EIOPA · 2998 - DORA031

2998 - DORA031

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
N/A
Submitted
2024-02-14
Answered
2024-11-28

Question

Does the reference in Art. 30 para. 3 (c) DORA on “the provision of services by the financial entity in line with its regulatory framework” relate to the services the financial entity provides to its customers (e.g. the policy holders in case of an insurance undertaking)?

Background

Explanation: It is unclear if the requirement to implement and test business contingency plans and to have in place ICT security measures, tools and policies relates to the services the ICT Third Party Service Provider provides, as the clause refers to services the financial entity provides, without specifying what services are meant. A specification would be helpful.

Answer

This question has been rejected because it seeks confirmation of a requirement already clearly set out in the regulation.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.