EIOPA · DORA188 - 3200
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 28
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-12-06
- Answered
- 2025-08-08
Question
What are the standards Article 28(5) is referring to? Article 28(5) Financial entities may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards. When those contractual arrangements concern critical or important functions, financial entities shall, prior to concluding the arrangements, take due consideration of the use, by ICT third- party service providers, of the most up-to-date and highest quality information security standards.
Answer
Appropriate information security standards refer to the industry best practices and standards. Due to the evolving nature (up to date) of the standards, the L1 text cannot refer to a specific set of standards.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.