Summary
- ESMA plans continued DORA compliance work across its supervisory mandates in 2027.
- The regulator will participate in oversight of critical ICT third-party providers with the other European Supervisory Authorities.
- ESMA also intends to strengthen its own cybersecurity and technology capabilities.
Cyber resilience is moving further into the routine machinery of European financial supervision, with the European Securities and Markets Authority setting out plans for DORA compliance, third-party technology oversight, and stronger internal cybersecurity capabilities during 2027.
ESMA published its annual work programme on 28 September, outlining priorities across market supervision, resilience, data, artificial intelligence, and digital finance.
Among the cyber-specific measures, ESMA says it will continue monitoring and promoting compliance with the Digital Operational Resilience Act across its supervisory mandates. It will also work with the other European Supervisory Authorities on oversight activities concerning critical ICT third-party service providers.
That oversight function is one of DORA’s most consequential structural changes. Financial institutions have long depended on cloud, software, communications, managed services, and other technology providers, but concentration among major suppliers means disruption at a single provider can affect multiple regulated organisations simultaneously.
DORA brings parts of that dependency inside a more formal supervisory framework. The objective is not to eliminate outsourcing or centralised technology platforms, but to create clearer expectations around risk management, incident reporting, testing, contracts, and oversight of critical providers.
ESMA’s programme suggests that the regime is now entering a more operational phase. Regulatory implementation work remains important, but supervisors increasingly need to assess whether institutions and suppliers can demonstrate resilience rather than merely produce compliant documentation.
The authority is also planning to strengthen its own cybersecurity capabilities while expanding its use of data and artificial intelligence in supervision. That combination creates a parallel governance requirement: regulators adopting more advanced analytics and AI tools must manage the security, integrity, and accountability of their own technology estates while scrutinising similar risks in the organisations they supervise.
Other parts of the programme reinforce that shift towards operational dependency. ESMA will review clearing-market resilience, continue work with national competent authorities, supervise expanding categories of market participants, and support wider EU efforts to modernise market infrastructure.
Financial-sector resilience increasingly depends on systems that cross organisational and national boundaries. Trading venues, clearing services, market-data platforms, cloud providers, identity systems, and outsourced technology services can sit in the path of critical market functions without being owned directly by the financial institution exposed to their failure.
The challenge for DORA supervision in 2027 will therefore be less about whether organisations have identified third-party risk in principle and more about how that risk is evidenced, tested, governed, and remediated across real supplier relationships.
ESMA’s programme does not announce a specific enforcement action or new cyber rule. It instead shows how cybersecurity and operational resilience are being absorbed into mainstream European financial supervision, where technology dependency is treated as part of financial stability and market integrity rather than as a separate IT problem.





