There is no single DORA-equivalent across the bloc; resilience is built into national payments vision documents and cyber directives. SARB has issued a directive on cybersecurity and cyber-resilience within the national payment system. Nigeria's Payments… Full module →
Operational Resilience & Critical Infrastructure
W3Every jurisdiction World Payments Monitor tracks for W3, with the standing position recorded in the current weekly cycle. Each entry links to the full module on that jurisdiction’s page, where the sourced findings and evidence sit.
Algeria adopted its first comprehensive cybersecurity governance architecture in 2025-2026, designating financial services as critical information infrastructure with a 5-day breach-reporting window.
BCRA operational-resilience and cyber rules apply on a functional basis to banks, PSPs (digital wallets, aggregators, facilitators) and systemically important payment systems. Core instruments are the IT/information-security risk standard (Com. "A" 7724… Full module →
APAC operational-resilience obligations sit within national frameworks rather than a single regime like DORA. Hong Kong's critical-infrastructure / CCS regime carries real-time incident reporting and severe fines; India imposes data-localisation and… Full module →
Operational resilience for APRA-regulated entities (incl. ADIs/banks providing payments) is governed by Prudential Standard CPS 230 Operational Risk Management, in force 1 July 2025, replacing CPS 231 (Outsourcing) and CPS 232 (Business Continuity… Full module →
DORA has applied directly in Austria since 17 January 2025, binding on all FMA-supervised entities including small payment and e-money institutions, and is enforced nationally via the DORA Enforcement Act. The FMA's Conduct and IT Risk Supervision division… Full module →
Bangladesh Bank has substantially escalated operational-resilience regulation in 2025-2026, moving from the long-standing ICT Security Guideline (v4.0, 2023) to a first-ever sector-wide, technology-neutral Cybersecurity Framework, Version 1.0 (2026)… Full module →
DORA has applied since 17 January 2025 across Belgian financial entities including PIs/EMIs, with NBB and FSMA as competent authorities. NBB runs TIBER-BE and requires ICT incident reporting via OneGate; SWIFT oversight is being strengthened with NBB as lead… Full module →
Operational resilience is governed by CMN Resolution 4.893/2021 (financial institutions) and BCB Resolution 85/2021 (payment institutions), effective from 2021, which mandate cybersecurity policies, incident response, business-continuity testing, and rules… Full module →
DORA has applied directly in Bulgaria since 17 January 2025, with BNB and FSC as enforcing authorities. Bulgaria faced EU infringement action for incomplete transposition of enabling national legislation. BNB is actively auditing bank-sector DORA-preparedness… Full module →
NBC has run a dedicated Technology Risk Management (TRM) framework since July 2019, refreshed as the Technology and Cyber Risk Management Guidelines in 2026, covering cybersecurity management, IT services outsourcing, business continuity management and… Full module →
Operational resilience obligations are distributed across COBAC's PSP operational-requirements regulation, the national Cybersecurity Law, and a CEMAC-wide technical-standardisation body (CORENOFI) which is compelling ISO 20022 migration by November 2025… Full module →
Operational resilience for non-bank PSPs runs through the RPAA's operational-risk-management and incident-response obligations (in force September 8, 2025), supervised by the Bank of Canada. Systemic payment infrastructure (Lynx) is designated under the… Full module →
Operational resilience for Alberta-touching non-bank PSPs is governed by the RPAA's operational risk management and incident response framework, in force since September 8, 2025, with material-incident notification and annual reporting obligations.
Operational resilience for BC-serving PSPs is governed federally through the RPAA's operational risk management and incident response framework (in force since September 8, 2025), with a 48-hour material-incident notification duty to the Bank of Canada and… Full module →
Operational resilience for retail payments in NB (as elsewhere in Canada) is governed federally by the RPAA's risk management and incident response (RMIR) framework administered by the Bank of Canada, which prescribes written risk-management frameworks… Full module →
The RPAA's operational risk-management framework (in force since September 8, 2025) requires PSPs to manage risks that could reduce, deteriorate or break down retail payment activities; OSFI's 2025-26 Annual Risk Outlook flags state-actor threats; the… Full module →
The Bank of Canada's RPAA-based Operational Risk and Incident Response supervisory guideline governs PSP operational resilience, with a binding 48-hour material-incident notification rule and mandatory third-party risk management, in force alongside… Full module →
Two regimes apply: sectoral CMF cybersecurity/operational-resilience rules in the RAN (20-7 outsourcing, 20-8 operational-incident information, 20-9 business continuity, 20-10 information security & cybersecurity) for banks, their support companies, and card… Full module →
Operational resilience sits within China's cyber/data-security stack: amended Cybersecurity Law (in force 1 Jan 2026) tightens CIIO obligations; Network Data Security Regulations and sector-specific financial data-security measures create graded… Full module →
Colombia's operational-resilience/data-sharing regime is anchored by the mandatory Sistema de Finanzas Abiertas (Decreto 0368 de 2026, signed 7 Apr 2026, amending Decreto 2555/2010 per Art. 89 Ley 2294/2023), superseding the voluntary Decreto 1297/2022 scheme… Full module →
Costa Rica's operational-resilience posture was shaped decisively by the April 2022 Conti/Hive ransomware campaign against government systems, which triggered a national state of emergency. IT/outsourcing risk management for the regulated financial sector… Full module →
DORA (Regulation (EU) 2022/2554) entered into application EU-wide from 17 January 2025, with HNB and HANFA jointly coordinating implementation for Croatian financial entities. Croatia faces above-average third-party ICT dependency and limited specialist… Full module →
CBCS maintains a dedicated IT, Cyber & Operational Risk supervisory pillar (IT Governance, Business Continuity Management, Information Security Management provisions) and has flagged fintech/cyber risk as a priority in its 2026-2028 Research Agenda… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT… Full module →
DORA (Regulation (EU) 2022/2554) became fully applicable in the Czech Republic on 17 January 2025, transposed via the Act on the Digitalisation of the Financial Market (Act No. 31/2025 Coll.), with the CNB as DORA supervisory/sanctioning authority working… Full module →
Operational resilience is now governed by DORA, with Finanstilsynet as the single competent authority for credit institutions, PIs, EMIs, investment firms, insurers and MiCA CASPs. Danmarks Nationalbank separately conducts financial-infrastructure oversight… Full module →
Operational resilience is set by SIPARD's minimum technological requirements built on CPMI-IOSCO PFMI; BCRD's LBTR (since 2008) underpins systemic-risk reduction; SB began a structured cybersecurity dialogue in 2026.
Operational resilience is governed by the SB's Norma de Control para la Gestión del Riesgo Operativo, mandating ISO 22301-based BCM and ISO 27000-based information-security management, layered with BCE cybersecurity standards for the new instant-payments… Full module →
Operational resilience is anchored by the CBE's Financial Cybersecurity Framework (the first such sectoral framework in Egypt) plus a dedicated CBE cybersecurity sector and the country's first financial-sector CERT. Outsourcing of services and data hosting by… Full module →
DORA applies directly in Estonia since 17 January 2025 with Finantsinspektsioon as NCA across banks, PIs, EMIs and CASPs.
The EEA operational-resilience regime for payments is the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), which entered into force 16 January 2023 and applied in full from 17 January 2025 with no transition period. DORA covers ICT risk… Full module →
DORA applies in Finland since 17 Jan 2025 with FIN-FSA as competent authority; 2025 cycle added AI Act thematic review.
France's operational-resilience regime is anchored by DORA (Regulation (EU) 2022/2554), applicable from 17 January 2025, supervised by the ACPR for banking/insurance/payment entities, with Banque de France oversight of systemically important payment systems… Full module →
DORA directly applicable since 17 Jan 2025 + FinmadiG; BaFin national ICT hub, 4-hour deadline; first DORA fine EUR 450k Q3 2025; 600+ incidents registered.
Operational resilience is anchored by BoG's Cyber & Information Security Directive (CISD, October 2018), a ~131-page directive requiring ISMS/ISO 27001 certification and PCI DSS compliance, applicable to banks, SDIs, PSPs and fintechs. BoG established the… Full module →
Gibraltar has implemented a UK-equivalent Operational Resilience regime: the GFSC published Operational Resilience, Outsourcing/Third-Party Risk Management and Liquidity Risk Management Guidance Notes in 2024 following industry consultation. Firms identify… Full module →
DORA applies since 17 January 2025; Law 5193/2025 Articles 148-152 designate BoG as competent authority for credit institutions/PIs/EMIs and HCMC for investment/securities entities and CASPs. BoG supervisory commentary (Oct 2025) flags payment firms and EMIs… Full module →
Operational resilience for HKMA-authorised institutions is governed by SPM module OR-2 'Operational Resilience' (issued 31 May 2022), which required AIs to develop an OR framework within one year and fully implement (mapping interconnections, scenario… Full module →
DORA (Regulation (EU) 2022/2554) applies in Hungary from 17 January 2025, implemented domestically via a 10 April 2024 Implementing Law that names the MNB as competent authority and layers a national CSIRT dual-reporting duty and a simplified 'Mini DORA'… Full module →
CBI is sole supervisor of cyber/operational risk in Iceland's financial sector and has driven a multi-year core-payment-system migration alongside the SURF industry-coordination forum. DORA enters into force in Iceland on 1 November 2025, formalising ICT… Full module →
Operational resilience for payments rests on the RBI Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024), the Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective 1 April… Full module →
Operational resilience for payment institutions is anchored on the MAS Technology Risk Management (TRM) Guidelines (updated January 2021), the legally binding MAS Notice on Cyber Hygiene (Notice 655) and Notice 658 on cyber-incident reporting. Although the… Full module →
The EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied since 17 January 2025; the CBI supervises DORA compliance for in-scope firms (including credit institutions, investment firms, CASPs, PIs and EMIs), embedding ICT risk… Full module →
There is no Isle of Man equivalent to DORA; operational resilience obligations for licenceholders derive from FSA08-era guidance (the Operational Risk Guidance Note and Outsourcing/Delegation of Functions guidance) rather than a standalone resilience statute… Full module →
Italy's operational-resilience regime for payment/e-money institutions is anchored in the Disposizioni di vigilanza per gli IP e IMEL, updated by Banca d'Italia's 3 February 2026 provvedimento to transpose DORA, its delegated acts, and the PSD2-amending… Full module →
There is no DORA-equivalent consolidated operational-resilience instrument in UEMOA. Operational resilience is embedded in BCEAO payment-system oversight (STAR-UEMOA/SICA-UEMOA risk management) and Banking Commission supervision of governance and information… Full module →
Operational resilience for the financial sector is delivered through the FSA's Comprehensive Supervision Guidelines for Major Banks (which embed operational-resilience expectations) referencing the Guidelines on Cybersecurity for the Finance Sector (published… Full module →
Operational resilience runs through the 2015 Informatization Law's critical-infrastructure cyber-risk obligations, the 2023-2029 national Digital Transformation/Cybersecurity Concept, and NBK's 2022 mandatory cybersecurity-protocol directive to financial… Full module →
Operational resilience for non-bank PSPs is anchored in the CBK Guideline on Cybersecurity for Payment Service Providers (July 2019), issued under s.31(2)(b) NPS Act, mandating board-level cyber governance, a CISO, written policies, dependency/third-party… Full module →
Operational resilience is governed by the Law on Cybersecurity No. 87/NA (2025), which established a 24-hour Cyber Command Center and National Cybersecurity Operations Center, building on the 2015 Law on Prevention and Combatting Cyber Crime (which created… Full module →
C&M Software (30 Jun 2025, ~R$800m–>R$1bn) and Sinqia (Aug 2025, ~R$710m) Pix-rail breaches exposed PSTIs as a systemic single point of failure; BCB/CMN cyber resolutions in force 18 Dec 2025, full compliance 1 Mar 2026.
DORA applies since 17 Jan 2025; national complementary law effective 1 Oct 2025; EC infringement procedure opened March 2025 remains unresolved (CAUTION).
DORA is fully in force in Liechtenstein via the EEA-DORA Implementation Act, with accelerated national application from 1 February 2025 and full incorporation into the EEA Agreement effective 1 July 2025, superseding the previous FMA Directive 2021/3… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, supervised by the Bank of Lithuania as integrated financial supervisor across banks, insurers, EMIs/PIs and investment firms. Obligations cover… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, with the Luxembourg implementing law published 2 July 2024 designating the CSSF and CAA as competent authorities. The CSSF issued Circulars… Full module →
AMCM has built out a dense technology-and-cyber-risk supervisory stack since 2019, anchored in dedicated circulars on cyber risk management, electronic-banking risk, outsourcing and cloud outsourcing, most recently refreshed for the insurance sector in 2025… Full module →
Operational resilience is governed by BNM's Risk Management in Technology (RMiT) policy document, the Malaysian analogue to DORA/FCA op-res. RMiT was first issued 2019/2020, updated 1 June 2023, and substantially revised effective 28 November 2025. It applies… Full module →
DORA (EU 2022/2554) applicable 17 Jan 2025; MFSA designated national supervisor (TLPT under Legal Notice 166 of 2024, TIBER-MT); annual RoI submission 1 Jan-21 Mar from 2026 reflecting 31 Dec prior-year status.
Mexico has no standalone operational-resilience regulation (no DORA equivalent). Resilience, cybersecurity and incident-reporting obligations are assembled from CNBV's Circular Única de Bancos (CUB) for banks, CNBV cybersecurity/information-security… Full module →
Operational resilience rests on cybersecurity Law 05-20 (Dahir 1-20-69, 25 July 2020) and implementing Decree 2-21-406 (2021), with DGSSI (attached to National Defence) as national cyber authority and maCERT for incident response; the National Directive on IS… Full module →
Mozambique's operational-resilience regime is emergent: a 2018 vendor licensing dispute caused a nationwide SIMORede payment-system blackout, exposing third-party dependency risk. Parliament unanimously approved a Cybersecurity Law in April 2026, and the… Full module →
CBM-NET (Myanmar's RTGS/CSD platform, live since January 2016) carries formal Business Continuity Planning guidelines, but the wider payments operating environment suffers acute, recurring operational-resilience stress from conflict-driven telecom… Full module →
NRB's operational-resilience regime centres on the Cyber Resilience Guidelines (2023), applied to all licensed PSPs/PSOs and BFIs, and a new Framework for Identifying Systemically Important Payment Systems (SIPS, issued 1 September 2025) that operationalises… Full module →
Operational resilience is governed by the EU DORA Regulation (EU 2022/2554), applicable from 17 January 2025, which applies directly to Dutch PIs, EMIs, banks, investment firms and MiCA CASPs. DNB is the designated competent authority (with AFM for conduct… Full module →
Operational resilience of payment/settlement infrastructure runs through the Financial Market Infrastructures Act 2021 (FMI Act), under which RBNZ designates and supervises systemically important FMIs. ESAS (the RTGS) is a designated settlement system under… Full module →
Operational resilience is governed primarily by the CBN Risk-Based Cybersecurity Framework, first effective 1 January 2019 for DMBs/PSPs and replaced by a May 2024 version for DMBs and Payment Service Banks (with a separate 2022 OFI framework), structured… Full module →
Norway transposed DORA via a dedicated national DORA Act effective 1 July 2025, replacing the 2003 ICT Regulation for in-scope entities, with Finanstilsynet as supervisor and TIBER-NO forming the basis for mandatory threat-led penetration testing of the most… Full module →
SBP's 2017 IT security framework plus 2018-2020 cyber circulars, reinforced by the 2026 Cyber Shield strategy targeting institutional resilience and recovery.
Panama's operational-resilience framework for regulated financial entities rests on a set of pre-DORA SBP agreements covering outsourcing, electronic banking, and IT risk management, with cloud-service use outside Panama requiring prior SBP/SMV approval or… Full module →
Operational resilience for SBS-supervised entities governed by Resolucion SBS 504-2021 (proportionate three-tier SGSI-C), complementing Res. 2116-2009. The new BCRP payments regulation (Circular 0022-2025-BCRP) extends analogous cybersecurity expectations… Full module →
Operational resilience runs through the Payment System Oversight Framework (Circular 1089), which designates Systemically/Prominently Important Payment Systems and applies the BIS-IOSCO PFMI (adopted via Circular 1126). The Peso RTGS (PhilPaSSplus) and… Full module →
Resilience rests on EU DORA (directly applicable) plus NBP oversight of systemically important payment systems and KNF supervision. Critical retail infrastructure (Elixir, Express Elixir, BLIK) is overseen by NBP under the Settlement Finality Act and… Full module →
DORA (Regulation (EU) 2022/2554) has been fully applicable since 17 January 2025, with Banco de Portugal designated as the national ICT-incident focal point and mandated to cooperate formally with ASF and CMVM. This layers atop pre-existing PSD2-based… Full module →
Qatar's operational-resilience regime for banks rests on the QCB Technology Risks circular (2018), covering cybersecurity governance, IT operations, enterprise security, business continuity and fraud prevention, with a one-hour incident-reporting requirement… Full module →
Operational resilience is governed by EU DORA (Regulation 2022/2554), in application since 17 January 2025, supplemented nationally by Emergency Ordinance No. 14/2026 designating the BNR and ASF as competent authorities (with DNSC involvement). DORA imposes… Full module →
Financial-sector operational resilience sits within Russia's Critical Information Infrastructure (CII) regime under Federal Law 187-FZ (2017, in force since Jan 2018), which lists banking and other financial-market areas among protected CII sectors… Full module →
Operational resilience for BNR-regulated institutions is governed by Regulation N° 50/2022 of 17/06/2022 on Cyber Security in Regulated Institutions, issued under the BNR, banking, MFI and payment-system laws, mandating protection-detection-response-recovery… Full module →
Operational resilience for SAMA-regulated entities (banks, PSPs, finance and insurance firms) rests on the SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements (CRFR)… Full module →
BCEAO manages SICA-UEMOA and STAR-UEMOA under Regulation n°15/2002/CM/WAMU; GIM-UEMOA holds PCI DSS 4.0.1 Level-1 certification.
Operational and ICT resilience for Serbian payment service providers rests on two tracks: sector-specific NBS rules under the Law on Payment Services (operational/security risk management, incident notification to the NBS) and the horizontal Law on… Full module →
MAS frames operational resilience around four pillars — operational risk, technology & cyber risk, third-party risk, and business continuity management. The Technology Risk Management (TRM) Guidelines (revised January 2021) and Business Continuity Management… Full module →
Operational resilience in Slovakia is governed directly by the EU's Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, applicable since 17 January 2025 to most NBS-supervised entities including PSPs, EMIs and CASPs, with no separate… Full module →
DORA applies directly across the EU financial sector including PSPs from 17 January 2025, but Slovenia's national implementing act (distributing supervisory tasks between Banka Slovenije, ATVP and the Insurance Supervision Agency) was still in the legislative… Full module →
Operational resilience is anchored on SARB Directive 1 of 2024 'Cybersecurity and Cyber-resilience within the National Payment System' (issued 17 May 2024, compliance from 17 August 2024) together with Joint Standard 1 of 2023 (IT Governance and Risk… Full module →
Korea has no single DORA-equivalent instrument; operational resilience for the financial sector is built on the EFTA and its subordinate Regulation on Supervision of Electronic Financial Transactions plus FSC IT-outsourcing and cloud-use guidelines… Full module →
DORA directly applicable since 17 Jan 2025; CNMV 74-question FAQ (early 2026); FSB Nov-2025 peer review confirms robust BdE cyber supervision.
CBSL regulates technology/cyber risk via Banking Act Directions No. 16 of 2021 (amended Dec 2023) and a parallel Technology Risk & Resilience framework for licensed finance companies; licensed banks must report IT/cybersecurity incidents to CBSL; the RTGS… Full module →
DORA has applied since 17 January 2025 with FI designated the competent supervisory authority for financial-entity compliance and the Riksbank responsible for threat-led penetration testing (TLPT) of firms FI selects. FI has also directly ordered the three… Full module →
The core operational-resilience instrument is FINMA Circular 2023/1 'Operational risks and resilience – banks', in force since 1 January 2024, which integrates the Basel Committee's 2021 operational-resilience principles and covers governance, ICT/cyber… Full module →
Taiwan's operational-resilience regime combines the cross-sector Cybersecurity Management Act (critical-infrastructure designation) with FSC-specific financial-sector cybersecurity action plans, supply-chain and cloud-outsourcing rules, and 2025 legislative… Full module →
BoT operates and oversees the systemically important payment infrastructures — TISS (real-time gross settlement, since 2004), the Tanzania Automated Clearing House (TACH/ECH since 2002), EFT, and the Tanzania Instant Payment System (TIPS). Resilience is… Full module →
Operational resilience for payment providers is governed by BOT IT-risk supervision and information-security notifications under the PSA, requiring business-continuity planning, incident response, backup systems and third-party/outsourcing oversight. BOT… Full module →
The BCT's payment-systems oversight function (established under Law 2016-35) targets security, stability, soundness and efficiency of national payment systems, complemented by Circular 2018-16 security/business-continuity obligations for payment institutions… Full module →
Operational resilience for Turkish payments draws on the CBRT's information-systems communiqué for PIs/EMIs and the BDDK's 2020 banking IT regulation (Regulation on Banks' Information Systems and Electronic Banking Services). Institutions must run annual… Full module →
BoU issued mandatory Cyber and Technology Risk Management Guidelines for all supervised financial institutions effective 1 December 2024, layered on the NPSA's 24-hour fraud/breach notification obligation for payment providers. The Computer Misuse (Amendment)… Full module →
The NBU oversees payment-infrastructure resilience under Regulation No. 187 (2022), which mandates incident reporting and 2-hour recovery for systemically important payment systems; wartime conditions have forced an unusually mature operational cyber-defence… Full module →
Operational resilience for onshore institutions is built from sector regulations rather than a single DORA-style instrument: the CBUAE Operational Risk Management Regulation/Standards, the Outsourcing Regulation & Standards for Banks (covering material… Full module →
UK operational resilience rests on the FCA/PRA op-res framework plus the Critical Third Parties (CTP) regime introduced under FSMA 2023 (finalised in PS24/16). A new unified operational-incident and material-third-party reporting regime was finalised in March… Full module →
The US has no single statutory operational-resilience regime equivalent to EU DORA; resilience is delivered through supervisory guidance from the prudential banking agencies. The cornerstone is the June 2023 Interagency Guidance on Third-Party Relationships… Full module →
Alabama's operational-resilience layer for payments data is anchored in the 2018 Data Breach Notification Act (the last such law enacted among U.S. states) and the newly signed but not-yet-effective Alabama Personal Data Protection Act (2026). There is no… Full module →
Alaska has no bespoke operational-resilience statute; resilience obligations flow from (a) statutory examination cadence for state-chartered banks under Title 6, (b) federal FFIEC/OCC/FDIC cybersecurity supervisory guidance applicable to Alaska-domiciled… Full module →
Arizona has no dedicated payments-specific operational-resilience or critical-infrastructure statute analogous to DORA. Safety-and-soundness supervision of state-chartered banks runs through DIFI's CAMELS examination framework, aligned with federal… Full module →
Arkansas has no bespoke state operational-resilience regime for payment/financial institutions; resilience oversight of the state's 70 state-chartered banks flows through FFIEC-aligned federal examination standards applied jointly by the Arkansas State Bank… Full module →
There is no California-specific operational-resilience regime; resilience for payments in California flows from the federal layer — the Federal Reserve's instant-payments infrastructure (FedNow) and the private RTP network, both ISO 20022-based, plus federal… Full module →
Operational resilience for Colorado payment entities is embedded in the money-transmitter examination/recordkeeping regime (quarterly NMLS reporting, agent-roster reporting, record-retention rules) rather than a dedicated op-res statute, supplemented by a… Full module →
Connecticut lacks a DORA-style dedicated payments operational-resilience regime; resilience obligations arise via the state's data-breach-notification statute, a NIST/ISO/CIS-based cybersecurity safe-harbor law, and PCI DSS as applied to any business handling… Full module →
Operational resilience for payments-relevant data is governed primarily by Delaware's data breach notification statute (6 Del.C. Ch.12B), requiring reasonable security practices, resident notification within 60 days, Attorney General notification above 500… Full module →
DC has no standalone operational-resilience statute; DC-chartered banks and DISB-licensed nonbanks fall under the federal interagency cybersecurity/operational-resilience framework (OCC/FDIC/Federal Reserve), with DISB coordinating examinations jointly with… Full module →
Florida has no DORA-style prudential operational-resilience regime specific to payments; the operative baseline protection is the Florida Information Protection Act (FIPA), a strict 30-day breach-notification law enforced by the Attorney General, supplemented… Full module →
Georgia has no standalone payments-specific operational-resilience statute analogous to DORA; resilience oversight flows through DBF's third-party service-provider examination authority over state-chartered banks/credit unions and federal FFIEC/BSA-linked… Full module →
Hawaii lacks a DORA-style ICT/critical-third-party resilience regime. Operational resilience for licensed financial institutions runs through DFI's examination/enforcement rules (HAR Chapters 26-27) and the state's general security-breach notification law… Full module →
Idaho has no state-specific operational-resilience statute for payments; state-chartered banks/credit unions are examined under the federal/CSBS InTREx framework and FFIEC guidance.
Illinois operational resilience obligations for payments-adjacent entities run through IDFPR's Division of Banking IT-examination authority for state-chartered institutions and, since 2025, through DACPA's explicit cybersecurity/business-continuity mandate… Full module →
DFI supervises IT/operational risk via FFIEC-aligned advisory letters, transitioning to NIST CSF 2.0.
Iowa's operational-resilience posture for payments rests on general-purpose statutes rather than a payments-specific op-res regime: the Security Breach Notification law (Chapter 715C) governs incident disclosure for financial-account data, the Insurance Data… Full module →
Kansas layers a GLBA-equivalent information-security statute onto covered financial institutions (including money transmitters), a state security-breach notification law with tight timing obligations, and a distinct public-sector cybersecurity… Full module →
Kentucky has no payments-specific operational-resilience regime; the operative framework is the general information-security/breach-notification statute (KRS 365.732, in force since 2015), which exempts GLBA-covered financial institutions in favor of federal… Full module →
Louisiana does not maintain a bespoke state-level operational-resilience regime for payments firms; resilience obligations flow chiefly from the federal Gramm-Leach-Bliley Act (GLBA) Safeguards Rule applicable to money transmitters as "financial… Full module →
Maine has no DORA-equivalent operational-resilience/critical-third-party statute; resilience runs through generic GLBA-consistent infosec rules and BFI's standard IT/BSA examination cycle.
Maryland lacks a dedicated payments-sector operational-resilience statute equivalent to DORA; resilience obligations for payments/financial entities instead flow from the state's general data-breach notification law (PIPA), sector-specific insurance-carrier… Full module →
Massachusetts operational-resilience exposure for payments firms runs through the state's data-security regime (M.G.L. c.93H / 201 CMR 17.00) requiring a Written Information Security Program and breach notification to the AG and OCABR, plus the new c.169B/209… Full module →
Michigan's operational-resilience layer combines MCL 445.72 breach notification, DIFS cybersecurity event notification (Form FIS 2359), and PA 690 of 2018 for insurance licensees. A five-bill reform package (SB 360-364), passed by the Senate August 2025… Full module →
Minnesota lacks a payments-sector-specific operational resilience statute akin to DORA; resilience obligations for payments-adjacent entities instead arise from general data-breach notification law, a public-sector cybersecurity incident reporting mandate… Full module →
Mississippi lacks a dedicated operational-resilience regime; resilience obligations arise from DBCF's general examination authority, the newly enacted licensee-specific Data Security for Money Transmitters Act (2026), and the state's general data-breach… Full module →
Operational resilience runs through federal FFIEC/FDIC guidance and CIRCIA, layered with the new state Insurance Data Security Act (effective Jan 1 2026).
Montana's operational-resilience posture rests on breach-notification statutes requiring immediate AG notification ahead of consumer notice.
Operational-resilience obligations in Nebraska run primarily through data-breach/cybersecurity statutes rather than a dedicated payments-resilience regime: the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 sets… Full module →
Nevada has no general cross-sector payments operational-resilience statute; the standing regime is sector-specific to gaming payments via Regulation 14.
NH layers state breach-notification (RSA 359-C) and insurance-sector cybersecurity reporting (RSA 420-P) atop federal operational-resilience expectations; third-party vendor risk materialised via the 2025 Marquis Software Solutions ransomware incident.
New Jersey imposes cybersecurity/incident-reporting obligations on DOBI-regulated entities via Regulation 22-05 and a general data-breach duty under the Identity Theft Prevention Act, with S3100 still pending.
No standalone NM operational-resilience regime; federal FFIEC/GLBA/NCUA baseline applies.
NY's resilience regime is anchored by the NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, effective since March 2017 and substantially amended by the November 2023 Second Amendment. It mandates a documented cybersecurity program, a CISO, MFA, asset… Full module →
NC has no payments-specific operational-resilience regime akin to DORA; resilience flows from the ITPA breach law, federal GLBA safeguards, and CIRCIA critical-infrastructure reporting, layered on NCCOB's own breach intake.
ND operational resilience runs on two tracks: depository institutions (banks/credit unions) are examined by NDDFI on a roughly 18-24 month cycle aligned to FFIEC/NCUA IT-examination frameworks, while non-depository payments-adjacent licensees (money… Full module →
Ohio has no bespoke state operational-resilience statute for payments; resilience obligations for MTL licensees flow through ORC 1315.081 (mandatory written reporting of specified events within 15 business days) and DFI examination powers, layered on top of… Full module →
Operational resilience in Oklahoma is governed principally through the data-security and breach-notification lens rather than a dedicated payments operational-resilience regime. The Security Breach Notification Act was substantially overhauled effective… Full module →
Operational-resilience obligations touching Oregon-chartered and nationally chartered banks operating in the state derive almost entirely from the federal layer: the OCC/Fed/FDIC computer-security incident notification rule (12 CFR 53) and FFIEC/NIST… Full module →
Pennsylvania lacks a payments-specific operational-resilience regime; DoBS points regulated entities to federal FFIEC/OCC/FDIC/Fed third-party risk guidance rather than issuing its own binding rules for payment firms. The Commonwealth's own binding… Full module →
Rhode Island enacted a standalone cybersecurity regime for DBR-licensed nonbank financial institutions (S603, effective July 2, 2025), modeled closely on NYDFS Part 500 but with a more lenient three-business-day breach notification window. This sits alongside… Full module →
SC has no payments-specific operational-resilience/critical-infrastructure regime akin to DORA. Applicable standing framework is the general breach-notification statute (since 2009) and the Insurance Data Security Act, layered under federal GLBA/FFIEC… Full module →
South Dakota does not operate a bespoke operational-resilience regime; resilience obligations for regulated payments/financial entities flow from the federal GLBA Safeguards Rule referenced on the Division's own regulatory-reference page, from Division… Full module →
Tennessee's operational-resilience layer for payments rests on its general breach-notification statute (Tenn. Code §47-18-2107), the 2023 Tennessee Information Protection Act (TIPA) which exempts GLBA-covered financial institutions, and TDFI's own internal… Full module →
Texas imposes a dedicated cybersecurity-incident notification rule on money services businesses (7 TAC §33.30), requiring confidential reporting to the Banking Commissioner of material incidents, layered on top of federal BSA/SAR obligations. A separate… Full module →
Utah's operational-resilience baseline for payments is anchored in the Protection of Personal Information Act (breach notification since 2006, amended 2024) and the Utah Cyber Center's coordination role, rather than a payments-specific operational-resilience… Full module →
Vermont's operational-resilience layer is anchored in the Security Breach Notice Act (9 V.S.A. §§2430, 2435), dual-track DFR/AG notification, most recently amended by Act 89 (2020).
Virginia has no payments-specific operational-resilience regime analogous to DORA; resilience oversight runs through the Secretary of Public Safety and Homeland Security (as Chief Resilience Officer) and university-partnered cybersecurity research… Full module →
Operational resilience obligations for Washington money transmitters are embedded in WAC 208-690 rather than a standalone resilience statute: cybersecurity, business-continuity, recordkeeping and third-party/agent oversight duties are examination-enforced by… Full module →
WV has no DORA-style dedicated financial-sector operational-resilience statute; resilience oversight runs through the Division of Financial Institutions' general examination authority (extended explicitly to third-party IT vendors) layered on top of the… Full module →
Operational resilience rests on the state Data Breach Notification Law and Insurance Data Security Law for OCI licensees, with no dedicated state operational-resilience regime.
Wyoming has no distinct state-level operational-resilience statute for payments/banking; state-chartered banks and SPDIs operate under the federal FFIEC/OCC/FDIC/Federal Reserve examination framework (Business Continuity Management booklet, Cybersecurity… Full module →
BCU is building a graduated cyber-supervision regime for the payments system anchored on AGESIC's national Marco de Ciberseguridad (MCU), starting with mandatory periodic cyber-capability reporting by IEDEs (from 1 July) and continuity/outsourcing-governance… Full module →
No standalone operational-resilience/critical-third-party framework equivalent to DORA or FCA/PRA op-res rules was located for Venezuela. Resilience obligations appear embedded piecemeal within SUDEBAN's general banking-supervision and AML circulars, and… Full module →
Operational resilience is driven by SBV cybersecurity and authentication mandates rather than a single DORA-style instrument. Decision 2345/QD-NHNN (effective 1 July 2024) mandates biometric authentication for high-risk transactions, supplemented by Circular… Full module →
Operational resilience now sits substantially under the Cyber Security Act 2025 and Cyber Crimes Act 2025, designating payment gateways/core banking as critical infrastructure with registration, localisation, audit and incident-reporting duties.
No jurisdiction matches those filters.