Strengthening Digital Operational Resilience: Lessons from the 2025 Authorisation Cycle - MFSA

https://www.mfsa.mt/publication/strengthening-digital-operational-resilience-lessons-from-the-2025-authorisation-cycle/
Success
Specialism
Obligation
Activity
Themes
Functions
2026-07-09 08:29:50 · tojuri@vixio.com
Meta Id
3306660
Content ID
3315142
GUID
2bbe0627ca4c032cb3010733a18cb0ea

The Malta Financial Services Authority’s (the “Authority”) Circular General Observations on Digital Operational Resilience in Authorisation Applications Received in 2025 offers valuable insights into the evolving state of digital operational resilience across the financial services sector.

Pipeline Progress

🔄 Pipeline Journey

⏱ 18s total
Queued 08:29:31
+0s
Metadata 08:29:31
+0s
S3 Content 08:29:31
+0s
Extracted 08:29:31
+6s
LLM Gen 08:29:37
+12s
Stored 08:29:49
TITLE: Malta Financial Services Authority Publishes Digital Operational Resilience Observations from 2025 Authorisation Cycle BODY: On July 8, 2026, the Malta Financial Services Authority (MFSA) published a circular containing general observations on digital operational resilience in authorisation applications received during 2025. The circular draws on insights gathered during the Authority's review of authorisation applications and highlights common themes and recurring challenges encountered by applicants seeking to demonstrate compliance with the Digital Operational Resilience Act (DORA). The MFSA's observations reveal that while awareness of digital operational resilience requirements continues to grow among applicants, many still face difficulties translating regulatory obligations into effective operational practices. The circular emphasises the importance of developing robust governance arrangements, sound information and communications technology (ICT) risk management processes, effective incident management procedures, and well-structured oversight of third-party ICT service providers. A key message emerging from the circular is that digital operational resilience extends beyond the preparation of policies and documentation. Applicants must demonstrate a clear understanding of how resilience measures operate in practice and how they support the continuity, security, and reliability of their business activities. The Authority notes the importance of ensuring that all submissions are appropriately tailored to the applicant's specific business model and risk profile. The circular identifies areas where applicants generally demonstrated stronger levels of preparedness, particularly in relation to digital operational resilience testing. However, it emphasises the need for continued industry-wide efforts to strengthen resilience frameworks and enhance the practical implementation of DORA requirements. By publishing these observations, the MFSA seeks to support both prospective and existing licence holders in their preparation for authorisation processes. The publication reinforces the Authority's commitment to promoting a resilient financial sector capable of managing ICT-related risks and adapting to an increasingly complex digital environment.
  • Scraped:2026-07-09 08:29:50
  • Created:2026-07-09 08:29:49
  • By:tojuri@vixio.com (9)