France's Financial Markets Authority has published its first assessment of major information and communication technology incidents reported under the EU Digital Operational Resilience Act in 2025. Portfolio management companies submitted 47 initial notifications, of which 31 were confirmed as major incidents. Third party service providers caused 27, or 87%, while cyberattacks accounted for 22, or 71%, including 15 incidents involving data exfiltration and seven involving compromised company tools. The incidents disrupted critical activities including portfolio monitoring, order transmission, access to internal data and know your customer procedures. They affected portfolio managers of all sizes, ownership structures and investment strategies, underscoring the sector's reliance on interconnected technology providers. Implementation weaknesses also persisted during DORA's first year of application. Although reporting quality improved in the second half of 2025, a November self-assessment found that 23% of portfolio management companies had not established a DORA-compliant major incident reporting system. The authority expects third party technology risk to receive particular attention in firms' governance and internal controls and to remain a key supervisory theme. Portfolio managers reported difficulties securing DORA-compliant contractual terms from providers, particularly audit, testing and regulatory cooperation rights. The authority also expects more reports from crypto-asset service providers in 2026 as the number of authorized firms has increased following the end of France's transitional regime.