NorwayFinanstilsynet
DORA replaces Norway’s ICT rules for additional financial firms
From 1 September 2026, financing, debt-collection and estate-agency firms face adapted DORA requirements. The supervisor specifies temporary incident-reporting channels.
By Taxxa AI OyPublished 31 August 2026
From 1 September 2026, adapted DORA requirements apply to financing companies, debt-collection firms, estate-agency firms and Norsk naturskadepool.Finanstilsynet The same amendment repeals IKT-forskriften.
Lovdata Firms entering the new framework must identify the requirements that apply to their activities, including the specific limits for estate-agency settlement functions and smaller debt collectors.
Financing companies are brought under DORA's governance and risk-management framework in Articles 5–15. Estate-agency firms, debt collectors and Norsk naturskadepool instead use the simplified framework in Article 16. The Norwegian regulation also applies provisions on incident management, resilience testing and ICT third-party risk, with stated adaptations.
For estate-agency firms, incident classification and reporting requirements apply only to incidents related to the settlement function. Their notification duty for ICT-service agreements is similarly limited to services used for that function. For debt collectors, the agreement-notification requirement applies to medium-sized or larger firms. Finanstilsynet describes the notification duty as covering critical or important ICT-service agreements.
The covered firms must keep an entity-level register of ICT-service agreements. The Norwegian minimum-content rules include supplier identifiers, the service description, supplier and subcontractor locations, contract dates or rolling status, and the date of the latest risk assessment. The EU implementing regulation on the standard register template does not apply to this adapted register.
Finanstilsynet says the newly covered firms cannot use Altinn form KRT-3190 for incident reporting for the time being. Serious incidents and cyberthreats must instead be sent to hendelse@finanstilsynet.no. For information the firm considers sensitive, the notice offers KRT-1060, marked “Hendelsesrapportering IKT” in field 2.2, or email with an encrypted, password-protected Word attachment and separately arranged password exchange. Personal data must be protected.
Reports must explain the incident, affected systems or data, known consequences and cause, detection and occurrence times, recovery status and measures. The amendment also allocates threat-led penetration-testing responsibilities between Finanstilsynet and Norges Bank and updates payment-service incident references.
The legal basis is FOR-2026-08-20-1657, particularly DORA-forskriften chapters 2–3 and the repeal of IKT-forskriften, read with Finanstilsynet's reporting notice.
Map the adapted DORA requirements and use Finanstilsynet’s stated interim channels for reportable ICT incidents.