Financial services companies and their digital technology suppliers are under intense pressure to achieve compliance with strict new rules from the EU that require them to boost their cyber resilience.
By the start of next year, financial services firms and their technology suppliers will have to make sure that they’re in compliance with a new incoming law from the European Union known as DORA, or the Digital Operational Resilience Act.
CNBC runs through what you need to know about DORA — including what it is, why it matters, and what banks are doing to make sure they’re prepared for it.
What is DORA?
DORA requires banks, insurance companies and investment to strengthen their IT security. The EU regulation also seeks to ensure the financial services industry is resilient in the event of a severe disruption to operations.
Such disruptions could include a ransomware attack that causes a financial company’s computers to shut down, or a DDOS (distributed denial of service) attack that forces a firm’s website to go offline.
Multiple banks, payment firms and investment companies — from JPMorgan Chase and Santander, to Visa and Charles Schwab — were unable to provide service due to the outage. It took these firms several hours to restore service to consumers.
In the future, such an event would fall under the type of service disruption that would face scrutiny under the EU’s incoming rules.
Mike Sleightholme, president of fintech firm Broadridge International, notes that a standout factor of DORA is that it doesn’t just focus on what banks do to ensure resiliency — it also takes a close look at firms’ tech suppliers.
Under DORA, banks will be required to undertake rigorous IT risk management, incident management, classification and reporting, digital operational resilience testing, information and intelligence sharing in relation to cyber threats and vulnerabilities, and measures to manage third-party risks.
Firms will be required to conduct assessments of “concentration risk” related to the outsourcing of critical or important operational functions to external companies.
These IT providers often deliver “critical digital services to customers,” said Joe Vaccaro, general manager of Cisco-owned internet quality monitoring firm ThousandEyes.
“These third-party providers must now be part of the testing and reporting process, meaning financial services companies need to adopt solutions that help them uncover and map these sometimes hidden dependencies with providers,” he told CNBC.
Banks will also have to “expand their ability to assure the delivery and performance of digital experiences across not just the infrastructure they own, but also the one they don’t,” Vaccaro added.
When does the law apply?
DORA entered into force on Jan. 16, 2023, but the rules won’t be enforced by EU member states until Jan. 17, 2025.
The EU has prioritised these reforms because of how the financial sector is increasingly dependent on technology and tech companies to deliver vital services. This has made banks and other financial services providers more vulnerable to cyberattacks and other incidents.
“There’s a lot of focus on third-party risk management” now, Sleightholme told CNBC. “Banks use third-party service providers for important parts of their technology infrastructure.”
“Enhanced recovery time objectives is an important part of it. It really is about security around technology, with a particular focus on cybersecurity recoveries from cyber events,” he added.
Many EU digital policy reforms from the last few years tend to focus on the obligations of companies themselves to make sure their systems and frameworks are robust enough to protect against damaging events like the loss of data to hackers or unauthorized individuals and entities.
The EU’s General Data Protection Regulation, or GDPR, for example, requires companies to ensure the way they process personally identifiable information is done with consent, and that it’s handled with sufficient protections to minimize the potential of such data being exposed in a breach or leak.
DORA will focus more on banks’ digital supply chain — which represents a new, potentially less comfortable legal dynamic for financial firms.
What if a firm fails to comply?
For financial firms that fall foul of the new rules, EU authorities will have the power to levy fines of up to 2% of their annual global revenues.
Individual managers can also be held responsible for breaches. Sanctions on individuals within financial entities could come in as high a 1 million euros ($1.1 million).
For IT providers, regulators can levy fines of as high as 1% of average daily global revenues in the previous business year. Firms can also be fined every day for up to six months until they achieve compliance.
Third-party IT firms deemed “critical” by EU regulators could face fines of up to 5 million euros — or, in the case of an individual manager, a maximum of 500,000 euros.
That’s slightly less severe than a law such as GDPR, under which firms can be fined up to 10 million euros ($10.9 million), or 4% of their annual global revenues — whichever is the higher amount.
Carl Leonard, EMEA cybersecurity strategist at security software firm Proofpoint, stresses that criminal sanctions may vary from member state to member state depending on how each EU country applies the rules in their respective markets.
DORA also calls for a “principle of proportionality” when it comes to penalties in response to breaches of the legislation, Leonard added.
That means any response to legal failings would have to balance the time, effort and money firms spend on enhancing their internal processes and security technologies against how critical the service they’re offering is and what data they’re trying to protect.
Are banks and their suppliers ready?
Stephen McDermid, EMEA chief security officer for cybersecurity firm Okta, told CNBC that many financial services firms have prioritized using existing internal operational resilience and third-party risk programs to get into compliance with DORA and “identify any gaps they may have.”
“This is the intention of DORA, to create alignment of many existing governance programs under a single supervisory authority and harmonise them across the EU,” he added.
Fredrik Forslund vice president and general manager of international at data sanitization firm Blancco, warned that though banks and tech vendors have been making progress toward compliance with DORA, there’s still “work to be done.”
On a scale from one to 10 — with a value of one representing noncompliance and 10 representing full compliance — Forslund said, “We’re at 6 and we’re scrambling to get to 7.”
“We know that we have to be at a 10 by January,” he said, adding that “not everyone will be there by January.”
Financial markets opened September on a firm footing following a solid performance in August, where the S&P 500 gained 2.6% and the tech-heavy Nasdaq Composite rose 3.9%. Corporate earnings across major index constituents showed impressive momentum, with S&P 500 year-over-year earnings growth topping historic averages. However, despite robust corporate balance sheets, equity market valuations face headwinds as benchmark 10-year Treasury yields remain elevated near 4.75%.
The current financial environment is characterized by a strong divergence between corporate earnings resilience and bond market pressure. Enterprise technology leaders, financial institutions, and consumer sectors reported strong profit margins, benefiting from operational efficiency gains and disciplined cost management. Yet, institutional investors remain cautious about expanding price-to-earnings multiples when risk-free benchmark bond yields offer yields near 4.7%.
Fixed income markets continue to reflect restrictive monetary conditions. The broader aggregate bond market recorded flat total returns year-to-date, while fixed income yields—such as 30-day SEC yields on core bond funds—stayed above 4.6%. This yield profile provides institutional and retail investors with meaningful cash flow returns without taking on equity market downside risk, creating a competitive alternative for institutional capital allocation.
Portfolio managers and investment strategists recommend a disciplined, quality-oriented approach entering the final quarter of 2026. Rather than chasing speculative momentum, capital flows are favoring companies with strong cash flow generation, low debt-to-equity ratios, and robust pricing power capable of withstanding elevated input costs.
Why This Information Matters
The tension between strong corporate earnings and elevated bond yields directly impacts portfolio allocations and retirement wealth. Individual investors and wealth managers must balance equity market participation with fixed-income yield opportunities, ensuring portfolios are diversified against sudden valuation adjustments caused by fluctuating benchmark interest rates.
A turbulent week in the U.S. Treasury market prompted the Treasury Department to sharply increase the size of its long-term debt buyback program, as bond prices fell even while equity markets pushed toward record highs. The divergence has drawn attention from fixed-income strategists who see it as a signal of underlying investor unease about federal borrowing levels.
What Happened This Week
U.S. Treasury Secretary Scott Bessent told CNBC on Thursday, August 20, 2026, that the Treasury had doubled the size of its long-term debt buyback operations, moving from roughly $2 billion to at least $4 billion per operation. Bessent indicated the figure could climb further, saying “we’re going to increase the size of the buyback,” and noted the accelerated pace could exceed the announced $4 billion threshold per issue.
Buybacks allow the Treasury to repurchase outstanding government bonds directly from the market, which can help support prices and dampen yield volatility during periods of stress. The expanded program came as stocks staged a late-week recovery: the S&P 500 and Russell 2000 both advanced on Friday, August 21, even as Treasuries logged mild losses, according to Bloomberg market data.
Why Bond and Equity Markets Are Diverging
Capital.com senior market analyst Daniela Hathorn described the week’s dynamic as markets “ending the week on a softer tone after the relative calm of early August was disrupted by renewed pressure in global bond markets, another rise in oil prices, and growing uncertainty around the Federal Reserve’s next move.” She noted that higher long-term borrowing costs are increasingly challenging elevated equity valuations, even as U.S. equities pull back modestly from record highs.
This divergence — equities near record levels while bonds sell off is unusual and reflects two different sets of investor concerns. Equity investors have remained focused on corporate earnings strength, particularly from large technology companies ahead of Nvidia’s closely watched August 26 earnings report. Bond investors, by contrast, are more directly exposed to concerns about the scale of federal borrowing, highlighted this week by the national debt crossing the $40 trillion threshold for the first time.
The Fed and Treasury “Working in Opposite Directions”
Wilmington Trust senior bond portfolio manager Wil Stith told Yahoo Finance that current conditions reflect “the Fed and the Treasury basically working in sort of opposite directions,” adding that the imbalance will likely require the Federal Reserve which he described as having “the larger sandbox” to adjust the federal funds rate rather than relying on Treasury market interventions alone to manage yields.
Notably, the bond market’s reaction to the Treasury’s buyback expansion was relatively muted; strategists described the move as being largely absorbed without a major rally, suggesting the underlying pressure on yields stems from factors, such as inflation persistence and debt sustainability concerns, that a buyback program alone cannot resolve.
What Comes Next
Markets are now looking to two major events in the days ahead: Nvidia’s earnings report on Wednesday, August 26, and the Federal Reserve’s Jackson Hole Economic Symposium, running August 27-29. This will be the first Jackson Hole gathering under new Fed Chair Kevin Warsh, whose public communication style and policy signals remain less established than his predecessors’, according to market commentary from Regards of Wall Street.
For investors, the key metrics to watch are the size and frequency of future Treasury buyback operations, movements in the 10-year Treasury yield, and any policy signals from Warsh’s keynote address. Continued yield volatility alongside record equity valuations would suggest the market imbalance identified this week has not yet been resolved.
The global banking system is undergoing a comprehensive modernization of cross-border payment infrastructure. Driven by real-time settlement networks, open banking APIs, and interoperable messaging standards, financial institutions and multinational corporations are eliminating multi-day delays and reducing transaction costs associated with legacy international wire transfers.
Transition to Real-Time Gross Settlement Networks
Historically, international business-to-business (B2B) payments relied on complex correspondent banking relationships involving intermediary fees and processing delays. In 2026, the widespread adoption of ISO 20022 messaging protocols alongside interconnected Real-Time Gross Settlement (RTGS) systems allows direct, end-to-end processing of cross-border transfers.
Commercial banks are providing corporate clients with continuous, 24/7 payment clearing capabilities. Real-time transaction confirmation and automated FX rate locking allow international businesses to settle cross-border trade obligations within minutes, significantly reducing counterparty risk.
Central Bank Digital Currency (CBDC) Interoperability
Wholesale Central Bank Digital Currency (CBDC) pilot initiatives are reaching operational maturity across several key financial centers. Collaborative multi-CBDC platforms enable participating central banks and commercial institutions to settle foreign exchange and international trade transactions directly on shared distributed ledgers.
These wholesale digital currency networks eliminate traditional clearinghouse delays and minimize foreign exchange slippage. Enterprise treasury departments benefit from enhanced liquidity management, as cross-border cash balances can be deployed and repatriated instantaneously.
Corporate Treasury Transformation
For enterprise treasurers, instant cross-border settlement transforms cash management strategies:
– Working Capital Optimization: Reduced transaction float allows companies to lower precautionary cash reserves and optimize short-term liquidity investments.
– Automated Reconciliation: Enriched data formats embedded in ISO 20022 payment messages streamline automated general ledger posting and invoice matching.
– Reduced Processing Overhead: Account-to-account (A2A) real-time clearing bypasses costly intermediary correspondent banking fees.
Strategic Financial Priorities
1. Upgrade Treasury Systems: Ensure internal core enterprise software supports real-time ISO 20022 payment messaging standards.
2. Leverage Instant Clearing Rails: Utilize direct payment networks to lower cross-border transaction fees and eliminate settlement delays.
3. Evaluate Multi-Currency Liquidity: Modernize liquidity management frameworks to capitalize on 24/7 real-time settlement capabilities.