EIOPA · DORA 181 - 3243

DORA 181 - 3243

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
18
Submitted
2025-02-10
Answered
2025-11-20

Question

Article 18 refers to "Member States" in regard to geographical spread. However, this implies that the article does not include EEA members, i.e., incidents that spread to EEA and non-EU members (Iceland, Liechtenstein, Norway) are not to be considered in the classification of major ICT-related incidents and cyber threats. Can you confirm that it is correctly understood that there is no legal obligation to include Iceland, Liechtenstein, and Norway when it comes to geographical spread? And what is the reasoning behind the decision to exclude these geographies in the legal text?

Answer

The answer to the question can be found in the regulatory texts (Level 2 papers).

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.