Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

DORA 181 - 3243

Q&A

Question ID: DORA 181 - 3243

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Article: 18(1)(c)

Status: Rejected

Date of submission: 10 Feb 2025

Question

Article 18 refers to "Member States" in regard to geographical spread. However, this implies that the article does not include EEA members, i.e., incidents that spread to EEA and non-EU members (Iceland, Liechtenstein, Norway) are not to be considered in the classification of major ICT-related incidents and cyber threats. Can you confirm that it is correctly understood that there is no legal obligation to include Iceland, Liechtenstein, and Norway when it comes to geographical spread? And what is the reasoning behind the decision to exclude these geographies in the legal text?

EIOPA answer

The answer to the question can be found in the regulatory texts (Level 2 papers).