EIOPA · DORA033 - 2996

ICT risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
8
Topic
ICT risk management (DORA)
Submitted
2024-02-14
Answered
2025-07-24

Question

Art. 8 VII: Financial entities, other than microenterprises, shall on a regular basis, and at least yearly, conduct a specific ICT risk assessment on all legacy ICT systems and, in any case before and after connecting technologies, applications or systems. What does DORA mean by connecting?

Background

Explanation: Article 8 VII refers explicit to legacy systems. However, it is unclear whether "before and after connection of technologies, applications or systems" refers to all changes.

Answer

Under Art. 8(7) of DORA, FEs must perform ICT risk assessments on legacy systems at least annually and in any case before and after connecting technologies, applications, or systems. In this regard, “connection” relates to e.g. integrations, interfacing of systems/tools, or changes to legacy systems that can add new interdependencies and/or vulnerabilities.Moreover, the RTS on RMF detail this interpretation by describing the procedures for ICT risk management, such as the need of change management policy and procedures (Art. 17) and the identification of interdependencies between systems and providers (Art. 8). These provisions highlight the importance of assessing connections as part of a broader strategy to manage ICT risks.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.