Norway's Finanstilsynet stated on August 31, 2026 that from September 1, 2026 the national ICT Regulation (IKT-forskriften, FOR-2003-05-21-630) is repealed and replaced by rules in the Digital Operational Resilience Act. The Ministry of Finance laid down FOR-2026-08-20-1657 on August 20, 2026, promulgated in Norsk Lovtidend on August 24, 2026, amending the DORA-forskriften (FOR-2025-06-24-1296). From that date, finance companies (finansieringsforetak), real-estate brokerage firms (eiendomsmeglingsforetak), debt-collection firms (inkassoforetak) and Norsk naturskadepool must apply Regulation (EU) 2022/2554 as adapted in DORA-forskriften chapter 2.
DORA-loven (LOV-2025-05-27-18) has been in force since July 1, 2025 for the EEA-incorporated DORA perimeter. This amendment is the operational extension: those four entity types leave the IKT-forskriften and enter a tailored DORA chapter. Finanstilsynet's supervisor notice also changes how serious ICT incidents must be filed.
Who must apply DORA from September 1, 2026, and under which rules?
Chapter 2 applies DORA, so far as sections 4 to 11 provide, to finance companies, real-estate brokerage firms, debt-collection firms and Norsk naturskadepool. It is not a full copy of the EU perimeter: section 6 splits the ICT risk-management framework, and several third-party and incident duties are narrowed for brokers and collectors. New chapter 3 recasts TLPT: Finanstilsynet designates which firms must run it and how often; Norges Bank is the TLPT cyber team.
| Duty | Finance companies | Brokers, collectors, Naturskadepool |
|---|---|---|
| ICT risk management | Articles 5 to 15 (full framework) | Article 16 simplified framework |
| Incident handling, classification, reporting (Arts. 17 to 19) | Applies so far as they fit | Applies; for brokers, only incidents tied to the settlement function |
| Resilience testing (Arts. 24 and 25) | Applies so far as they fit | Applies so far as they fit |
| ICT-agreement register (Art. 28(3)) | Entity-level register only; Commission Implementing Regulation (EU) 2024/2956 does not apply | Same national six-field register |
| Notification of critical or important ICT agreements | Applies so far as it fits | Brokers: settlement function only. Collectors: medium-sized (Art. 3(64)) or larger only |
| Follow EU oversight recommendations (Art. 42) and cyber-threat information sharing (Art. 45) | Applies so far as they fit | Applies so far as they fit |
What ICT-risk, incident and third-party duties actually apply?
Finance companies take Articles 5 to 15; brokers, collectors and Norsk naturskadepool take only the simplified framework in Article 16. Incident handling, classification and reporting (Articles 17 to 19) apply across the chapter 2 perimeter, but real-estate brokers must meet the classification and reporting rules only for incidents related to the settlement function (oppgjørsfunksjonen).
The ICT third-party block (Articles 28 to 30) applies with three Norwegian adaptations. The register of ICT service agreements is entity-level only, and Commission Implementing Regulation (EU) 2024/2956 does not apply. The register must at least record provider name, organisation number, LEI and EUID; agreement type; provider head-office country; subcontractor name, organisation number and head-office country; start and end dates, or that the contract is rolling; and the date of the last risk assessment. Notification of critical or important ICT agreements is limited for brokers to settlement services, and for collectors to medium-sized or larger firms. Firms must also follow recommendations from the EU oversight authority for critical ICT third-party providers. Administrative fines track DORA-loven section 4, first paragraph only. Finanstilsynet's guidance on notifying ICT service agreements is the operational manual for those filings.
How must firms report serious ICT incidents from September 1?
Firms cannot use Altinn form KRT-3190 for incident reporting for the time being. Serious ICT incidents and cyber threats must be sent to [email protected]. Finanstilsynet expects newly in-scope firms to report serious incidents and will take the novelty of the regime into account in supervisory follow-up.
If the firm treats the content as sensitive, it may file Altinn form KRT-1060 marked "Hendelsesrapportering IKT" in field 2.2, or send ordinary email with the report attached as an encrypted, password-protected Word document (the password is exchanged with Finanstilsynet in a separate dialogue). Personal data must be shielded under the Personal Data Act (personopplysningsloven). The filing must state when the incident arose, when it was detected, contact details, which systems or data are affected, preliminary consequences, cause so far as known, time of restored operations or an estimate, recovery measures, and measures to prevent recurrence. An internal incident form may be used if it covers those fields. The channel and content rules sit in Finanstilsynet's DORA incident-reporting guidance.
What should newly in-scope firms do this week?
Confirm the legal category first: finansieringsforetak, eiendomsmeglingsforetak, inkassoforetak, Norsk naturskadepool, or already inside DORA-loven section 1. Map the full versus simplified ICT risk-management split and the settlement-function and size filters. Stand up the six-field entity-level register and file outstanding critical or important ICT agreements where notification is required. Switch incident reporting off KRT-3190, test [email protected] (and the KRT-1060 or encrypted-Word fallback), and brief operations, ICT risk and the board that serious-incident reporting is live from September 1, 2026.
Continuous per-jurisdiction monitoring surfaces this kind of Finanstilsynet notice the moment it publishes, so a live-duty switch does not wait on a weekly legal round-up.
Subscribe to the free newsletter
Next steps: verify applicability under DORA-forskriften chapter 2; check that the ICT-agreement register and notification files match section 9; put the new incident channel and the nine required content fields into the operational playbook before the next serious event; brief the relevant ICT-risk, operations and settlement teams. Obsidian follows Finanstilsynet and Lovdata so the next DORA channel or register change is visible the day it lands.


