EIOPA · DORA 249 - 3377

ICT third-party risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
N/A
Topic
ICT third-party risk management (DORA)
Submitted
2025-07-04
Answered
2025-11-21

Question

The company has several business lines. Only one is subject to DORA. If the external supplier provides services for only one business line not subject to DORA, should they be treated as ICT suppliers?

Answer

This question has been rejected because the matter falls within the scope of Q&A 136.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.