Operational Resilience & Critical Infrastructure

W3
The rules requiring firms and their critical suppliers to keep payments running — DORA, FCA/PRA resilience and the critical-third-party regime.
155Jurisdictions
90Moved this cycle
681Sourced findings
W3Module

Every jurisdiction World Payments Monitor tracks for W3, with the standing position recorded in the current weekly cycle. Each entry links to the full module on that jurisdiction’s page, where the sourced findings and evidence sit.

Africa

AFRHigh4 sourced findings

There is no single DORA-equivalent across the bloc; resilience is built into national payments vision documents and cyber directives. SARB has issued a directive on cybersecurity and cyber-resilience within the national payment system. Nigeria's Payments… Full module →

Algeria

DZHigh5 sourced findings

Algeria adopted its first comprehensive cybersecurity governance architecture in 2025-2026, designating financial services as critical information infrastructure with a 5-day breach-reporting window.

Argentina

ARConfirmed4 sourced findings

BCRA operational-resilience and cyber rules apply on a functional basis to banks, PSPs (digital wallets, aggregators, facilitators) and systemically important payment systems. Core instruments are the IT/information-security risk standard (Com. "A" 7724… Full module →

Asia-Pacific

APACAssessed3 sourced findings

APAC operational-resilience obligations sit within national frameworks rather than a single regime like DORA. Hong Kong's critical-infrastructure / CCS regime carries real-time incident reporting and severe fines; India imposes data-localisation and… Full module →

Australia

AUConfirmed4 sourced findings

Operational resilience for APRA-regulated entities (incl. ADIs/banks providing payments) is governed by Prudential Standard CPS 230 Operational Risk Management, in force 1 July 2025, replacing CPS 231 (Outsourcing) and CPS 232 (Business Continuity… Full module →

Austria

ATConfirmed5 sourced findings

DORA has applied directly in Austria since 17 January 2025, binding on all FMA-supervised entities including small payment and e-money institutions, and is enforced nationally via the DORA Enforcement Act. The FMA's Conduct and IT Risk Supervision division… Full module →

Bangladesh

BDHigh4 sourced findings

Bangladesh Bank has substantially escalated operational-resilience regulation in 2025-2026, moving from the long-standing ICT Security Guideline (v4.0, 2023) to a first-ever sector-wide, technology-neutral Cybersecurity Framework, Version 1.0 (2026)… Full module →

Belgium

BEConfirmed5 sourced findings

DORA has applied since 17 January 2025 across Belgian financial entities including PIs/EMIs, with NBB and FSMA as competent authorities. NBB runs TIBER-BE and requires ICT incident reporting via OneGate; SWIFT oversight is being strengthened with NBB as lead… Full module →

Brazil

BRConfirmed4 sourced findings

Operational resilience is governed by CMN Resolution 4.893/2021 (financial institutions) and BCB Resolution 85/2021 (payment institutions), effective from 2021, which mandate cybersecurity policies, incident response, business-continuity testing, and rules… Full module →

Bulgaria

BGHigh5 sourced findings

DORA has applied directly in Bulgaria since 17 January 2025, with BNB and FSC as enforcing authorities. Bulgaria faced EU infringement action for incomplete transposition of enabling national legislation. BNB is actively auditing bank-sector DORA-preparedness… Full module →

Cambodia

KHHigh5 sourced findings

NBC has run a dedicated Technology Risk Management (TRM) framework since July 2019, refreshed as the Technology and Cyber Risk Management Guidelines in 2026, covering cybersecurity management, IT services outsourcing, business continuity management and… Full module →

Cameroon

CMHigh6 sourced findings

Operational resilience obligations are distributed across COBAC's PSP operational-requirements regulation, the national Cybersecurity Law, and a CEMAC-wide technical-standardisation body (CORENOFI) which is compelling ISO 20022 migration by November 2025… Full module →

Canada

CAConfirmed3 sourced findings

Operational resilience for non-bank PSPs runs through the RPAA's operational-risk-management and incident-response obligations (in force September 8, 2025), supervised by the Bank of Canada. Systemic payment infrastructure (Lynx) is designated under the… Full module →

Canada – Alberta

CA-ABConfirmed4 sourced findings

Operational resilience for Alberta-touching non-bank PSPs is governed by the RPAA's operational risk management and incident response framework, in force since September 8, 2025, with material-incident notification and annual reporting obligations.

Canada – British Columbia

CA-BCConfirmed5 sourced findings

Operational resilience for BC-serving PSPs is governed federally through the RPAA's operational risk management and incident response framework (in force since September 8, 2025), with a 48-hour material-incident notification duty to the Bank of Canada and… Full module →

Canada – New Brunswick

CA-NBConfirmed5 sourced findings

Operational resilience for retail payments in NB (as elsewhere in Canada) is governed federally by the RPAA's risk management and incident response (RMIR) framework administered by the Bank of Canada, which prescribes written risk-management frameworks… Full module →

Canada – Ontario

CA-ONConfirmed5 sourced findings

The RPAA's operational risk-management framework (in force since September 8, 2025) requires PSPs to manage risks that could reduce, deteriorate or break down retail payment activities; OSFI's 2025-26 Annual Risk Outlook flags state-actor threats; the… Full module →

Canada – Quebec

CA-QCConfirmed5 sourced findings

The Bank of Canada's RPAA-based Operational Risk and Incident Response supervisory guideline governs PSP operational resilience, with a binding 48-hour material-incident notification rule and mandatory third-party risk management, in force alongside… Full module →

Chile

CLConfirmed4 sourced findings

Two regimes apply: sectoral CMF cybersecurity/operational-resilience rules in the RAN (20-7 outsourcing, 20-8 operational-incident information, 20-9 business continuity, 20-10 information security & cybersecurity) for banks, their support companies, and card… Full module →

China (mainland)

CNConfirmed5 sourced findings

Operational resilience sits within China's cyber/data-security stack: amended Cybersecurity Law (in force 1 Jan 2026) tightens CIIO obligations; Network Data Security Regulations and sector-specific financial data-security measures create graded… Full module →

Colombia

COHigh4 sourced findings

Colombia's operational-resilience/data-sharing regime is anchored by the mandatory Sistema de Finanzas Abiertas (Decreto 0368 de 2026, signed 7 Apr 2026, amending Decreto 2555/2010 per Art. 89 Ley 2294/2023), superseding the voluntary Decreto 1297/2022 scheme… Full module →

Costa Rica

CRHigh4 sourced findings

Costa Rica's operational-resilience posture was shaped decisively by the April 2022 Conti/Hive ransomware campaign against government systems, which triggered a national state of emergency. IT/outsourcing risk management for the regulated financial sector… Full module →

Croatia

HRHigh5 sourced findings

DORA (Regulation (EU) 2022/2554) entered into application EU-wide from 17 January 2025, with HNB and HANFA jointly coordinating implementation for Croatian financial entities. Croatia faces above-average third-party ICT dependency and limited specialist… Full module →

Curaçao

CWHigh4 sourced findings

CBCS maintains a dedicated IT, Cyber & Operational Risk supervisory pillar (IT Governance, Business Continuity Management, Information Security Management provisions) and has flagged fintech/cyber risk as a priority in its 2026-2028 Research Agenda… Full module →

Cyprus

CYConfirmed3 sourced findings

Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT… Full module →

Czech Republic

CZConfirmed5 sourced findings

DORA (Regulation (EU) 2022/2554) became fully applicable in the Czech Republic on 17 January 2025, transposed via the Act on the Digitalisation of the Financial Market (Act No. 31/2025 Coll.), with the CNB as DORA supervisory/sanctioning authority working… Full module →

Denmark

DKConfirmed4 sourced findings

Operational resilience is now governed by DORA, with Finanstilsynet as the single competent authority for credit institutions, PIs, EMIs, investment firms, insurers and MiCA CASPs. Danmarks Nationalbank separately conducts financial-infrastructure oversight… Full module →

Dominican Republic

DOHigh4 sourced findings

Operational resilience is set by SIPARD's minimum technological requirements built on CPMI-IOSCO PFMI; BCRD's LBTR (since 2008) underpins systemic-risk reduction; SB began a structured cybersecurity dialogue in 2026.

Ecuador

ECConfirmed5 sourced findings

Operational resilience is governed by the SB's Norma de Control para la Gestión del Riesgo Operativo, mandating ISO 22301-based BCM and ISO 27000-based information-security management, layered with BCE cybersecurity standards for the new instant-payments… Full module →

Egypt

EGHigh4 sourced findings

Operational resilience is anchored by the CBE's Financial Cybersecurity Framework (the first such sectoral framework in Egypt) plus a dedicated CBE cybersecurity sector and the country's first financial-sector CERT. Outsourcing of services and data hosting by… Full module →

Estonia

EEHigh5 sourced findings

DORA applies directly in Estonia since 17 January 2025 with Finantsinspektsioon as NCA across banks, PIs, EMIs and CASPs.

European Economic Area

EEAConfirmed4 sourced findings

The EEA operational-resilience regime for payments is the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which entered into force 16 January 2023 and applied in full from 17 January 2025 with no transition period. DORA covers ICT risk… Full module →

Finland

FIConfirmed5 sourced findings

DORA applies in Finland since 17 Jan 2025 with FIN-FSA as competent authority; 2025 cycle added AI Act thematic review.

France

FRConfirmed4 sourced findings

France's operational-resilience regime is anchored by DORA (Regulation (EU) 2022/2554), applicable from 17 January 2025, supervised by the ACPR for banking/insurance/payment entities, with Banque de France oversight of systemically important payment systems… Full module →

Germany

DEConfirmed4 sourced findings

DORA directly applicable since 17 Jan 2025 + FinmadiG; BaFin national ICT hub, 4-hour deadline; first DORA fine EUR 450k Q3 2025; 600+ incidents registered.

Ghana

GHConfirmed5 sourced findings

Operational resilience is anchored by BoG's Cyber & Information Security Directive (CISD, October 2018), a ~131-page directive requiring ISMS/ISO 27001 certification and PCI DSS compliance, applicable to banks, SDIs, PSPs and fintechs. BoG established the… Full module →

Gibraltar

GIHigh4 sourced findings

Gibraltar has implemented a UK-equivalent Operational Resilience regime: the GFSC published Operational Resilience, Outsourcing/Third-Party Risk Management and Liquidity Risk Management Guidance Notes in 2024 following industry consultation. Firms identify… Full module →

Greece

GRConfirmed4 sourced findings

DORA applies since 17 January 2025; Law 5193/2025 Articles 148-152 designate BoG as competent authority for credit institutions/PIs/EMIs and HCMC for investment/securities entities and CASPs. BoG supervisory commentary (Oct 2025) flags payment firms and EMIs… Full module →

Hong Kong

HKConfirmed4 sourced findings

Operational resilience for HKMA-authorised institutions is governed by SPM module OR-2 'Operational Resilience' (issued 31 May 2022), which required AIs to develop an OR framework within one year and fully implement (mapping interconnections, scenario… Full module →

Hungary

HUConfirmed5 sourced findings

DORA (Regulation (EU) 2022/2554) applies in Hungary from 17 January 2025, implemented domestically via a 10 April 2024 Implementing Law that names the MNB as competent authority and layers a national CSIRT dual-reporting duty and a simplified 'Mini DORA'… Full module →

Iceland

ISConfirmed6 sourced findings

CBI is sole supervisor of cyber/operational risk in Iceland's financial sector and has driven a multi-year core-payment-system migration alongside the SURF industry-coordination forum. DORA enters into force in Iceland on 1 November 2025, formalising ICT… Full module →

India

INConfirmed4 sourced findings

Operational resilience for payments rests on the RBI Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024), the Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective 1 April… Full module →

Indonesia

IDConfirmed4 sourced findings

Operational resilience for payment institutions is anchored on the MAS Technology Risk Management (TRM) Guidelines (updated January 2021), the legally binding MAS Notice on Cyber Hygiene (Notice 655) and Notice 658 on cyber-incident reporting. Although the… Full module →

Ireland

IEConfirmed4 sourced findings

The EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied since 17 January 2025; the CBI supervises DORA compliance for in-scope firms (including credit institutions, investment firms, CASPs, PIs and EMIs), embedding ICT risk… Full module →

Isle of Man

IMHigh5 sourced findings

There is no Isle of Man equivalent to DORA; operational resilience obligations for licenceholders derive from FSA08-era guidance (the Operational Risk Guidance Note and Outsourcing/Delegation of Functions guidance) rather than a standalone resilience statute… Full module →

Italy

ITConfirmed4 sourced findings

Italy's operational-resilience regime for payment/e-money institutions is anchored in the Disposizioni di vigilanza per gli IP e IMEL, updated by Banca d'Italia's 3 February 2026 provvedimento to transpose DORA, its delegated acts, and the PSD2-amending… Full module →

Ivory Coast (UEMOA bloc)

CIConfirmed4 sourced findings

There is no DORA-equivalent consolidated operational-resilience instrument in UEMOA. Operational resilience is embedded in BCEAO payment-system oversight (STAR-UEMOA/SICA-UEMOA risk management) and Banking Commission supervision of governance and information… Full module →

Japan

JPConfirmed4 sourced findings

Operational resilience for the financial sector is delivered through the FSA's Comprehensive Supervision Guidelines for Major Banks (which embed operational-resilience expectations) referencing the Guidelines on Cybersecurity for the Finance Sector (published… Full module →

Kazakhstan

KZHigh5 sourced findings

Operational resilience runs through the 2015 Informatization Law's critical-infrastructure cyber-risk obligations, the 2023-2029 national Digital Transformation/Cybersecurity Concept, and NBK's 2022 mandatory cybersecurity-protocol directive to financial… Full module →

Kenya

KEConfirmed4 sourced findings

Operational resilience for non-bank PSPs is anchored in the CBK Guideline on Cybersecurity for Payment Service Providers (July 2019), issued under s.31(2)(b) NPS Act, mandating board-level cyber governance, a CISO, written policies, dependency/third-party… Full module →

Laos

LAHigh5 sourced findings

Operational resilience is governed by the Law on Cybersecurity No. 87/NA (2025), which established a 24-hour Cyber Command Center and National Cybersecurity Operations Center, building on the 2015 Law on Prevention and Combatting Cyber Crime (which created… Full module →

Latin America

LATAMConfirmed4 sourced findings

C&M Software (30 Jun 2025, ~R$800m–>R$1bn) and Sinqia (Aug 2025, ~R$710m) Pix-rail breaches exposed PSTIs as a systemic single point of failure; BCB/CMN cyber resolutions in force 18 Dec 2025, full compliance 1 Mar 2026.

Latvia

LVHigh6 sourced findings

DORA applies since 17 Jan 2025; national complementary law effective 1 Oct 2025; EC infringement procedure opened March 2025 remains unresolved (CAUTION).

Liechtenstein

LIConfirmed5 sourced findings

DORA is fully in force in Liechtenstein via the EEA-DORA Implementation Act, with accelerated national application from 1 February 2025 and full incorporation into the EEA Agreement effective 1 July 2025, superseding the previous FMA Directive 2021/3… Full module →

Lithuania

LTConfirmed3 sourced findings

Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, supervised by the Bank of Lithuania as integrated financial supervisor across banks, insurers, EMIs/PIs and investment firms. Obligations cover… Full module →

Luxembourg

LUConfirmed4 sourced findings

Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, with the Luxembourg implementing law published 2 July 2024 designating the CSSF and CAA as competent authorities. The CSSF issued Circulars… Full module →

Macau SAR

MOHigh6 sourced findings

AMCM has built out a dense technology-and-cyber-risk supervisory stack since 2019, anchored in dedicated circulars on cyber risk management, electronic-banking risk, outsourcing and cloud outsourcing, most recently refreshed for the insurance sector in 2025… Full module →

Malaysia

MYConfirmed5 sourced findings

Operational resilience is governed by BNM's Risk Management in Technology (RMiT) policy document, the Malaysian analogue to DORA/FCA op-res. RMiT was first issued 2019/2020, updated 1 June 2023, and substantially revised effective 28 November 2025. It applies… Full module →

Malta

MTConfirmed4 sourced findings

DORA (EU 2022/2554) applicable 17 Jan 2025; MFSA designated national supervisor (TLPT under Legal Notice 166 of 2024, TIBER-MT); annual RoI submission 1 Jan-21 Mar from 2026 reflecting 31 Dec prior-year status.

Mexico

MXHigh4 sourced findings

Mexico has no standalone operational-resilience regulation (no DORA equivalent). Resilience, cybersecurity and incident-reporting obligations are assembled from CNBV's Circular Única de Bancos (CUB) for banks, CNBV cybersecurity/information-security… Full module →

Morocco

MAConfirmed4 sourced findings

Operational resilience rests on cybersecurity Law 05-20 (Dahir 1-20-69, 25 July 2020) and implementing Decree 2-21-406 (2021), with DGSSI (attached to National Defence) as national cyber authority and maCERT for incident response; the National Directive on IS… Full module →

Mozambique

MZHigh6 sourced findings

Mozambique's operational-resilience regime is emergent: a 2018 vendor licensing dispute caused a nationwide SIMORede payment-system blackout, exposing third-party dependency risk. Parliament unanimously approved a Cybersecurity Law in April 2026, and the… Full module →

Myanmar

MMHigh5 sourced findings

CBM-NET (Myanmar's RTGS/CSD platform, live since January 2016) carries formal Business Continuity Planning guidelines, but the wider payments operating environment suffers acute, recurring operational-resilience stress from conflict-driven telecom… Full module →

Nepal

NPHigh5 sourced findings

NRB's operational-resilience regime centres on the Cyber Resilience Guidelines (2023), applied to all licensed PSPs/PSOs and BFIs, and a new Framework for Identifying Systemically Important Payment Systems (SIPS, issued 1 September 2025) that operationalises… Full module →

Netherlands

NLConfirmed4 sourced findings

Operational resilience is governed by the EU DORA Regulation (EU 2022/2554), applicable from 17 January 2025, which applies directly to Dutch PIs, EMIs, banks, investment firms and MiCA CASPs. DNB is the designated competent authority (with AFM for conduct… Full module →

New Zealand

NZConfirmed3 sourced findings

Operational resilience of payment/settlement infrastructure runs through the Financial Market Infrastructures Act 2021 (FMI Act), under which RBNZ designates and supervises systemically important FMIs. ESAS (the RTGS) is a designated settlement system under… Full module →

Nigeria

NGConfirmed4 sourced findings

Operational resilience is governed primarily by the CBN Risk-Based Cybersecurity Framework, first effective 1 January 2019 for DMBs/PSPs and replaced by a May 2024 version for DMBs and Payment Service Banks (with a separate 2022 OFI framework), structured… Full module →

Norway

NOConfirmed5 sourced findings

Norway transposed DORA via a dedicated national DORA Act effective 1 July 2025, replacing the 2003 ICT Regulation for in-scope entities, with Finanstilsynet as supervisor and TIBER-NO forming the basis for mandatory threat-led penetration testing of the most… Full module →

Pakistan

PKConfirmed6 sourced findings

SBP's 2017 IT security framework plus 2018-2020 cyber circulars, reinforced by the 2026 Cyber Shield strategy targeting institutional resilience and recovery.

Panama

PAAssessed5 sourced findings

Panama's operational-resilience framework for regulated financial entities rests on a set of pre-DORA SBP agreements covering outsourcing, electronic banking, and IT risk management, with cloud-service use outside Panama requiring prior SBP/SMV approval or… Full module →

Peru

PEConfirmed5 sourced findings

Operational resilience for SBS-supervised entities governed by Resolucion SBS 504-2021 (proportionate three-tier SGSI-C), complementing Res. 2116-2009. The new BCRP payments regulation (Circular 0022-2025-BCRP) extends analogous cybersecurity expectations… Full module →

Philippines

PHConfirmed4 sourced findings

Operational resilience runs through the Payment System Oversight Framework (Circular 1089), which designates Systemically/Prominently Important Payment Systems and applies the BIS-IOSCO PFMI (adopted via Circular 1126). The Peso RTGS (PhilPaSSplus) and… Full module →

Poland

PLHigh4 sourced findings

Resilience rests on EU DORA (directly applicable) plus NBP oversight of systemically important payment systems and KNF supervision. Critical retail infrastructure (Elixir, Express Elixir, BLIK) is overseen by NBP under the Settlement Finality Act and… Full module →

Portugal

PTConfirmed5 sourced findings

DORA (Regulation (EU) 2022/2554) has been fully applicable since 17 January 2025, with Banco de Portugal designated as the national ICT-incident focal point and mandated to cooperate formally with ASF and CMVM. This layers atop pre-existing PSD2-based… Full module →

Qatar

QAAssessed3 sourced findings

Qatar's operational-resilience regime for banks rests on the QCB Technology Risks circular (2018), covering cybersecurity governance, IT operations, enterprise security, business continuity and fraud prevention, with a one-hour incident-reporting requirement… Full module →

Romania

ROConfirmed4 sourced findings

Operational resilience is governed by EU DORA (Regulation 2022/2554), in application since 17 January 2025, supplemented nationally by Emergency Ordinance No. 14/2026 designating the BNR and ASF as competent authorities (with DNSC involvement). DORA imposes… Full module →

Russia

RUAssessed5 sourced findings

Financial-sector operational resilience sits within Russia's Critical Information Infrastructure (CII) regime under Federal Law 187-FZ (2017, in force since Jan 2018), which lists banking and other financial-market areas among protected CII sectors… Full module →

Rwanda

RWHigh4 sourced findings

Operational resilience for BNR-regulated institutions is governed by Regulation N° 50/2022 of 17/06/2022 on Cyber Security in Regulated Institutions, issued under the BNR, banking, MFI and payment-system laws, mandating protection-detection-response-recovery… Full module →

Saudi Arabia

SAConfirmed4 sourced findings

Operational resilience for SAMA-regulated entities (banks, PSPs, finance and insurance firms) rests on the SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements (CRFR)… Full module →

Senegal

SNHigh4 sourced findings

BCEAO manages SICA-UEMOA and STAR-UEMOA under Regulation n°15/2002/CM/WAMU; GIM-UEMOA holds PCI DSS 4.0.1 Level-1 certification.

Serbia

RSAssessed5 sourced findings

Operational and ICT resilience for Serbian payment service providers rests on two tracks: sector-specific NBS rules under the Law on Payment Services (operational/security risk management, incident notification to the NBS) and the horizontal Law on… Full module →

Singapore

SGConfirmed4 sourced findings

MAS frames operational resilience around four pillars — operational risk, technology & cyber risk, third-party risk, and business continuity management. The Technology Risk Management (TRM) Guidelines (revised January 2021) and Business Continuity Management… Full module →

Slovakia

SKConfirmed3 sourced findings

Operational resilience in Slovakia is governed directly by the EU's Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, applicable since 17 January 2025 to most NBS-supervised entities including PSPs, EMIs and CASPs, with no separate… Full module →

Slovenia

SIHigh4 sourced findings

DORA applies directly across the EU financial sector including PSPs from 17 January 2025, but Slovenia's national implementing act (distributing supervisory tasks between Banka Slovenije, ATVP and the Insurance Supervision Agency) was still in the legislative… Full module →

South Africa

ZAConfirmed4 sourced findings

Operational resilience is anchored on SARB Directive 1 of 2024 'Cybersecurity and Cyber-resilience within the National Payment System' (issued 17 May 2024, compliance from 17 August 2024) together with Joint Standard 1 of 2023 (IT Governance and Risk… Full module →

South Korea

KRConfirmed3 sourced findings

Korea has no single DORA-equivalent instrument; operational resilience for the financial sector is built on the EFTA and its subordinate Regulation on Supervision of Electronic Financial Transactions plus FSC IT-outsourcing and cloud-use guidelines… Full module →

Spain

ESConfirmed5 sourced findings

DORA directly applicable since 17 Jan 2025; CNMV 74-question FAQ (early 2026); FSB Nov-2025 peer review confirms robust BdE cyber supervision.

Sri Lanka

LKConfirmed4 sourced findings

CBSL regulates technology/cyber risk via Banking Act Directions No. 16 of 2021 (amended Dec 2023) and a parallel Technology Risk & Resilience framework for licensed finance companies; licensed banks must report IT/cybersecurity incidents to CBSL; the RTGS… Full module →

Sweden

SEConfirmed5 sourced findings

DORA has applied since 17 January 2025 with FI designated the competent supervisory authority for financial-entity compliance and the Riksbank responsible for threat-led penetration testing (TLPT) of firms FI selects. FI has also directly ordered the three… Full module →

Switzerland

CHConfirmed4 sourced findings

The core operational-resilience instrument is FINMA Circular 2023/1 'Operational risks and resilience – banks', in force since 1 January 2024, which integrates the Basel Committee's 2021 operational-resilience principles and covers governance, ICT/cyber… Full module →

Taiwan

TWConfirmed6 sourced findings

Taiwan's operational-resilience regime combines the cross-sector Cybersecurity Management Act (critical-infrastructure designation) with FSC-specific financial-sector cybersecurity action plans, supply-chain and cloud-outsourcing rules, and 2025 legislative… Full module →

Tanzania

TZConfirmed4 sourced findings

BoT operates and oversees the systemically important payment infrastructures — TISS (real-time gross settlement, since 2004), the Tanzania Automated Clearing House (TACH/ECH since 2002), EFT, and the Tanzania Instant Payment System (TIPS). Resilience is… Full module →

Thailand

THConfirmed4 sourced findings

Operational resilience for payment providers is governed by BOT IT-risk supervision and information-security notifications under the PSA, requiring business-continuity planning, incident response, backup systems and third-party/outsourcing oversight. BOT… Full module →

Tunisia

TNConfirmed4 sourced findings

The BCT's payment-systems oversight function (established under Law 2016-35) targets security, stability, soundness and efficiency of national payment systems, complemented by Circular 2018-16 security/business-continuity obligations for payment institutions… Full module →

Turkey

TRConfirmed4 sourced findings

Operational resilience for Turkish payments draws on the CBRT's information-systems communiqué for PIs/EMIs and the BDDK's 2020 banking IT regulation (Regulation on Banks' Information Systems and Electronic Banking Services). Institutions must run annual… Full module →

Uganda

UGConfirmed5 sourced findings

BoU issued mandatory Cyber and Technology Risk Management Guidelines for all supervised financial institutions effective 1 December 2024, layered on the NPSA's 24-hour fraud/breach notification obligation for payment providers. The Computer Misuse (Amendment)… Full module →

Ukraine

UAHigh6 sourced findings

The NBU oversees payment-infrastructure resilience under Regulation No. 187 (2022), which mandates incident reporting and 2-hour recovery for systemically important payment systems; wartime conditions have forced an unusually mature operational cyber-defence… Full module →

United Arab Emirates

AEConfirmed4 sourced findings

Operational resilience for onshore institutions is built from sector regulations rather than a single DORA-style instrument: the CBUAE Operational Risk Management Regulation/Standards, the Outsourcing Regulation & Standards for Banks (covering material… Full module →

United Kingdom

UKConfirmed4 sourced findings

UK operational resilience rests on the FCA/PRA op-res framework plus the Critical Third Parties (CTP) regime introduced under FSMA 2023 (finalised in PS24/16). A new unified operational-incident and material-third-party reporting regime was finalised in March… Full module →

United States

USConfirmed4 sourced findings

The US has no single statutory operational-resilience regime equivalent to EU DORA; resilience is delivered through supervisory guidance from the prudential banking agencies. The cornerstone is the June 2023 Interagency Guidance on Third-Party Relationships… Full module →

United States – Alabama

US-ALHigh5 sourced findings

Alabama's operational-resilience layer for payments data is anchored in the 2018 Data Breach Notification Act (the last such law enacted among U.S. states) and the newly signed but not-yet-effective Alabama Personal Data Protection Act (2026). There is no… Full module →

United States – Alaska

US-AKAssessed4 sourced findings

Alaska has no bespoke operational-resilience statute; resilience obligations flow from (a) statutory examination cadence for state-chartered banks under Title 6, (b) federal FFIEC/OCC/FDIC cybersecurity supervisory guidance applicable to Alaska-domiciled… Full module →

United States – Arizona

US-AZAssessed3 sourced findings

Arizona has no dedicated payments-specific operational-resilience or critical-infrastructure statute analogous to DORA. Safety-and-soundness supervision of state-chartered banks runs through DIFI's CAMELS examination framework, aligned with federal… Full module →

United States – Arkansas

US-ARHigh4 sourced findings

Arkansas has no bespoke state operational-resilience regime for payment/financial institutions; resilience oversight of the state's 70 state-chartered banks flows through FFIEC-aligned federal examination standards applied jointly by the Arkansas State Bank… Full module →

United States – California

US-CAConfirmed4 sourced findings

There is no California-specific operational-resilience regime; resilience for payments in California flows from the federal layer — the Federal Reserve's instant-payments infrastructure (FedNow) and the private RTP network, both ISO 20022-based, plus federal… Full module →

United States – Colorado

US-COHigh5 sourced findings

Operational resilience for Colorado payment entities is embedded in the money-transmitter examination/recordkeeping regime (quarterly NMLS reporting, agent-roster reporting, record-retention rules) rather than a dedicated op-res statute, supplemented by a… Full module →

United States – Connecticut

US-CTHigh4 sourced findings

Connecticut lacks a DORA-style dedicated payments operational-resilience regime; resilience obligations arise via the state's data-breach-notification statute, a NIST/ISO/CIS-based cybersecurity safe-harbor law, and PCI DSS as applied to any business handling… Full module →

United States – Delaware

US-DEConfirmed5 sourced findings

Operational resilience for payments-relevant data is governed primarily by Delaware's data breach notification statute (6 Del.C. Ch.12B), requiring reasonable security practices, resident notification within 60 days, Attorney General notification above 500… Full module →

United States – District of Columbia

US-DCHigh4 sourced findings

DC has no standalone operational-resilience statute; DC-chartered banks and DISB-licensed nonbanks fall under the federal interagency cybersecurity/operational-resilience framework (OCC/FDIC/Federal Reserve), with DISB coordinating examinations jointly with… Full module →

United States – Florida

US-FLHigh4 sourced findings

Florida has no DORA-style prudential operational-resilience regime specific to payments; the operative baseline protection is the Florida Information Protection Act (FIPA), a strict 30-day breach-notification law enforced by the Attorney General, supplemented… Full module →

United States – Georgia

US-GAHigh3 sourced findings

Georgia has no standalone payments-specific operational-resilience statute analogous to DORA; resilience oversight flows through DBF's third-party service-provider examination authority over state-chartered banks/credit unions and federal FFIEC/BSA-linked… Full module →

United States – Hawaii

US-HIHigh5 sourced findings

Hawaii lacks a DORA-style ICT/critical-third-party resilience regime. Operational resilience for licensed financial institutions runs through DFI's examination/enforcement rules (HAR Chapters 26-27) and the state's general security-breach notification law… Full module →

United States – Idaho

US-IDAssessed4 sourced findings

Idaho has no state-specific operational-resilience statute for payments; state-chartered banks/credit unions are examined under the federal/CSBS InTREx framework and FFIEC guidance.

United States – Illinois

US-ILConfirmed4 sourced findings

Illinois operational resilience obligations for payments-adjacent entities run through IDFPR's Division of Banking IT-examination authority for state-chartered institutions and, since 2025, through DACPA's explicit cybersecurity/business-continuity mandate… Full module →

United States – Indiana

US-INConfirmed5 sourced findings

DFI supervises IT/operational risk via FFIEC-aligned advisory letters, transitioning to NIST CSF 2.0.

United States – Iowa

US-IAConfirmed5 sourced findings

Iowa's operational-resilience posture for payments rests on general-purpose statutes rather than a payments-specific op-res regime: the Security Breach Notification law (Chapter 715C) governs incident disclosure for financial-account data, the Insurance Data… Full module →

United States – Kansas

US-KSConfirmed4 sourced findings

Kansas layers a GLBA-equivalent information-security statute onto covered financial institutions (including money transmitters), a state security-breach notification law with tight timing obligations, and a distinct public-sector cybersecurity… Full module →

United States – Kentucky

US-KYConfirmed5 sourced findings

Kentucky has no payments-specific operational-resilience regime; the operative framework is the general information-security/breach-notification statute (KRS 365.732, in force since 2015), which exempts GLBA-covered financial institutions in favor of federal… Full module →

United States – Louisiana

US-LAHigh5 sourced findings

Louisiana does not maintain a bespoke state-level operational-resilience regime for payments firms; resilience obligations flow chiefly from the federal Gramm-Leach-Bliley Act (GLBA) Safeguards Rule applicable to money transmitters as "financial… Full module →

United States – Maine

US-MEAssessed2 sourced findings

Maine has no DORA-equivalent operational-resilience/critical-third-party statute; resilience runs through generic GLBA-consistent infosec rules and BFI's standard IT/BSA examination cycle.

United States – Maryland

US-MDConfirmed5 sourced findings

Maryland lacks a dedicated payments-sector operational-resilience statute equivalent to DORA; resilience obligations for payments/financial entities instead flow from the state's general data-breach notification law (PIPA), sector-specific insurance-carrier… Full module →

United States – Massachusetts

US-MAConfirmed4 sourced findings

Massachusetts operational-resilience exposure for payments firms runs through the state's data-security regime (M.G.L. c.93H / 201 CMR 17.00) requiring a Written Information Security Program and breach notification to the AG and OCABR, plus the new c.169B/209… Full module →

United States – Michigan

US-MIHigh4 sourced findings

Michigan's operational-resilience layer combines MCL 445.72 breach notification, DIFS cybersecurity event notification (Form FIS 2359), and PA 690 of 2018 for insurance licensees. A five-bill reform package (SB 360-364), passed by the Senate August 2025… Full module →

United States – Minnesota

US-MNConfirmed5 sourced findings

Minnesota lacks a payments-sector-specific operational resilience statute akin to DORA; resilience obligations for payments-adjacent entities instead arise from general data-breach notification law, a public-sector cybersecurity incident reporting mandate… Full module →

United States – Mississippi

US-MSHigh4 sourced findings

Mississippi lacks a dedicated operational-resilience regime; resilience obligations arise from DBCF's general examination authority, the newly enacted licensee-specific Data Security for Money Transmitters Act (2026), and the state's general data-breach… Full module →

United States – Missouri

US-MOHigh6 sourced findings

Operational resilience runs through federal FFIEC/FDIC guidance and CIRCIA, layered with the new state Insurance Data Security Act (effective Jan 1 2026).

United States – Montana

US-MTConfirmed5 sourced findings

Montana's operational-resilience posture rests on breach-notification statutes requiring immediate AG notification ahead of consumer notice.

United States – Nebraska

US-NEConfirmed5 sourced findings

Operational-resilience obligations in Nebraska run primarily through data-breach/cybersecurity statutes rather than a dedicated payments-resilience regime: the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 sets… Full module →

United States – Nevada

US-NVHigh5 sourced findings

Nevada has no general cross-sector payments operational-resilience statute; the standing regime is sector-specific to gaming payments via Regulation 14.

United States – New Hampshire

US-NHHigh4 sourced findings

NH layers state breach-notification (RSA 359-C) and insurance-sector cybersecurity reporting (RSA 420-P) atop federal operational-resilience expectations; third-party vendor risk materialised via the 2025 Marquis Software Solutions ransomware incident.

United States – New Jersey

US-NJHigh5 sourced findings

New Jersey imposes cybersecurity/incident-reporting obligations on DOBI-regulated entities via Regulation 22-05 and a general data-breach duty under the Identity Theft Prevention Act, with S3100 still pending.

United States – New Mexico

US-NMAssessed4 sourced findings

No standalone NM operational-resilience regime; federal FFIEC/GLBA/NCUA baseline applies.

United States – New York

US-NYConfirmed4 sourced findings

NY's resilience regime is anchored by the NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, effective since March 2017 and substantially amended by the November 2023 Second Amendment. It mandates a documented cybersecurity program, a CISO, MFA, asset… Full module →

United States – North Carolina

US-NCHigh5 sourced findings

NC has no payments-specific operational-resilience regime akin to DORA; resilience flows from the ITPA breach law, federal GLBA safeguards, and CIRCIA critical-infrastructure reporting, layered on NCCOB's own breach intake.

United States – North Dakota

US-NDConfirmed5 sourced findings

ND operational resilience runs on two tracks: depository institutions (banks/credit unions) are examined by NDDFI on a roughly 18-24 month cycle aligned to FFIEC/NCUA IT-examination frameworks, while non-depository payments-adjacent licensees (money… Full module →

United States – Ohio

US-OHAssessed3 sourced findings

Ohio has no bespoke state operational-resilience statute for payments; resilience obligations for MTL licensees flow through ORC 1315.081 (mandatory written reporting of specified events within 15 business days) and DFI examination powers, layered on top of… Full module →

United States – Oklahoma

US-OKConfirmed4 sourced findings

Operational resilience in Oklahoma is governed principally through the data-security and breach-notification lens rather than a dedicated payments operational-resilience regime. The Security Breach Notification Act was substantially overhauled effective… Full module →

United States – Oregon

US-ORConfirmed4 sourced findings

Operational-resilience obligations touching Oregon-chartered and nationally chartered banks operating in the state derive almost entirely from the federal layer: the OCC/Fed/FDIC computer-security incident notification rule (12 CFR 53) and FFIEC/NIST… Full module →

United States – Pennsylvania

US-PAAssessed4 sourced findings

Pennsylvania lacks a payments-specific operational-resilience regime; DoBS points regulated entities to federal FFIEC/OCC/FDIC/Fed third-party risk guidance rather than issuing its own binding rules for payment firms. The Commonwealth's own binding… Full module →

United States – Rhode Island

US-RIHigh5 sourced findings

Rhode Island enacted a standalone cybersecurity regime for DBR-licensed nonbank financial institutions (S603, effective July 2, 2025), modeled closely on NYDFS Part 500 but with a more lenient three-business-day breach notification window. This sits alongside… Full module →

United States – South Carolina

US-SCHigh5 sourced findings

SC has no payments-specific operational-resilience/critical-infrastructure regime akin to DORA. Applicable standing framework is the general breach-notification statute (since 2009) and the Insurance Data Security Act, layered under federal GLBA/FFIEC… Full module →

United States – South Dakota

US-SDConfirmed4 sourced findings

South Dakota does not operate a bespoke operational-resilience regime; resilience obligations for regulated payments/financial entities flow from the federal GLBA Safeguards Rule referenced on the Division's own regulatory-reference page, from Division… Full module →

United States – Tennessee

US-TNHigh5 sourced findings

Tennessee's operational-resilience layer for payments rests on its general breach-notification statute (Tenn. Code §47-18-2107), the 2023 Tennessee Information Protection Act (TIPA) which exempts GLBA-covered financial institutions, and TDFI's own internal… Full module →

United States – Texas

US-TXHigh4 sourced findings

Texas imposes a dedicated cybersecurity-incident notification rule on money services businesses (7 TAC §33.30), requiring confidential reporting to the Banking Commissioner of material incidents, layered on top of federal BSA/SAR obligations. A separate… Full module →

United States – Utah

US-UTHigh4 sourced findings

Utah's operational-resilience baseline for payments is anchored in the Protection of Personal Information Act (breach notification since 2006, amended 2024) and the Utah Cyber Center's coordination role, rather than a payments-specific operational-resilience… Full module →

United States – Vermont

US-VTConfirmed5 sourced findings

Vermont's operational-resilience layer is anchored in the Security Breach Notice Act (9 V.S.A. §§2430, 2435), dual-track DFR/AG notification, most recently amended by Act 89 (2020).

United States – Virginia

US-VAAssessed5 sourced findings

Virginia has no payments-specific operational-resilience regime analogous to DORA; resilience oversight runs through the Secretary of Public Safety and Homeland Security (as Chief Resilience Officer) and university-partnered cybersecurity research… Full module →

United States – Washington

US-WAHigh4 sourced findings

Operational resilience obligations for Washington money transmitters are embedded in WAC 208-690 rather than a standalone resilience statute: cybersecurity, business-continuity, recordkeeping and third-party/agent oversight duties are examination-enforced by… Full module →

United States – West Virginia

US-WVConfirmed5 sourced findings

WV has no DORA-style dedicated financial-sector operational-resilience statute; resilience oversight runs through the Division of Financial Institutions' general examination authority (extended explicitly to third-party IT vendors) layered on top of the… Full module →

United States – Wisconsin

US-WIHigh4 sourced findings

Operational resilience rests on the state Data Breach Notification Law and Insurance Data Security Law for OCI licensees, with no dedicated state operational-resilience regime.

United States – Wyoming

US-WYHigh5 sourced findings

Wyoming has no distinct state-level operational-resilience statute for payments/banking; state-chartered banks and SPDIs operate under the federal FFIEC/OCC/FDIC/Federal Reserve examination framework (Business Continuity Management booklet, Cybersecurity… Full module →

Uruguay

UYHigh4 sourced findings

BCU is building a graduated cyber-supervision regime for the payments system anchored on AGESIC's national Marco de Ciberseguridad (MCU), starting with mandatory periodic cyber-capability reporting by IEDEs (from 1 July) and continuity/outsourcing-governance… Full module →

Venezuela

VEPossible2 sourced findings

No standalone operational-resilience/critical-third-party framework equivalent to DORA or FCA/PRA op-res rules was located for Venezuela. Resilience obligations appear embedded piecemeal within SUDEBAN's general banking-supervision and AML circulars, and… Full module →

Vietnam

VNHigh4 sourced findings

Operational resilience is driven by SBV cybersecurity and authentication mandates rather than a single DORA-style instrument. Decision 2345/QD-NHNN (effective 1 July 2024) mandates biometric authentication for high-risk transactions, supplemented by Circular… Full module →

Zambia

ZMHigh6 sourced findings

Operational resilience now sits substantially under the Cyber Security Act 2025 and Cyber Crimes Act 2025, designating payment gateways/core banking as critical infrastructure with registration, localisation, audit and incident-reporting duties.