On 26 June 2026 the EBA published the Final Report on its revised Guidelines on common procedures and methodologies for SREP and supervisory stress testing (EBA/GL/2026/06). They apply from 1 January 2027 and repeal both the existing SREP Guidelines (EBA/GL/2022/03) and the standalone Guidelines on ICT risk assessment under SREP. Every P2R and P2G decision in the 2027 cycle will be formed under this text — including, for the first time inside the SREP framework itself, an operationalisation of what happens to P2R when the output floor binds. If your ICAAP still argues capital for risks the floor now covers under Pillar 1, expect the JST to raise it before you do.
This is not a maintenance update to EBA/GL/2022/03. The revision consolidates every SREP provision into a single framework, absorbs the standalone ICT-risk assessment, and settles a question competent authorities have been answering case by case since CRR3 went live: how P2R interacts with a revised Pillar 1 — output floor included.
EBA/GL/2022/03 and the ICT-risk Guidelines (EBA/GL/2017/05) are repealed and consolidated, with the new CRD mandates folded in. One risk taxonomy, one scoring architecture, one document your SREP response team works from in 2027.
The ICT risk assessment is integrated into Title 6 under operational risk, incorporating DORA. There is no standalone ICT module any more — ICT resilience is scored where operational risk is scored, by the same assessment.
The guidelines restate that P2R addresses only risks not covered, or not sufficiently covered, by Pillar 1 — and set out how that principle is operationalised when an institution becomes bound by the output floor, following EBA/Op/2025/01.
| Change | What the Final Report does | Who feels it first |
|---|---|---|
| Consolidation | Single SREP framework; new CRD mandates incorporated; clarified risk taxonomy with non-exhaustive sub-categories for credit, market, operational risk and IRRBB | Every SSM bank — the 2027 SREP letter cites this text |
| ICT / DORA | ICT-risk Guidelines repealed; ICT assessment integrated in Title 6 under operational risk, incorporating DORA, alongside a broader operational-resilience concept | Banks whose ICT risk documentation was written for the old standalone assessment |
| P2R × output floor | Complementary nature of P1R and P2R preserved; interaction with P2R operationalised when the floor binds, reflecting EBA/Op/2025/01 | IRB-heavy banks at or near the floor |
| P2G / P2G-LR | Stress-test-driven guidance set separately for excessive leverage and other risks — CET1 quality for P2G, Tier 1 for P2G-LR | Banks with thin stress-test depletion buffers into the 2027 EBA exercise |
| ESG & CSRBB | ESG factors integrated into the existing SREP assessments rather than annexed; credit spread risk from non-trading activities (CSRBB) made explicit alongside IRRBB | Banks treating ESG and CSRBB as ICAAP appendix material |
| Third-country branches | New Title 12 delivers the Article 48n(6)(a) CRD VI mandate — a SREP for third-country branches, applying from 11 January 2027 | Non-EU groups branching into the Union under CRD VI |
| Proportionality | Four-category model retained; assessments calibrated in scope, depth and intensity; multi-year SREP approach with in-depth reviews planned across cycles | Category 3–4 institutions — and their supervisors’ planning calendars |
There is no transition year. The guidelines apply from 1 January 2027, so the 2027 SREP — the cycle that runs alongside the 2027 EU-wide stress test — is assessed on the new framework from day one. The ICAAP you submit in early 2027 is the first artefact read under it.
Source: EBA Final Report on revised SREP and supervisory stress testing Guidelines (EBA/GL/2026/06), 26 June 2026 — publication and application dates as stated by the EBA.
Since CRR3 went live, floor-bound banks have faced an uncomfortable arithmetic: the output floor raises Pillar 1 requirements against model risk and RWA understatement — the same territory parts of many P2R add-ons were built on. The revised guidelines carry the EBA’s January 2025 Opinion (EBA/Op/2025/01) into the SREP framework itself: where a relevant change in the Pillar 1 framework has a material impact on the capital profile, the competent authority assesses the interplay with the relevant P2R so that, in the EBA’s words, “P2R addresses only those risks, or elements of risk, that are not covered or not sufficiently covered by P1R.” When an institution becomes bound by the floor, the guidelines set out how that interaction is operationalised.
From the 2027 cycle, “what does the floor do to our P2R?” has an official answer — and your ICAAP is the evidence base the answer gets built from. Banks that can decompose their P2R into floor-covered and non-floor-covered elements will negotiate; banks that cannot will receive.
The mechanism is an assessment, not a formula. The complementary-nature principle obliges the competent authority to re-examine overlap when the floor binds — it does not oblige it to conclude in your favour. The quality of the decomposition you table decides which way the assessment runs.
Where supervisory stress testing suggests own-funds requirements may not be met under stress, guidance is set separately for other risks and for excessive leverage — P2G covered in CET1, P2G-LR in Tier 1. The 2027 EU-wide exercise and the 2027 SREP now run on the same consolidated rulebook.
The clarified risk taxonomy — non-exhaustive sub-categories across credit, market, operational risk and IRRBB, with CSRBB explicit — is what “covered by P1R” gets tested against. An ICAAP mapped to the old taxonomy makes the overlap argument harder than it needs to be.
P2R set in the 2026 cycle was formed under the old guidelines; the first re-formation under the new text lands with 2027 SREP decisions. A floor-bound bank that wants the interaction assessed properly should have the analysis in its ICAAP before the cycle opens — not raise it in the draft-decision hearing.
The banks for which the P2R interaction is worth real basis points are the ones whose floored RWA already exceeds, or will exceed through the phase-in, their modelled RWA. For them the 2027 SREP is a capital event, not a compliance one — the P2R re-assessment either recognises the floor’s coverage or silently double-counts it.
ICT risk is no longer a standalone assessment feeding in from the side — it is scored inside the operational-risk element of core SREP, on DORA-era expectations. A weak ICT file now moves an operational-risk score that flows directly into P2R formation. DORA compliance artefacts and the SREP narrative need to be the same story.
Title 12 gives third-country branches their first harmonised SREP under CRD VI from 11 January 2027 — non-EU groups get a supervisory review where many had none. And with CSRBB explicit in the taxonomy alongside IRRBB, banks that measured credit-spread risk in the banking book loosely will find the gap scored, not noted.
Walk your internal risk inventory against the new sub-categories — credit, market, operational risk, IRRBB, CSRBB. Every ICAAP risk that does not land cleanly in the new taxonomy is a risk the JST will classify for you.
If you are floor-bound or will be during the phase-in: decompose the current P2R into elements the floored Pillar 1 now covers, partially covers, or does not touch. That analysis — quantified, in the ICAAP — is the input the competent authority’s interaction assessment works from.
The standalone ICT assessment is gone. Fold DORA testing results, register-of-information quality and ICT incident data into the operational-risk and operational-resilience narrative the SREP will actually score.
CSRBB now sits explicitly in the assessed taxonomy alongside IRRBB. If your banking-book credit-spread measurement is an annual memo rather than a governed metric with limits, fix that in 2026 — it is cheaper than defending it in 2027.
Dates, reference numbers and quoted language verified against the EBA Final Report at publication (27 July 2026). Corrections: research@ezelman.com.
Partner-led, senior-only, no audit conflict. If the question in this piece is live at your institution, the first conversation is with a partner — not a BD team.
Talk to a partner →