EIOPA · DORA194 - 3208
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 28
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-12-13
- Answered
- 2025-08-08
Question
Can the usage of code-sharing platforms (e.g. Bitbucket, Github) be considered an ICT-service under DORA?
Background
Going by the DORA-criteria this seems likely. As with our similar question on social media usage, the terms and conditions of these platforms will probably not be adapted to satisfy DORA Article 30, which might block financial entities from using them in case they are meant to be designated ICT service providers. The impact of this seems difficult to estimate. A clarification on European level would be very welcome.
Answer
This question has been rejected because the answer can be found in Q&A DORA030.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-11-20
ICT third-party risk management (DORA)
Answered 2025-11-20
ICT third-party risk management (DORA)
Answered 2025-11-21
ICT third-party risk management (DORA), Other DORA topics
Answered 2025-07-25
ICT third-party risk management (DORA)
Answered 2025-08-08
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.