The Dutch Authority for the Financial Markets has published its seventh update on the Digital Operational Resilience Act (DORA), reporting substantial improvement in firms’ registers of information while identifying gaps in required policies, procedures and incident reporting. The share of registers approved by the European Banking Authority rose from 40% in 2025 to 94% in 2026, although firms should continue to review the quality of registers and their underlying data. Supervisory reviews found that some firms lack mandatory policy documents and procedures or have frameworks that do not fully align with DORA. Firms must ensure their information and communications technology risk management arrangements remain current and work in practice, including where group-level documentation is used, as the licensed entity remains responsible for compliance. The authority also noted fewer DORA incident notifications than expected and reminded firms to detect, classify and, where required, report incidents within statutory deadlines. Insurance intermediaries should assess recent Q&As clarifying how DORA thresholds apply when insurance distribution is a limited part of their activities and within group structures.