EBA · 2025_7414 Rejected question
Dora agreements - ICT service supports a CIF
- Regulation
- Regulation (EU) No 2022/2554 (DORA Reg)
- Article
- 3, para. 21
- Topic
- ICT-related incidents (management / classification / reporting)
- Submitted by
- Law firm
- Submitted
- 2025-04-11
Question
When an ICT Service supports a Critical and Important Function (CIF) within a financial entity, providers must sign DORA agreements with their suppliers if the supplier: a) Provides an ICT Service (as per the DORA definition). b) Critically underpins the ICT Service , meaning its disruption could affect security or continuity ( based on ITS on Register of Information, Article 3(2)(b)). Is this interpretation correct? Or must DORA agreements be signed with all critical suppliers, even those that do not provide ICT Services?
Background
N/A
No answer published yet.
Original source: European Banking Authority, Q&A ID 2025_7414
This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
Scope of Article 6 lit. c RTS
Answered 2026-10-02
Classification of phishing-attacks as a reportable major ICT-related incident
Answered 2026-02-06
Types of "telephone services" included under the definition of "ICT services"
Answered 2026-02-06
Staff costs
Answered 2025-11-14
Duplicate ICT Incident Reporting
Answered 2024-12-11
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.