DORA – Legal Bases

Legal Bases
Regulation (EU) 2022/2554 covers the fundamental standards on digital operational resilience for the EU financial sector.
Directive (EU) 2022/2556 amends existing sectoral directives to ensure their consistency with DORA requirements.
The DORA Enforcement Act (DORA-VG) which was passed by the National Council on 03 July 2024 implements the DORA Regulation and amends other Regulations in Austria.
ICT risk management
|
Digital operational resilience testing
|
Managing of ICT third-party risk
|
Oversight framework of critical ICT third-party service providers
|
EU-Systemic Cyber Incident Coordination Framework (EU-SCICF):
ESAs Factsheet on the EU SCICF (Format: pdf, Size: 2,2 MB, Language: English)
ESAs establish framework to strengthen coordination in case of systemic cyber incidents
Further Links
Preparations for notifications of registers of information
ESAs Statement on DORA Appllication
ESAs’ report on the landscape of ICT third-party providers in the EU
Finals drafts in the second wave
The final ESA consultation drafts for the second wave of draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) as well as Guidelines were published on 17 July 2024:
Final report draft RTS on joint examination teams (Format: pdf, Size: 545,1 KB, Language: English)
Final report draft RTS and ITS on incident reporting (Format: pdf, Size: 1,4 MB, Language: English)
Final report DORA RTS on subcontracting (Format: pdf, Size: 745,5 KB, Language: English)
Second wave of consultations
The public consultations for the second wave of draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) as well as Guidelines ran until 04 March 2024:
CP on draft RTS subcontracting (Format: pdf, Size: 460,7 KB, Language: English)
CP on draft GL on costs and losses (Format: pdf, Size: 367,9 KB, Language: English)
CP on draft RTS on oversight harmonisation (Format: pdf, Size: 582,5 KB, Language: English)
CP on draft Guidelines on oversight cooperation (Format: pdf, Size: 504,2 KB, Language: English)
CP on draft RTS on TLPT (Format: pdf, Size: 703,0 KB, Language: English)
Finals reports in the first wave
On 17 January 2024, the European Supervisory Authorities published the first final draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS):
Final report on draft ITS on Register of Information (Format: pdf, Size: 2,9 MB, Language: English)
First wave of consultations
The public consultations for the first wave of draft Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) as well as Guidelines ran until 11 September 2023:
CP on draft RTS on ICT risk management (Format: pdf, Size: 953,0 KB, Language: English)
CP on draft ITS on register of information (Format: pdf, Size: 1,5 MB, Language: English)
Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information
History:
ESAs Press Release on the European Commission's Rejection of the ITS on Registers of Information
Final report on draft ITS on Register of Information (Format: pdf, Size: 2,9 MB, Language: English)
The contents on this website as well as hyperlinks to third party websites serve the purpose of providing general and non-binding information. These “Questions and Answers” do not constitute the FMA’s binding interpretation and in particular do not constitute interpretation within the scope of the question and answer processes (Q&As) of the three European Supervisory Authorities (EBA – European Banking Authority, ESMA – European Securities and Markets Authority, and EIOPA – European Insurance and Occupational Pensions Authority). All information on this website is provided without any guarantee, especially with regard to the up-to-dateness, completeness and correctness, and the FMA, including its employees or the persons responsible for this website, assume no liability whatsoever for the content; in addition, the FMA neither guarantees nor assumes liability for the use of hyperlinks or content that can be accessed via them.