EIOPA · DORA135 - 3191
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 28
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-11-20
- Answered
- 2025-07-25
Question
Is there a presumed timeline of the reissue of ITS regarding the standard template for the register of information referred to in article 28(3) DORA by the ESAs? Furthermore, is there a presumed timeline of adoption of the RTS on subcontracting ICT services supporting a critical or important function (legal basis being article 30(5) DORA)?
Background
As representatives of the financial entities to whom DORA applies, wishing to exercise the utmost diligence in assisting them in fulfilling the obligations imposed by EU law, we would appreciate a response on when we should expect progress on the DORA implementing acts.
Answer
The question has been rejected because it is out of scope of the regulatory Q&A process on DORA.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-08-08
ICT third-party risk management (DORA)
Answered 2024-11-28
ICT third-party risk management (DORA)
Answered 2025-11-20
ICT third-party risk management (DORA), Other DORA topics
Answered 2025-07-25
ICT third-party risk management (DORA)
Answered 2024-11-28
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.