There is no single DORA-equivalent across the bloc; resilience is built into national payments vision documents and cyber directives. SARB has issued a directive on cybersecurity and cyber-resilience within the national payment system. Nigeria's Payments… Full module →
Operational Resilience & Critical Infrastructure
W3Every jurisdiction World Payments Monitor tracks for W3, with the standing position recorded in the current weekly cycle. Each entry links to the full module on that jurisdiction’s page, where the sourced findings and evidence sit.
Algeria adopted its first comprehensive cybersecurity governance architecture in 2025-2026, designating financial services as critical information infrastructure with a 5-day breach-reporting window.
BCRA operational-resilience and cyber rules apply on a functional basis to banks, PSPs (digital wallets, aggregators, facilitators) and systemically important payment systems. Core instruments are the IT/information-security risk standard (Com. "A" 7724… Full module →
APAC operational-resilience obligations sit within national frameworks rather than a single regime like DORA. Hong Kong's critical-infrastructure / CCS regime carries real-time incident reporting and severe fines; India imposes data-localisation and… Full module →
Operational resilience for APRA-regulated entities (incl. ADIs/banks providing payments) is governed by Prudential Standard CPS 230 Operational Risk Management, in force 1 July 2025, replacing CPS 231 (Outsourcing) and CPS 232 (Business Continuity… Full module →
DORA (Regulation (EU) 2022/2554) has applied to Austrian payment institutions since 17 January 2025, embedding ICT risk-management, incident-reporting and third-party-register obligations into the FMA's supervisory file.
Bangladesh Bank has substantially escalated operational-resilience regulation in 2025-2026, moving from the long-standing ICT Security Guideline (v4.0, 2023) to a first-ever sector-wide, technology-neutral Cybersecurity Framework, Version 1.0 (2026)… Full module →
DORA has applied since 17 January 2025 across Belgian financial entities including PIs/EMIs, with NBB and FSMA as competent authorities. NBB runs TIBER-BE and requires ICT incident reporting via OneGate; SWIFT oversight is being strengthened with NBB as lead… Full module →
Operational resilience is governed by CMN Resolution 4.893/2021 (financial institutions) and BCB Resolution 85/2021 (payment institutions), effective from 2021, which mandate cybersecurity policies, incident response, business-continuity testing, and rules… Full module →
DORA has applied directly in Bulgaria since 17 January 2025, with BNB and FSC as enforcing authorities. Bulgaria faced EU infringement action for incomplete transposition of enabling national legislation. BNB is actively auditing bank-sector DORA-preparedness… Full module →
Bakong, the NBC's blockchain-based interbank/retail settlement rail, continues rapid scale-up; H1 2026 volumes reached roughly 1 billion transactions worth USD 135.8bn, with a marked mix-shift toward Khmer riel settlement.
Operational resilience obligations are distributed across COBAC's PSP operational-requirements regulation, the national Cybersecurity Law, and a CEMAC-wide technical-standardisation body (CORENOFI) which is compelling ISO 20022 migration by November 2025… Full module →
Operational resilience for non-bank PSPs runs through the RPAA's operational-risk-management and incident-response obligations (in force September 8, 2025), supervised by the Bank of Canada. Systemic payment infrastructure (Lynx) is designated under the… Full module →
Operational resilience for Alberta-touching non-bank PSPs is governed by the RPAA's operational risk management and incident response framework, in force since September 8, 2025, with material-incident notification and annual reporting obligations.
Canada's national payments infrastructure is undergoing its most significant modernization in decades: the RTR by-law and rules were approved and come into force August 24, 2026, ahead of Q3/Q4 2026 launch, running alongside the existing ACSS batch and Lynx… Full module →
Operational resilience for retail payments in NB (as elsewhere in Canada) is governed federally by the RPAA's risk management and incident response (RMIR) framework administered by the Bank of Canada, which prescribes written risk-management frameworks… Full module →
The RPAA's operational risk-management framework (in force since September 8, 2025) requires PSPs to manage risks that could reduce, deteriorate or break down retail payment activities; OSFI's 2025-26 Annual Risk Outlook flags state-actor threats; the… Full module →
The Bank of Canada's RPAA-based Operational Risk and Incident Response supervisory guideline governs PSP operational resilience, with a binding 48-hour material-incident notification rule and mandatory third-party risk management, in force alongside… Full module →
Two regimes apply: sectoral CMF cybersecurity/operational-resilience rules in the RAN (20-7 outsourcing, 20-8 operational-incident information, 20-9 business continuity, 20-10 information security & cybersecurity) for banks, their support companies, and card… Full module →
Operational resilience sits within China's cyber/data-security stack: amended Cybersecurity Law (in force 1 Jan 2026) tightens CIIO obligations; Network Data Security Regulations and sector-specific financial data-security measures create graded… Full module →
Colombia's operational-resilience/data-sharing regime is anchored by the mandatory Sistema de Finanzas Abiertas (Decreto 0368 de 2026, signed 7 Apr 2026, amending Decreto 2555/2010 per Art. 89 Ley 2294/2023), superseding the voluntary Decreto 1297/2022 scheme… Full module →
Costa Rica's operational-resilience posture was shaped decisively by the April 2022 Conti/Hive ransomware campaign against government systems, which triggered a national state of emergency. IT/outsourcing risk management for the regulated financial sector… Full module →
DORA (Regulation (EU) 2022/2554) entered into application EU-wide from 17 January 2025, with HNB and HANFA jointly coordinating implementation for Croatian financial entities. Croatia faces above-average third-party ICT dependency and limited specialist… Full module →
CBCS maintains a dedicated IT, Cyber & Operational Risk supervisory pillar (IT Governance, Business Continuity Management, Information Security Management provisions) and has flagged fintech/cyber risk as a priority in its 2026-2028 Research Agenda… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT… Full module →
DORA (Regulation (EU) 2022/2554) became fully applicable in the Czech Republic on 17 January 2025, transposed via the Act on the Digitalisation of the Financial Market (Act No. 31/2025 Coll.), with the CNB as DORA supervisory/sanctioning authority working… Full module →
Denmark's payments infrastructure is highly digitised (>90% of payments digital) but experienced two nationwide outages (July 2025, May 2026); Danmarks Nationalbank has responded by launching a Payments Council-coordinated offline card contingency and is… Full module →
Operational resilience is set by SIPARD's minimum technological requirements built on CPMI-IOSCO PFMI; BCRD's LBTR (since 2008) underpins systemic-risk reduction; SB began a structured cybersecurity dialogue in 2026.
Operational resilience is governed by the SB's Norma de Control para la Gestión del Riesgo Operativo, mandating ISO 22301-based BCM and ISO 27000-based information-security management, layered with BCE cybersecurity standards for the new instant-payments… Full module →
Operational resilience is anchored by the CBE's Financial Cybersecurity Framework (the first such sectoral framework in Egypt) plus a dedicated CBE cybersecurity sector and the country's first financial-sector CERT. Outsourcing of services and data hosting by… Full module →
DORA applies directly in Estonia since 17 January 2025 with Finantsinspektsioon as NCA across banks, PIs, EMIs and CASPs.
DORA was incorporated into the EEA Agreement by the EEA Joint Committee (Feb 2026 written procedure, alongside MiCA), entering into force in the EFTA pillar once constitutional requirements are cleared.
Finland is in the euro-area SEPA Instant Credit Transfer (SCT Inst) / Instant Payments Regulation (EU 2024/886) implementation phase: mandatory receipt of instant credit transfers since 9 January 2025, mandatory sending since 9 October 2025, and mandatory… Full module →
SEPA Instant Verification-of-Payee (VoP) has been mandatory since 9 October 2025 under the Instant Payments Regulation (EU) 2024/886, directly affecting Wero/Paylib instant-transfer operators (BNP Paribas, BPCE, Crédit Agricole, Société Générale, Crédit… Full module →
DORA directly applicable since 17 Jan 2025 + FinmadiG; BaFin national ICT hub, 4-hour deadline; first DORA fine EUR 450k Q3 2025; 600+ incidents registered.
Ghana's Cyber Security Authority (CSA), under the Cybersecurity Act 2020 (Act 1038), actively enforces licensing of Cybersecurity Service Providers to owners of Critical Information Infrastructure — including payment-system infrastructure operators. Recent… Full module →
Gibraltar has implemented a UK-equivalent Operational Resilience regime: the GFSC published Operational Resilience, Outsourcing/Third-Party Risk Management and Liquidity Risk Management Guidance Notes in 2024 following industry consultation. Firms identify… Full module →
DORA applies since 17 January 2025; Law 5193/2025 Articles 148-152 designate BoG as competent authority for credit institutions/PIs/EMIs and HCMC for investment/securities entities and CASPs. BoG supervisory commentary (Oct 2025) flags payment firms and EMIs… Full module →
Hong Kong's FPS underwent its first-ever scheduled 10-hour outage (9 Aug 2026), also the first outage affecting Payment Connect since June 2025 launch.
DORA (Regulation (EU) 2022/2554) applies in Hungary from 17 January 2025, implemented domestically via a 10 April 2024 Implementing Law that names the MNB as competent authority and layers a national CSIRT dual-reporting duty and a simplified 'Mini DORA'… Full module →
Iceland's central bank has agreed with the ECB to join the Eurosystem's TARGET Instant Payment Settlement (TIPS) system, with Icelandic-króna instant settlement in central-bank money going live in 2028 — a first-order infrastructure modernisation for a… Full module →
Operational resilience for payments rests on the RBI Master Directions on Cyber Resilience and Digital Payment Security Controls for non-bank PSOs (July 2024), the Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective 1 April… Full module →
The EU Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554) has applied since 17 January 2025; the CBI supervises DORA compliance for in-scope firms (including credit institutions, investment firms, CASPs, PIs and EMIs), embedding ICT risk… Full module →
There is no Isle of Man equivalent to DORA; operational resilience obligations for licenceholders derive from FSA08-era guidance (the Operational Risk Guidance Note and Outsourcing/Delegation of Functions guidance) rather than a standalone resilience statute… Full module →
Italy's operational-resilience regime for payment/e-money institutions is anchored in the Disposizioni di vigilanza per gli IP e IMEL, updated by Banca d'Italia's 3 February 2026 provvedimento to transpose DORA, its delegated acts, and the PSD2-amending… Full module →
There is no DORA-equivalent consolidated operational-resilience instrument in UEMOA. Operational resilience is embedded in BCEAO payment-system oversight (STAR-UEMOA/SICA-UEMOA risk management) and Banking Commission supervision of governance and information… Full module →
Operational resilience for the financial sector is delivered through the FSA's Comprehensive Supervision Guidelines for Major Banks (which embed operational-resilience expectations) referencing the Guidelines on Cybersecurity for the Finance Sector (published… Full module →
Operational resilience runs through the 2015 Informatization Law's critical-infrastructure cyber-risk obligations, the 2023-2029 national Digital Transformation/Cybersecurity Concept, and NBK's 2022 mandatory cybersecurity-protocol directive to financial… Full module →
Operational resilience for non-bank PSPs is anchored in the CBK Guideline on Cybersecurity for Payment Service Providers (July 2019), issued under s.31(2)(b) NPS Act, mandating board-level cyber governance, a CISO, written policies, dependency/third-party… Full module →
Operational resilience is governed by the Law on Cybersecurity No. 87/NA (2025), which established a 24-hour Cyber Command Center and National Cybersecurity Operations Center, building on the 2015 Law on Prevention and Combatting Cyber Crime (which created… Full module →
C&M Software (30 Jun 2025, ~R$800m–>R$1bn) and Sinqia (Aug 2025, ~R$710m) Pix-rail breaches exposed PSTIs as a systemic single point of failure; BCB/CMN cyber resolutions in force 18 Dec 2025, full compliance 1 Mar 2026.
DORA applies since 17 Jan 2025; national complementary law effective 1 Oct 2025; EC infringement procedure opened March 2025 remains unresolved (CAUTION).
DORA is fully in force in Liechtenstein via the EEA-DORA Implementation Act, with accelerated national application from 1 February 2025 and full incorporation into the EEA Agreement effective 1 July 2025, superseding the previous FMA Directive 2021/3… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, supervised by the Bank of Lithuania as integrated financial supervisor across banks, insurers, EMIs/PIs and investment firms. Obligations cover… Full module →
Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable since 17 January 2025, with the Luxembourg implementing law published 2 July 2024 designating the CSSF and CAA as competent authorities. The CSSF issued Circulars… Full module →
AMCM has built out a dense technology-and-cyber-risk supervisory stack since 2019, anchored in dedicated circulars on cyber risk management, electronic-banking risk, outsourcing and cloud outsourcing, most recently refreshed for the insurance sector in 2025… Full module →
TR PD issued 12 March 2026, consolidating technology-risk governance into a four-tier proportionality structure; BNM enforcement record shows escalating cybersecurity-related penalties including Bank Rakyat's second AMP in seven months.
DORA (EU 2022/2554) applicable 17 Jan 2025; MFSA designated national supervisor (TLPT under Legal Notice 166 of 2024, TIBER-MT); annual RoI submission 1 Jan-21 Mar from 2026 reflecting 31 Dec prior-year status.
Mexico has no standalone operational-resilience regulation (no DORA equivalent). Resilience, cybersecurity and incident-reporting obligations are assembled from CNBV's Circular Única de Bancos (CUB) for banks, CNBV cybersecurity/information-security… Full module →
Operational resilience rests on cybersecurity Law 05-20 (Dahir 1-20-69, 25 July 2020) and implementing Decree 2-21-406 (2021), with DGSSI (attached to National Defence) as national cyber authority and maCERT for incident response; the National Directive on IS… Full module →
BM launched the Mozambique Instant Payment System (SPIM/METIX) under Notice 1/GBM/2026, operated by the Interbank Society of Mozambique (SIMO), running 24/7 with per-transaction daily limits of 200,000 MZN for individuals and 500,000 MZN for legal entities… Full module →
CBM-NET (Myanmar's RTGS/CSD platform, live since January 2016) carries formal Business Continuity Planning guidelines, but the wider payments operating environment suffers acute, recurring operational-resilience stress from conflict-driven telecom… Full module →
NRB operates the RTGS system under the Payment System Related Unified Directives, 2081 and has published a Framework for Identifying Systemically Important Payment Systems (SIPS), formalising a systemic-risk-based oversight tier aligned to PFMI-style… Full module →
Operational resilience is governed by the EU DORA Regulation (EU 2022/2554), applicable from 17 January 2025, which applies directly to Dutch PIs, EMIs, banks, investment firms and MiCA CASPs. DNB is the designated competent authority (with AFM for conduct… Full module →
RBNZ launched a payments-modernisation consultation (issues paper, ~18 Aug 2026) proposing to overhaul NZ's retail payments infrastructure — including instant-payments capability — citing an estimated NZ$700m-$1.3bn/year economic benefit; submissions close 27… Full module →
Operational resilience is governed primarily by the CBN Risk-Based Cybersecurity Framework, first effective 1 January 2019 for DMBs/PSPs and replaced by a May 2024 version for DMBs and Payment Service Banks (with a separate 2022 OFI framework), structured… Full module →
Norges Bank is building next-generation settlement infrastructure: committed to NBO INST (instant NOK settlement) with a 2026 decision-basis target; signed a November 2024 agreement with the ECB to join TIPS; began a February 2025 investigation into joining… Full module →
SBP's Technology Risk Management Framework for Payment Institutions (Oct 2025) sets cyber-risk-control, governance and incident-reporting requirements for PSOs/PSPs/EMIs, with a 31 March 2026 compliance deadline.
Panama's operational-resilience framework for regulated financial entities rests on a set of pre-DORA SBP agreements covering outsourcing, electronic banking, and IT risk management, with cloud-service use outside Panama requiring prior SBP/SMV approval or… Full module →
Operational resilience for SBS-supervised entities governed by Resolucion SBS 504-2021 (proportionate three-tier SGSI-C), complementing Res. 2116-2009. The new BCRP payments regulation (Circular 0022-2025-BCRP) extends analogous cybersecurity expectations… Full module →
Operational resilience runs through the Payment System Oversight Framework (Circular 1089), which designates Systemically/Prominently Important Payment Systems and applies the BIS-IOSCO PFMI (adopted via Circular 1126). The Peso RTGS (PhilPaSSplus) and… Full module →
Resilience rests on EU DORA (directly applicable) plus NBP oversight of systemically important payment systems and KNF supervision. Critical retail infrastructure (Elixir, Express Elixir, BLIK) is overseen by NBP under the Settlement Finality Act and… Full module →
DORA (Regulation (EU) 2022/2554) has been fully applicable since 17 January 2025, with Banco de Portugal designated as the national ICT-incident focal point and mandated to cooperate formally with ASF and CMVM. This layers atop pre-existing PSD2-based… Full module →
Qatar's operational-resilience regime for banks rests on the QCB Technology Risks circular (2018), covering cybersecurity governance, IT operations, enterprise security, business continuity and fraud prevention, with a one-hour incident-reporting requirement… Full module →
Operational resilience is governed by EU DORA (Regulation 2022/2554), in application since 17 January 2025, supplemented nationally by Emergency Ordinance No. 14/2026 designating the BNR and ASF as competent authorities (with DNSC involvement). DORA imposes… Full module →
Financial-sector operational resilience sits within Russia's Critical Information Infrastructure (CII) regime under Federal Law 187-FZ (2017, in force since Jan 2018), which lists banking and other financial-market areas among protected CII sectors… Full module →
Operational resilience for BNR-regulated institutions is governed by Regulation N° 50/2022 of 17/06/2022 on Cyber Security in Regulated Institutions, issued under the BNR, banking, MFI and payment-system laws, mandating protection-detection-response-recovery… Full module →
Operational resilience for SAMA-regulated entities (banks, PSPs, finance and insurance firms) rests on the SAMA Cyber Security Framework (v1.0, May 2017), the Business Continuity Management Framework, and the Cyber Resilience Fundamental Requirements (CRFR)… Full module →
BCEAO manages SICA-UEMOA and STAR-UEMOA under Regulation n°15/2002/CM/WAMU; GIM-UEMOA holds PCI DSS 4.0.1 Level-1 certification.
Operational and ICT resilience for Serbian payment service providers rests on two tracks: sector-specific NBS rules under the Law on Payment Services (operational/security risk management, incident notification to the NBS) and the horizontal Law on… Full module →
MAS frames operational resilience around four pillars — operational risk, technology & cyber risk, third-party risk, and business continuity management. The Technology Risk Management (TRM) Guidelines (revised January 2021) and Business Continuity Management… Full module →
NBS operates TARGET2-SK and SIPS for clearing/settlement and provides Eurosystem TIPS instant-settlement service; EU Instant Payments Regulation 2024/886 obligations phased in through 9 October 2025.
Banka Slovenije rolled out instant-payment sending and payee-verification services to public-sector budget spending units under the Bank of Slovenia Act, aligning public-sector payment terms with IPR requirements, and is expanding ZPlaSSIED-based PSP… Full module →
SARB has withdrawn recognition of PASA as the Payment System Management Body, transferring rule-making, licensing, authorisation and registration functions to SARB itself and to PayInc, effective 2 September 2026, as part of the Payments Ecosystem… Full module →
Korea has no single DORA-equivalent instrument; operational resilience for the financial sector is built on the EFTA and its subordinate Regulation on Supervision of Electronic Financial Transactions plus FSC IT-outsourcing and cloud-use guidelines… Full module →
DORA directly applicable since 17 Jan 2025; CNMV 74-question FAQ (early 2026); FSB Nov-2025 peer review confirms robust BdE cyber supervision.
CBSL regulates technology/cyber risk via Banking Act Directions No. 16 of 2021 (amended Dec 2023) and a parallel Technology Risk & Resilience framework for licensed finance companies; licensed banks must report IT/cybersecurity incidents to CBSL; the RTGS… Full module →
The Riksbank's RIX-INST system underlies Swedish instant payments; Payments Report 2026 sets a March 2027 target for banks to offer instant A2A transfers via internet/mobile banking beyond Swish, with EU-modelled legislation threatened if the market fails to… Full module →
The core operational-resilience instrument is FINMA Circular 2023/1 'Operational risks and resilience – banks', in force since 1 January 2024, which integrates the Basel Committee's 2021 operational-resilience principles and covers governance, ICT/cyber… Full module →
Taiwan's operational-resilience regime combines the cross-sector Cybersecurity Management Act (critical-infrastructure designation) with FSC-specific financial-sector cybersecurity action plans, supply-chain and cloud-outsourcing rules, and 2025 legislative… Full module →
BoT operates and oversees the systemically important payment infrastructures — TISS (real-time gross settlement, since 2004), the Tanzania Automated Clearing House (TACH/ECH since 2002), EFT, and the Tanzania Instant Payment System (TIPS). Resilience is… Full module →
Operational resilience for payment providers is governed by BOT IT-risk supervision and information-security notifications under the PSA, requiring business-continuity planning, incident response, backup systems and third-party/outsourcing oversight. BOT… Full module →
The BCT's payment-systems oversight function (established under Law 2016-35) targets security, stability, soundness and efficiency of national payment systems, complemented by Circular 2018-16 security/business-continuity obligations for payment institutions… Full module →
Operational resilience for Turkish payments draws on the CBRT's information-systems communiqué for PIs/EMIs and the BDDK's 2020 banking IT regulation (Regulation on Banks' Information Systems and Electronic Banking Services). Institutions must run annual… Full module →
BoU issued mandatory Cyber and Technology Risk Management Guidelines for all supervised financial institutions effective 1 December 2024, layered on the NPSA's 24-hour fraud/breach notification obligation for payment providers. The Computer Misuse (Amendment)… Full module →
The NBU oversees payment-infrastructure resilience under Regulation No. 187 (2022), which mandates incident reporting and 2-hour recovery for systemically important payment systems; wartime conditions have forced an unusually mature operational cyber-defence… Full module →
Operational resilience for onshore institutions is built from sector regulations rather than a single DORA-style instrument: the CBUAE Operational Risk Management Regulation/Standards, the Outsourcing Regulation & Standards for Banks (covering material… Full module →
UK operational resilience rests on the FCA/PRA op-res framework plus the Critical Third Parties (CTP) regime introduced under FSMA 2023 (finalised in PS24/16). A new unified operational-incident and material-third-party reporting regime was finalised in March… Full module →
The US has no single statutory operational-resilience regime equivalent to EU DORA; resilience is delivered through supervisory guidance from the prudential banking agencies. The cornerstone is the June 2023 Interagency Guidance on Third-Party Relationships… Full module →
Alabama's operational-resilience layer for payments data is anchored in the 2018 Data Breach Notification Act (the last such law enacted among U.S. states) and the newly signed but not-yet-effective Alabama Personal Data Protection Act (2026). There is no… Full module →
Alaska has no bespoke operational-resilience statute; resilience obligations flow from (a) statutory examination cadence for state-chartered banks under Title 6, (b) federal FFIEC/OCC/FDIC cybersecurity supervisory guidance applicable to Alaska-domiciled… Full module →
Arizona has no dedicated payments-specific operational-resilience or critical-infrastructure statute analogous to DORA. Safety-and-soundness supervision of state-chartered banks runs through DIFI's CAMELS examination framework, aligned with federal… Full module →
Arkansas has no bespoke state operational-resilience regime for payment/financial institutions; resilience oversight of the state's 70 state-chartered banks flows through FFIEC-aligned federal examination standards applied jointly by the Arkansas State Bank… Full module →
There is no California-specific operational-resilience regime; resilience for payments in California flows from the federal layer — the Federal Reserve's instant-payments infrastructure (FedNow) and the private RTP network, both ISO 20022-based, plus federal… Full module →
Operational resilience for Colorado payment entities is embedded in the money-transmitter examination/recordkeeping regime (quarterly NMLS reporting, agent-roster reporting, record-retention rules) rather than a dedicated op-res statute, supplemented by a… Full module →
Connecticut lacks a DORA-style dedicated payments operational-resilience regime; resilience obligations arise via the state's data-breach-notification statute, a NIST/ISO/CIS-based cybersecurity safe-harbor law, and PCI DSS as applied to any business handling… Full module →
Operational resilience for payments-relevant data is governed primarily by Delaware's data breach notification statute (6 Del.C. Ch.12B), requiring reasonable security practices, resident notification within 60 days, Attorney General notification above 500… Full module →
DC has no standalone operational-resilience statute; DC-chartered banks and DISB-licensed nonbanks fall under the federal interagency cybersecurity/operational-resilience framework (OCC/FDIC/Federal Reserve), with DISB coordinating examinations jointly with… Full module →
Florida has no DORA-style prudential operational-resilience regime specific to payments; the operative baseline protection is the Florida Information Protection Act (FIPA), a strict 30-day breach-notification law enforced by the Attorney General, supplemented… Full module →
Georgia has no standalone payments-specific operational-resilience statute analogous to DORA; resilience oversight flows through DBF's third-party service-provider examination authority over state-chartered banks/credit unions and federal FFIEC/BSA-linked… Full module →
Hawaii lacks a DORA-style ICT/critical-third-party resilience regime. Operational resilience for licensed financial institutions runs through DFI's examination/enforcement rules (HAR Chapters 26-27) and the state's general security-breach notification law… Full module →
Idaho has no state-specific operational-resilience statute for payments; state-chartered banks/credit unions are examined under the federal/CSBS InTREx framework and FFIEC guidance.
Illinois operational resilience obligations for payments-adjacent entities run through IDFPR's Division of Banking IT-examination authority for state-chartered institutions and, since 2025, through DACPA's explicit cybersecurity/business-continuity mandate… Full module →
DFI supervises IT/operational risk via FFIEC-aligned advisory letters, transitioning to NIST CSF 2.0.
Iowa's operational-resilience posture for payments rests on general-purpose statutes rather than a payments-specific op-res regime: the Security Breach Notification law (Chapter 715C) governs incident disclosure for financial-account data, the Insurance Data… Full module →
Kansas layers a GLBA-equivalent information-security statute onto covered financial institutions (including money transmitters), a state security-breach notification law with tight timing obligations, and a distinct public-sector cybersecurity… Full module →
Kentucky has no payments-specific operational-resilience regime; the operative framework is the general information-security/breach-notification statute (KRS 365.732, in force since 2015), which exempts GLBA-covered financial institutions in favor of federal… Full module →
Louisiana does not maintain a bespoke state-level operational-resilience regime for payments firms; resilience obligations flow chiefly from the federal Gramm-Leach-Bliley Act (GLBA) Safeguards Rule applicable to money transmitters as "financial… Full module →
Maine has no DORA-equivalent operational-resilience/critical-third-party statute; resilience runs through generic GLBA-consistent infosec rules and BFI's standard IT/BSA examination cycle.
Maryland lacks a dedicated payments-sector operational-resilience statute equivalent to DORA; resilience obligations for payments/financial entities instead flow from the state's general data-breach notification law (PIPA), sector-specific insurance-carrier… Full module →
Massachusetts operational-resilience exposure for payments firms runs through the state's data-security regime (M.G.L. c.93H / 201 CMR 17.00) requiring a Written Information Security Program and breach notification to the AG and OCABR, plus the new c.169B/209… Full module →
Michigan's operational-resilience layer combines MCL 445.72 breach notification, DIFS cybersecurity event notification (Form FIS 2359), and PA 690 of 2018 for insurance licensees. A five-bill reform package (SB 360-364), passed by the Senate August 2025… Full module →
Minnesota lacks a payments-sector-specific operational resilience statute akin to DORA; resilience obligations for payments-adjacent entities instead arise from general data-breach notification law, a public-sector cybersecurity incident reporting mandate… Full module →
Mississippi lacks a dedicated operational-resilience regime; resilience obligations arise from DBCF's general examination authority, the newly enacted licensee-specific Data Security for Money Transmitters Act (2026), and the state's general data-breach… Full module →
Operational resilience runs through federal FFIEC/FDIC guidance and CIRCIA, layered with the new state Insurance Data Security Act (effective Jan 1 2026).
Montana's operational-resilience posture rests on breach-notification statutes requiring immediate AG notification ahead of consumer notice.
Operational-resilience obligations in Nebraska run primarily through data-breach/cybersecurity statutes rather than a dedicated payments-resilience regime: the Financial Data Protection and Consumer Notification of Data Security Breach Act of 2006 sets… Full module →
Nevada has no general cross-sector payments operational-resilience statute; the standing regime is sector-specific to gaming payments via Regulation 14.
NH layers state breach-notification (RSA 359-C) and insurance-sector cybersecurity reporting (RSA 420-P) atop federal operational-resilience expectations; third-party vendor risk materialised via the 2025 Marquis Software Solutions ransomware incident.
New Jersey imposes cybersecurity/incident-reporting obligations on DOBI-regulated entities via Regulation 22-05 and a general data-breach duty under the Identity Theft Prevention Act, with S3100 still pending.
No standalone NM operational-resilience regime; federal FFIEC/GLBA/NCUA baseline applies.
NYDFS's 23 NYCRR Part 500 cybersecurity regulation (Second Amendment, adopted Nov. 2023) has reached full implementation as of 2026, with NYDFS now in active enforcement mode against covered financial-services and payments entities, evidenced by a $2 million… Full module →
NC has no payments-specific operational-resilience regime akin to DORA; resilience flows from the ITPA breach law, federal GLBA safeguards, and CIRCIA critical-infrastructure reporting, layered on NCCOB's own breach intake.
ND operational resilience runs on two tracks: depository institutions (banks/credit unions) are examined by NDDFI on a roughly 18-24 month cycle aligned to FFIEC/NCUA IT-examination frameworks, while non-depository payments-adjacent licensees (money… Full module →
Ohio has no bespoke state operational-resilience statute for payments; resilience obligations for MTL licensees flow through ORC 1315.081 (mandatory written reporting of specified events within 15 business days) and DFI examination powers, layered on top of… Full module →
Operational resilience in Oklahoma is governed principally through the data-security and breach-notification lens rather than a dedicated payments operational-resilience regime. The Security Breach Notification Act was substantially overhauled effective… Full module →
Operational-resilience obligations touching Oregon-chartered and nationally chartered banks operating in the state derive almost entirely from the federal layer: the OCC/Fed/FDIC computer-security incident notification rule (12 CFR 53) and FFIEC/NIST… Full module →
Pennsylvania lacks a payments-specific operational-resilience regime; DoBS points regulated entities to federal FFIEC/OCC/FDIC/Fed third-party risk guidance rather than issuing its own binding rules for payment firms. The Commonwealth's own binding… Full module →
Rhode Island enacted a standalone cybersecurity regime for DBR-licensed nonbank financial institutions (S603, effective July 2, 2025), modeled closely on NYDFS Part 500 but with a more lenient three-business-day breach notification window. This sits alongside… Full module →
SC has no payments-specific operational-resilience/critical-infrastructure regime akin to DORA. Applicable standing framework is the general breach-notification statute (since 2009) and the Insurance Data Security Act, layered under federal GLBA/FFIEC… Full module →
South Dakota does not operate a bespoke operational-resilience regime; resilience obligations for regulated payments/financial entities flow from the federal GLBA Safeguards Rule referenced on the Division's own regulatory-reference page, from Division… Full module →
Tennessee's operational-resilience layer for payments rests on its general breach-notification statute (Tenn. Code §47-18-2107), the 2023 Tennessee Information Protection Act (TIPA) which exempts GLBA-covered financial institutions, and TDFI's own internal… Full module →
Texas imposes a dedicated cybersecurity-incident notification rule on money services businesses (7 TAC §33.30), requiring confidential reporting to the Banking Commissioner of material incidents, layered on top of federal BSA/SAR obligations. A separate… Full module →
Utah's operational-resilience baseline for payments is anchored in the Protection of Personal Information Act (breach notification since 2006, amended 2024) and the Utah Cyber Center's coordination role, rather than a payments-specific operational-resilience… Full module →
Vermont's operational-resilience layer is anchored in the Security Breach Notice Act (9 V.S.A. §§2430, 2435), dual-track DFR/AG notification, most recently amended by Act 89 (2020).
Virginia has no payments-specific operational-resilience regime analogous to DORA; resilience oversight runs through the Secretary of Public Safety and Homeland Security (as Chief Resilience Officer) and university-partnered cybersecurity research… Full module →
Operational resilience obligations for Washington money transmitters are embedded in WAC 208-690 rather than a standalone resilience statute: cybersecurity, business-continuity, recordkeeping and third-party/agent oversight duties are examination-enforced by… Full module →
WV has no DORA-style dedicated financial-sector operational-resilience statute; resilience oversight runs through the Division of Financial Institutions' general examination authority (extended explicitly to third-party IT vendors) layered on top of the… Full module →
Operational resilience rests on the state Data Breach Notification Law and Insurance Data Security Law for OCI licensees, with no dedicated state operational-resilience regime.
Wyoming has no distinct state-level operational-resilience statute for payments/banking; state-chartered banks and SPDIs operate under the federal FFIEC/OCC/FDIC/Federal Reserve examination framework (Business Continuity Management booklet, Cybersecurity… Full module →
BCU is building a graduated cyber-supervision regime for the payments system anchored on AGESIC's national Marco de Ciberseguridad (MCU), starting with mandatory periodic cyber-capability reporting by IEDEs (from 1 July) and continuity/outsourcing-governance… Full module →
No standalone operational-resilience/critical-third-party framework equivalent to DORA or FCA/PRA op-res rules was located for Venezuela. Resilience obligations appear embedded piecemeal within SUDEBAN's general banking-supervision and AML circulars, and… Full module →
Operational resilience is driven by SBV cybersecurity and authentication mandates rather than a single DORA-style instrument. Decision 2345/QD-NHNN (effective 1 July 2024) mandates biometric authentication for high-risk transactions, supplemented by Circular… Full module →
Operational resilience now sits substantially under the Cyber Security Act 2025 and Cyber Crimes Act 2025, designating payment gateways/core banking as critical infrastructure with registration, localisation, audit and incident-reporting duties.
No jurisdiction matches those filters.