EIOPA · DORA153 - 3214

ICT third-party risk management (DORA), Other DORA topics

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
28-31
Topic
ICT third-party risk management (DORA), Other DORA topics
Submitted
2024-12-18
Answered
2025-07-25

Question

We have a supplier who handles a critical process for us. Although the service itself is not directly ICT-related, the supplier uses ICT systems to deliver these services to us. The supplier believes that they should not be classified as a third party under DORA and therefore do not need an additional agreement. When I make an overall assessment of this, I believe they fall within the scope of DORA, as we should consider their systems as our own due to it being an outsourcing function. I am having difficulty finding the exact wording in DORA to support our assessment. Could you clarify which specific articles and regulations within DORA apply to the classification of third parties handling critical or important functions, even if the service is not directly ICT-related? Is it correct that our supplier, who uses ICT systems to deliver critical services, should be subject to DORA's requirements for third parties?

Answer

This question has been rejected because the answer to the question can be found in the regulatory texts and the question has already been answered in Q&A DORA030 - 2999 - EIOPA

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.