Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

3622 - DORA 300

Q&A

Question ID: 3622 - DORA 300

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Topic: Other DORA topics

Article: 3(21)

Status: Rejected

Date of submission: 17 Jul 2026

Question

Question 1: 

May contractual performance consisting of granting of a licence for on-premise software, that is operated exclusively within the financial entity's infrastructure and without the ongoing provision of operational or other support activities by the supplier, be considered an ICT service within the meaning of Article 3 Point 21 of the DORA?

Question 2:

What is the significance for this assessment of the fact that, in addition to the software license, the supplier makes new versions, updates, or security patches available without simultaneously providing management, monitoring, or other active operational support? 

Question 3:

Under what circumstances do the requirements of Articles 28 and 30 of DORA apply to such contractual relationship, particularly in terms of requirements regarding key contractual provisions with third-party ICT service providers? 

Question 4:

For the purposes of Articles 28 and 30 of DORA, should a situation where the software in question supports a critical or important function of a financial entity be assessed differently? 

Question 5:

If provision of license as described in the above-mentioned model do not constitute an ICT service within the definition of DORA, what minimum regulatory requirements would a national competent authority consider that a financial entity should take into account when managing the associated risks?

Background of the question

Although we have provided five questions they all relate to each other and boil down to interpretaion of definition of Article 3 point 21 specifically a line between ICT service and service that is not an ICT service. We have received these questions from multiple market participants using our FAQ tool.

EIOPA answer

This question has been rejected because it is seeking confirmation of a requirement already set out in the regulation and already addressed in Q&A DORA030.