Back to blog

2026, the ACPR's « year of supervision »: what the regulator will actually look at under DORA

The ACPR made 2026 its DORA supervision year. Control priorities, evidence logic, and what « show me » changes for your teams.

By Arthur Chédeville··Read time : 7 min·For Executives, compliance, CISO
ACPR supervision and DORA oversight

For two years, the supervisor's question was: « where do you stand on DORA? ». In 2026, its nature changes. The ACPR has published its annual work programme and set an unambiguous framework: after a 2025 focused on support, 2026 is the year of supervision. The concrete translation for financial entities: you will no longer be asked to describe your framework, you will be asked to prove it.

This shift is not rhetorical. It comes with explicit control priorities, a reorganisation within the regulator, and a markedly higher documentary standard. Here is what it implies.

Three control priorities for 2026

In its 2026 work programme, the ACPR identified three control priorities regarding information and communication technology (ICT) risk:

  1. Incident management — improving the detection, classification and notification process for major incidents.
  2. ICT risk management frameworks — their effective implementation, and above all the clear identification of the control function.
  3. Contract compliance with IT service providers — the integration of DORA's mandatory clauses into ICT agreements.

These three areas are not theoretical: in 2026, the control teams will carry out targeted initiatives with the entities concerned on each of them. In other words, these are the doors through which the supervisor will enter.

The « expected evidence » logic: the real paradigm shift

The classic trap is having treated DORA as a purely IT or cyber project. What the ACPR controls spans three inseparable dimensions: governance, processes and evidence.

Concretely, for each block of the framework, the supervisor expects documented, traceable elements:

  • Responsibility of the management body → board and committee decisions and minutes, budget trade-offs, remediation tracking.
  • ICT risk management framework → formalised policies, asset mapping, KPIs and KRIs, independence of the control function.
  • Incident management → classification procedure, incident register, timelines, post-mortems, exercises.
  • ICT third parties → up-to-date register of information, due diligence, contractual clauses, concentration analysis.

The message is consistent: a framework that exists on paper but cannot quickly produce its evidence will be considered fragile. Consistency across the different sources (register, incident dashboards, test results) is itself now an object of control.

Supervision that is equipping itself

The tightening is not only in the discourse. The ACPR has reorganised its supervision around a new directorate dedicated to innovation, data and technological risks, bringing together AI and cyber supervision. It has also set up specific teams to steer regulatory data collection and to control the quality of submissions.

On-site inspections now combine documentary analysis with technical tests, with teams including IT profiles able to assess the real effectiveness of declared frameworks — not just their formal existence. In parallel, off-site controls rely on standardised periodic submissions whose consistency is examined.

The completeness of narrative reports: the point that will hurt

Beyond the three priorities, the ACPR has announced particular attention to the completeness of narrative reports. It expects significantly richer information on two areas in particular:

  • The risk profile, including exposure to ICT and provider-related risks.
  • The risk management system, with the indispensable identification of the control function for the ICT risk management framework.

This is an underestimated point. Many entities produced formally compliant but terse submissions. In 2026, an incomplete report becomes a negative signal in itself.

The starting point: many remain « partially compliant »

This tightening rests on a lucid assessment by the regulator: at the end of 2025, despite notable progress, a large number of players remained « partially compliant », particularly on outsourcing risk management — historically the most fragile pillar. As most entities only took up the subject in 2024 or 2025, delays on action plans were widely shared.

In other words, if your framework is not yet fully operational, you are not alone — but the window of leniency is closing.

What this changes for you, concretely

The practical consequence is simple: « doing DORA » is no longer enough, you must be able to demonstrate it on demand. This requires your compliance data to be linked, up to date and exportable without manual reconstruction. A register kept in a frozen file, evidence scattered across teams, incidents documented by hand: all configurations that hold as long as you are not asked to prove, and that give way the day you are.

Where Axenia fits in. For 2026 supervision, the point is no longer to describe a framework: it is to produce evidence on demand. Axenia ties each DORA requirement to its demonstration elements, so your responses to controls stay consistent and current.


This article offers a synthetic reading of the ACPR's public guidance. It does not constitute legal advice. For any compliance decision, refer to the official texts and a qualified professional.

Want to see how Axenia structures your DORA evidence? Book a demo →