EIOPA · DORA 181 - 3243
DORA 181 - 3243
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 18
- Submitted
- 2025-02-10
- Answered
- 2025-11-20
Question
Article 18 refers to "Member States" in regard to geographical spread. However, this implies that the article does not include EEA members, i.e., incidents that spread to EEA and non-EU members (Iceland, Liechtenstein, Norway) are not to be considered in the classification of major ICT-related incidents and cyber threats. Can you confirm that it is correctly understood that there is no legal obligation to include Iceland, Liechtenstein, and Norway when it comes to geographical spread? And what is the reasoning behind the decision to exclude these geographies in the legal text?
Answer
The answer to the question can be found in the regulatory texts (Level 2 papers).
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
1494
Answered 2019-09-12
Treatment of intragroup liabilities when one of the institutions is established in a country being a member of EEA and EFTA (i.e. non-EU Member State but EEA Member State)
Answered 2024-03-22
30
Answered 2019-10-25
Critical Services Affected
Answered 2024-12-11
Scope (Art. 1 IDD)
Answered 2023-05-25
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.