EIOPA · 2993 - DORA036

2993 - DORA036

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Submitted
2024-02-14
Answered
2024-11-28

Question

Art.8 III DORA: Financial entities, other than microenterprises, shall perform a risk assessment upon each major change in the network and information system infrastructure, in the processes or procedures affecting their ICT supported business functions, information assets or ICT assets. What does DORA understand by "major changes"? What are the criteria for major changes?

Answer

This question has been rejected because it is an institution-specific question requiring bespoke advice.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.