EIOPA · DORA124 - 3169

ICT risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
Article 3: Definition
Topic
ICT risk management (DORA)
Submitted
2024-10-16
Answered
2025-02-20

Question

In what circumstances are service providers which are financial entities to be considered as ICT third-party service providers and included in the Register of Information?

Background

Recital 7 stipulates that when a financial entity outsources a function that makes use of a supportive ICT service that service provider should be considered a ICT third-party service provider. DORA Dry Run FAQ was published on 4th July which clarified that such regulated entities are not to be considered as ICT third-party service providers. This clarification was later withdrawn DORA Dry Run FAQ was published on 29th July.

Answer

This question has been rejected because the issue it deals with is already explained or addressed in Article 3 (Definitions) (19) of Regulation (EU) 2022/2554, ‘ICT third-party service provider’ means an undertaking providing ICT services. Therefore if a financial entity is providing ICT services, the FE is considered as an ‘ICT third-party service provider’ and needed to be included in the RoI. Please refer to Q&A DORA030 on the definition of ICT service.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.