EIOPA · DORA188 - 3200

ICT third-party risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
28
Topic
ICT third-party risk management (DORA)
Submitted
2024-12-06
Answered
2025-08-08

Question

What are the standards Article 28(5) is referring to? Article 28(5) Financial entities may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards. When those contractual arrangements concern critical or important functions, financial entities shall, prior to concluding the arrangements, take due consideration of the use, by ICT third- party service providers, of the most up-to-date and highest quality information security standards.

Answer

Appropriate information security standards refer to the industry best practices and standards. Due to the evolving nature (up to date) of the standards, the L1 text cannot refer to a specific set of standards.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.