Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

2993 - DORA036

Q&A

Question ID: 2993 - DORA036

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Status: Rejected

Date of submission: 14 Feb 2024

Question

Art.8 III DORA: Financial entities, other than microenterprises, shall perform a risk assessment upon each major change in the network and information system infrastructure, in the processes or procedures affecting their ICT supported business functions, information assets or ICT assets. What does DORA understand by "major changes"? What are the criteria for major changes?

EIOPA answer

This question has been rejected because it is an institution-specific question requiring bespoke advice.