Annual PSD2 Article 95(2) Filing
Independent PSD2 Operational & Security Risk Assessment for
DORA-covered EU/EEA PSPs
An independent, DORA-aligned assessment for your mandatory PSD2 Article 95(2) filing, built to hold up if a supervisor or board member checks it later.
CyAdvisoled by Andrey Gubarev, Founder & vCISOCISM, CDPSE, SABSA
Is your Article 95(2) filing still aligned with DORA, not just PSD2?
Since 17 January 2025, the Digital Operational Resilience Act (DORA) has been the operative ICT-risk framework for DORA-covered payment institutions, e-money institutions and bank-PSPs. The European Banking Authority narrowed its own pre-2025 PSD2 guidance for exactly this reason: a DORA-covered institution is no longer assessed against the older, PSD2-only ICT checklist alone. Article 95(2) of PSD2 still requires you to file an updated and comprehensive assessment of your operational and security risks at least once a year; that continuing statutory duty has not gone away. For a DORA-covered institution, though, the assessment behind that filing has to be built on DORA as the primary operative framework, with PSD2 Article 95/96 named as the continuing duty the filing discharges, never treated as a stand-alone “PSD2 assessment.”
Why a self-graded filing can go stale unnoticed. A self-graded filing that has run on the same template for several years risks staying anchored to that superseded logic without anyone noticing, until a board member, your Head of Internal Audit, or a later supervisory review asks whether this year’s filing actually reflects DORA. An independent assessment closes that gap before anyone else asks the question, not after.
How we assess both layers, by one reviewer. We assess your institution against both layers explicitly, in every finding: DORA as the primary operative framework where it applies, and PSD2 Article 95/96 named as the continuing statutory duty your filing discharges. One reviewer holds DORA, PSD2 and ICT-risk-management expertise across all six domains your filing needs to cover, governance through incident reporting, so nothing is handed between a legal reviewer and a separate technical assessor.
Why a bundled generalist engagement typically falls short. That combination is what a bundled engagement with your existing financial or ISO 27001 auditor typically does not carry: a team pulled from an already-purchased assurance engagement usually produces that engagement’s own standard output, a certification surveillance report or a financial-controls memo, not a two-layer, DORA-primary/PSD2-continuing-duty assessment matrix built for this specific filing.
Six domains, one reviewer, two-layer legal basis throughout
Every finding below states its basis explicitly: DORA as the primary framework where your institution is DORA-covered, PSD2 Article 95/96 named as the continuing duty your filing discharges.
-
Governance: ICT/security-risk governance is documented and current, roles, policies, board oversight of ICT risk. DORA governance provisions, primary; PSD2 Art. 95(1) framework-establishment duty, continuing.
-
ICT-risk assessment: your institution’s risk-assessment methodology and results are current and defensible. DORA ICT risk-management framework, primary; PSD2 Art. 95(2) annual-assessment duty, continuing.
-
Protective and detective measures: implemented and evidenced. DORA protection-and-prevention provisions, primary; PSD2 Art. 95(1) mitigation-measures duty, continuing.
-
Business continuity: plans exist, are tested, and cover your ICT-dependent payment services. DORA business-continuity provisions, primary; PSD2 Art. 95(1) operational-risk-mitigation duty, continuing.
-
Testing: vulnerability, penetration and scenario testing performed at the required cadence. DORA digital operational resilience testing provisions, primary; PSD2 Art. 95(1) control-mechanism duty, continuing.
-
Incident reporting: your Article 96 major-incident reporting process and log, consistent with what you file. DORA ICT-incident-management and reporting provisions, primary; PSD2 Art. 96(1) major-incident notification duty (“without undue delay”), continuing.
What you receive
-
Agreed written scope: entities, branches and outsourced ICT services in scope, the two-layer legal basis stated explicitly, and a timeline against your filing deadline.
-
DORA/PSD2 Assessment Matrix: domain, regulatory reference (DORA primary / PSD2 Art. 95/96 continuing duty), evidence, assessment, finding, one row per domain. Every domain gets an explicit status, Compliant, Partially Compliant, Non-Compliant, or Not Applicable, none left ambiguous.
-
Independent assessment findings, produced by one reviewer holding combined DORA, PSD2 and ICT-risk-management expertise across all six domains, not handed off between a legal reviewer and a separate technical assessor.
-
A formal, regulator-legible assessment report, submittable as, or directly feeding, your annual Article 95(2) filing, and reusable without further preparation in your own board and governance reporting.
-
Conditional remediation and re-confirmation: only if a domain finding is Partially Compliant or Non-Compliant on a material item, not part of the critical path if your institution assesses cleanly.
-
A structured, reusable baseline: evidence map, prior findings, remediation status per domain, that next year’s cycle starts from rather than rebuilding from zero.
Who we work with
DORA-covered EU/EEA-licensed payment institutions, e-money institutions and bank-PSPs facing their annual, or NCA-directed shorter-interval, PSD2 Article 95(2) filing. Five moments most often bring an institution to this assessment:
- Your compliance team has self-graded this filing on the same template for years, and nobody has recently checked it against DORA’s post-2025 framework.
- Your existing financial or ISO 27001 auditor has been asked to bundle this filing into their engagement, and what comes back reads like a generic attestation, not a DORA/PSD2 assessment matrix.
- You have been filing a thin, minimal version and betting your regulator will not ask, and you would rather close that exposure on your own terms, now, not after a review starts.
- You would rather not wait for a major incident to be the reason this finally gets a proper, independent look.
- You already work with an independent assessor and are weighing whether this year’s renewal builds on last year’s work, or starts again from zero.
If your compliance team has already run its own review, that work becomes the starting evidence package for this engagement, not a discarded first draft.
If your immediate trigger is a formal or informal signal that your regulator is about to review you, or you have recently changed your ICT architecture or vendors and need to confirm it still holds, those are different, narrower engagements. Contact us and we will tell you honestly whether this assessment or something narrower fits your situation.
Our approach
Six steps, agreed against your filing deadline from the first conversation, with a seventh that only activates if it is needed.
-
1
Scope
We agree in writing which entities, outsourced ICT services and the two-layer legal basis are in scope, against a timeline that lands before your filing deadline. This first conversation gives you visibility and control before you commit any evidence-assembly effort, not a sales pitch.
Talk to us about your scope → -
2
Evidence
Your team compiles governance documentation, ICT-risk-assessment records, control evidence, business-continuity plans and test results, and incident logs across all six domains, coordinated through a single evidence-request checklist and one point of contact. Nothing is requested twice.
-
3
Independent assessment
One reviewer evaluates the evidence against the two-layer legal basis, DORA primary, PSD2 Art. 95/96 continuing, across all six domains.
-
4
Findings
Every domain receives an explicit Assessment Matrix status. Nothing is left ambiguous or assumed compliant by default.
-
Remediation and re-confirmation (where needed)
If a domain finding is material, it is closed and re-confirmed before your filing deadline, or a credible, evidenced remediation plan is on file if closure is not realistically achievable in time.
-
5
Report
A formal, regulator-legible Annual Assessment Report you can submit and hand directly to your own board, without further preparation.
-
6
Baseline
You keep a structured evidence and assessment baseline, evidence map, prior findings, remediation status per domain, for next year’s cycle to start from.
Why us
-
Combined expertise: DORA, PSD2 and ICT-risk-management expertise held by one reviewer across all six domains, not handed between a legal reviewer and a separate technical assessor.
-
Two-layer legal basis by construction: the Assessment Matrix bakes DORA-primary, PSD2-continuing-duty framing into every finding, not a separate disclaimer added afterward.
-
Independence: the team assessing your filing is operationally independent of the team that drafted it, for every engagement, by design.
-
Built for recurrence: a structured baseline that compounds year over year, not a fresh start every filing cycle.
Our practice is calibrated by our founder, Andrey Gubarev (CISM, SABSA, CDPSE), a two-time former CISO at EU-licensed fintechs.
Compared to your other options:
- An internal self-graded filing cannot independently confirm it reflects DORA’s post-2025 framework rather than the PSD2-only logic it may have run on for years.
- A generalist auditor bundling this filing into a broader assurance engagement rarely fields reviewers holding DORA, PSD2 and ICT-risk-management expertise together across all six domains, and typically produces that engagement’s own standard output instead of a two-layer assessment matrix.
- Another independent assessor who treats each year as a fresh, unconnected project leaves your year-two evidence-assembly effort at year-one levels, instead of starting from a maintained baseline.
This assessment does not end at a filed report
Unlike a one-off audit, this filing recurs every year, so the assessment is built to compound, not repeat from zero. You keep a structured baseline, evidence map, prior findings, remediation status per domain, so next year’s scoping and evidence-assembly steps start from where this cycle left off, not from a blank page. If your provider changes between cycles, that is expected practice, not a relationship break: we ask any prior assessor’s evidence package as part of onboarding, rather than starting from nothing.
The regulatory framework this assessment works against
PSD2 (Directive (EU) 2015/2366) Article 95 requires payment service providers to maintain an appropriate operational and security-risk-management framework and to provide their competent authority with an updated and comprehensive assessment of operational and security risks at least once a year; Article 96 requires major-incident notification without undue delay. Since 17 January 2025, the Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been the operative ICT-risk framework for DORA-covered financial entities, including most PSD2 payment institutions, e-money institutions and bank-PSPs. The European Banking Authority narrowed its own PSD2-era ICT and security-risk guidelines specifically because DORA now covers this population, to avoid duplicating requirements and to give the market legal clarity. For a DORA-covered institution, we assess against DORA as the primary operative framework and name PSD2 Article 95/96 as the continuing statutory duty your annual filing discharges, never one framework in place of the other.
For the wider regime comparison, see our DORA vs PSD2/PSD3 guide. For how the EBA’s own pre-2025 guidelines were narrowed because of DORA, see our EBA Guidelines on ICT and Security Risk Management After DORA.
Last reviewed 17 September 2026. Every claim above maps to primary regulatory text, confirm the current application status with counsel.
Show the sources
-
Directive (EU) 2015/2366: PSD2, EUR-Lex, Articles 95 and 96. Requires an annual operational and security-risk self-assessment and major-incident notification without undue delay.
-
Regulation (EU) 2022/2554: Digital Operational Resilience Act, EUR-Lex. The operative ICT-risk framework for DORA-covered financial entities since 17 January 2025, primary framework this assessment is built on.
-
EBA: Final report on amending Guidelines EBA/GL/2019/04, EBA/GL/2025/02. Narrows the EBA’s own pre-2025 PSD2 ICT and security-risk guidelines because DORA now covers this population, referenced above.
Subject matter, not a credential claim. CyAdviso is independent of, and not endorsed by, these bodies. Confirm the application to your entity with counsel and the relevant NCA.
Request an Assessment
Tell us your filing deadline and where you are in this year’s cycle. The first conversation is a scope discussion, not a commitment, and it costs you nothing to find out whether your timeline still works. No price is published here because every engagement is scoped to your institution; you will have a written scope before you commit to anything.
Or email info@cyadviso.com · No commitment. No sales pressure.