EstoniaFinantsinspektsioon
Estonia sets 2026 year-end DORA register round, adds TIBER-EE testing guide
The DORA information-register round is collected in early 2027 as of 31 December 2026, and a new section sets threat-led testing under the TIBER-EE national guide.
By Taxxa AI OyPublished 28 September 2026
Estonian financial firms face two updates on the Finantsinspektsioon DORA pages: next year's information-register collection now has its as-of date, and threat-led penetration testing in Estonia runs under the national TIBER-EE application guideFI.
The register collection moves one year forward. Under the European Supervisory Authorities' joint decision, the ESAs collect registers of information annually through the national supervisors to designate critical third-party ICT providers across Europe; consolidated groups file jointly at the highest level, and each collection reflects the preceding calendar year-end. The current round covers registers as of 31 December 2026FI
FI, collected in early 2027
FI — one year on from the previous early-2026 round as of 31 December 2025. Firms file the register through the Eesti Pank and Finantsinspektsioon data-collection portal at https://aruandlus.eestipank.ee, accessible to board members, other registered representatives and their authorised persons with ID-card, Mobiil-ID or Smart-ID authentication.
The section on threat-led penetration testing and TIBER-EE states that financial firms designated by the competent authority under Article 26 of Regulation (EU) 2022/2554 must carry out threat-led penetration testing to assess digital operational resilience by imitating real attackers under controlled conditionsFI. Detailed testing requirements and the criteria for identifying the firms required to test are laid down in Commission Delegated Regulation (EU) 2025/1190
FI. In Estonia, testing follows the national TIBER-EE application guide, which describes how the TIBER-EU framework applies in Estonia and specifies the organisation of the tests, the roles of the parties and their cooperation; further material on the TIBER-EU framework is available on the European Central Bank's TIBER-EU pages. The TIBER-EE guide is a recommendatory guide issued by Finantsinspektsioon board decision No 1.1-7/143
FI of 15 September 2026, and it applies as the national framework to firms the Finantsinspektsioon has identified as testing-obliged under DORA with a corresponding supervisory decision
FI. The guide adds that other financial firms may use TIBER-EE on a voluntary basis where this has been coordinated with the Finantsinspektsioon beforehand. Questions on TIBER-EE and threat-led penetration testing go to the Finantsinspektsioon at TLPT@fi.ee.
In practice, DORA-scope firms — banks, payment and e-money institutions, investment firms, crypto-asset service providers, trading venues, insurers and intermediaries, fund managers and crowdfunding providers — should diary the 31 December 2026 as-of date for the register round collected in early 2027, and firms that may be designated for threat-led testing should read the TIBER-EE national application guide now so roles, cooperation lines and contact points are settled before testing is ordered.
The legal basis is Article 28(3) of Regulation (EU) 2022/2554 for the registerFI, Articles 26 and 27 of that Regulation
Europa with Commission Delegated Regulation (EU) 2025/1190 for threat-led testing
FI, applied in Estonia through the Finantsinspektsioon TIBER-EE national application guide.
Diary the 31 December 2026 as-of date for the information-register round collected in early 2027, and read the TIBER-EE national application guide now if the firm may be designated for threat-led penetration testing.
Sources
- DORA määrusest ja nõuetest Eesti finantssektoris tegutsevatele ettevõtetele
- DORA määrusest ja nõuetest Eesti finantssektoris tegutsevatele ettevõtetele
- TIBER-EE riiklik rakendusjuhend
- COMMISSION DELEGATED REGULATION (EU) 2025/1190 of 13 February 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition (Text with EEA relevance)