Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

DORA124 - 3169

Q&A

Question ID: DORA124 - 3169

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Topic: ICT risk management (DORA)

Article: Article 3: Definition

Status: Rejected

Date of submission: 16 Oct 2024

Question

In what circumstances are service providers which are financial entities to be considered as ICT third-party service providers and included in the Register of Information?

Background of the question

Recital 7 stipulates that when a financial entity outsources a function that makes use of a supportive ICT service that service provider should be considered a ICT third-party service provider. DORA Dry Run FAQ was published on 4th July which clarified that such regulated entities are not to be considered as ICT third-party service providers. This clarification was later withdrawn DORA Dry Run FAQ was published on 29th July.

EIOPA answer

This question has been rejected because the issue it deals with is already explained or addressed in Article 3 (Definitions) (19) of Regulation (EU) 2022/2554, ‘ICT third-party service provider’ means an undertaking providing ICT services. Therefore if a financial entity is providing ICT services, the FE is considered as an ‘ICT third-party service provider’ and needed to be included in the RoI. Please refer to Q&A DORA030 on the definition of ICT service.