Question ID: 3633 - DORA 301
Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Topic: Information and Communication Technology (ICT)
Article: 10
Status: Rejected
Date of submission: 14 Aug 2026
Question
Article 10(2)(b) requires financial entities to perform automated vulnerability scanning and assessments at least weekly for ICT assets supporting critical or important functions.
Please clarify whether the weekly scanning and assessment requirement must be performed separately and independently for 2 different layers:
1) the application/software layer; or
2) the underlying supporting infrastructure layer, including operating systems, network components, and hosting platforms.
Background of the question
Financial entities may operate critical or important functions through applications hosted on shared or specialised infrastructure. Different technical layers can have different scanning capabilities, ownership models, and vulnerability-management processes. Clarification is requested on whether Article 10(2)(b) establishes a requirement for separate weekly scans at each technical layer, or whether compliance should be assessed based on the completeness and effectiveness of the weekly vulnerability-management process across the relevant ICT assets as a whole (includes both application/software and infrastructure layer).
EIOPA answer
This question can be rejected because the issue it deals with is already addressed in Article 10(2)(b) of Commission Delegated Regulation (EU) 2024/1774.