EIOPA · DORA124 - 3169
ICT risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- Article 3: Definition
- Topic
- ICT risk management (DORA)
- Submitted
- 2024-10-16
- Answered
- 2025-02-20
Question
In what circumstances are service providers which are financial entities to be considered as ICT third-party service providers and included in the Register of Information?
Background
Recital 7 stipulates that when a financial entity outsources a function that makes use of a supportive ICT service that service provider should be considered a ICT third-party service provider. DORA Dry Run FAQ was published on 4th July which clarified that such regulated entities are not to be considered as ICT third-party service providers. This clarification was later withdrawn DORA Dry Run FAQ was published on 29th July.
Answer
This question has been rejected because the issue it deals with is already explained or addressed in Article 3 (Definitions) (19) of Regulation (EU) 2022/2554, ‘ICT third-party service provider’ means an undertaking providing ICT services. Therefore if a financial entity is providing ICT services, the FE is considered as an ‘ICT third-party service provider’ and needed to be included in the RoI. Please refer to Q&A DORA030 on the definition of ICT service.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.