proposal covers mandatory reporting of severe information and communication technology incidents, voluntary notification of significant cyberthreats and information on contractual arrangements with third party technology service providers. It specifies reporting channels, file formats and procedures rather than creating parallel DORA obligations. Severe incidents would require initial, intermediate and final reports through the commission’s electronic portal, with updates when material changes or relevant new information arise. Complete registers of technology service contracts would be due annually by Feb. 28, based on information as of Dec. 31, and firms would have to correct identified errors. A complete register requested by the commission would be due within five business days. Firms included in consolidated reporting to another competent authority would not need to file separately, but would have to identify the reporting entity and authority and retain individual information for supervisory requests. Planned technology service contracts supporting critical or important functions would require at least 30 calendar days’ notice. Trading venues, central counterparties and central securities depositories would face a 60 day notice period and would have to provide the management body’s approval decision. Firms would also have to notify the commission, with reasons, as soon as a function is designated critical or important. As drafted, the regulation would take effect on the day after publication.
2026-09-15Portuguese Securities Commission (CMVM)
Portuguese Securities Commission launches consultation on DORA reporting procedures
The Portuguese Securities Commission is consulting on procedures for DORA reporting by entities under its prudential supervision, covering severe technology incidents, significant cyberthreats and third party technology contracts. Contract registers would be due annually by Feb. 28, while planned contracts supporting critical or important functions would require 30 days’ notice, rising to 60 days for specified market infrastructures.