EIOPA · 2998 - DORA031
2998 - DORA031
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- N/A
- Submitted
- 2024-02-14
- Answered
- 2024-11-28
Question
Does the reference in Art. 30 para. 3 (c) DORA on “the provision of services by the financial entity in line with its regulatory framework” relate to the services the financial entity provides to its customers (e.g. the policy holders in case of an insurance undertaking)?
Background
Explanation: It is unclear if the requirement to implement and test business contingency plans and to have in place ICT security measures, tools and policies relates to the services the ICT Third Party Service Provider provides, as the clause refers to services the financial entity provides, without specifying what services are meant. A specification would be helpful.
Answer
This question has been rejected because it seeks confirmation of a requirement already clearly set out in the regulation.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.