EIOPA · DORA 195 - 3209
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 28
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-12-13
- Answered
- 2025-11-20
Question
Software is bought as it is from an external provider. The contract specifies no further development, maintenance or support. However, the service provider publishes updates, which can optionally be downloaded by users. Would this constellation represent a DORA ICT-service?
Answer
This question has been rejected because the matter it refers to has been answered in Q&A 030.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-11-21
ICT third-party risk management (DORA)
Answered 2025-08-08
ICT third-party risk management (DORA)
Answered 2025-11-20
ICT third-party risk management (DORA), Other DORA topics
Answered 2025-07-25
ICT third-party risk management (DORA)
Answered 2025-08-08
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.