Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

3633 - DORA 301

Q&A

Question ID: 3633 - DORA 301

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Topic: Information and Communication Technology (ICT)

Article: 10

Status: Rejected

Date of submission: 14 Aug 2026

Question

Article 10(2)(b) requires financial entities to perform automated vulnerability scanning and assessments at least weekly for ICT assets supporting critical or important functions.

Please clarify whether the weekly scanning and assessment requirement must be performed separately and independently for 2 different layers: 

1) the application/software layer; or 

2) the underlying supporting infrastructure layer, including operating systems, network components, and hosting platforms.

Background of the question

Financial entities may operate critical or important functions through applications hosted on shared or specialised infrastructure. Different technical layers can have different scanning capabilities, ownership models, and vulnerability-management processes. Clarification is requested on whether Article 10(2)(b) establishes a requirement for separate weekly scans at each technical layer, or whether compliance should be assessed based on the completeness and effectiveness of the weekly vulnerability-management process across the relevant ICT assets as a whole (includes both application/software and infrastructure layer).

EIOPA answer

This question can be rejected because the issue it deals with is already addressed in Article 10(2)(b) of Commission Delegated Regulation (EU) 2024/1774.