EIOPA · DORA 164 - 3217
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 2
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-12-23
- Answered
- 2025-11-20
Question
In connection with the withdrawal the "Guidelines on information communication technology security and governance", for those insurance undertakings that fall outside the scope of DORA due to size, but falls within Solvency II in respect of system of governance, what guidelines are they expected to follow after the withdrawal of the EIOPA-BoS-20/600?
Background
An insurance undertaking is exempted from DORA due to it's size in line with DORA Article 2 (3. (b)). However, due to the local regulatory requirements, the entity is required to comply with Solvency II corporate governance, including the guidelines on informtion communication technology security and governance. When the guidelines EIOPA-BoS-20/600 are withdrawn, what are the requirements for those entities that do not fall within the scope of DORA.
Answer
The question has been rejected because the issue it deals with is already addressed in the regulatory text (Article 2 of DORA).
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.