EIOPA · DORA194 - 3208

ICT third-party risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
28
Topic
ICT third-party risk management (DORA)
Submitted
2024-12-13
Answered
2025-08-08

Question

Can the usage of code-sharing platforms (e.g. Bitbucket, Github) be considered an ICT-service under DORA?

Background

Going by the DORA-criteria this seems likely. As with our similar question on social media usage, the terms and conditions of these platforms will probably not be adapted to satisfy DORA Article 30, which might block financial entities from using them in case they are meant to be designated ICT service providers. The impact of this seems difficult to estimate. A clarification on European level would be very welcome.

Answer

This question has been rejected because the answer can be found in Q&A DORA030.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.