{"id":160749,"date":"2024-07-23T15:09:18","date_gmt":"2024-07-23T13:09:18","guid":{"rendered":"https:\/\/www.fma.gv.at\/?page_id=160749"},"modified":"2025-11-26T08:52:42","modified_gmt":"2025-11-26T07:52:42","slug":"dora-oversight-framework-of-critical-ict-third-party-service-providers","status":"publish","type":"page","link":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/","title":{"rendered":"DORA \u2013 Oversight framework of critical ICT third-party service providers"},"content":{"rendered":"<?xml encoding=\"utf-8\" ?><div class=\"wp-block-cover is-light\"><img loading=\"lazy\" decoding=\"async\" width=\"1700\" height=\"716\" class=\"wp-block-cover__image-background wp-image-50882\" alt=\"\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\" style=\"object-position:98% 13%\" data-object-fit=\"cover\" data-object-position=\"98% 13%\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg 1700w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2-320x135.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2-640x270.jpg 640w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2-1536x647.jpg 1536w\" sizes=\"auto, (max-width: 1700px) 100vw, 1700px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-background-dim\" style=\"background-color:#a0a5b3\"><\/span><div class=\"wp-block-cover__inner-container is-layout-constrained wp-block-cover-is-layout-constrained\">\n<p class=\"has-text-align-center has-medium-font-size wp-block-paragraph\"><strong>ICT third-party service providers<\/strong><\/p>\n<\/div><\/div><div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div><p class=\"wp-block-paragraph\">The Digital Operational Resilience Act&nbsp;(DORA) creates an oversight framework for the ongoing monitoring of the activities of information and communication technology service providers (ICT third-party service providers) that are critical ICT third-party service providers for financial undertakings. In particular this is in reaction to the increased outsourcing in the ICT area and the concentration of dependencies of ICT third-party service providers.<\/p><p class=\"wp-block-paragraph\">The Lead Overseers will collect oversight fees from critical ICT third-party service providers to cover the costs arising from the Oversight Framework.<\/p><h2 class=\"wp-block-heading\">Critical ICT third-party service providers<\/h2><p class=\"wp-block-paragraph\">ICT third-party service providers are classified as critical by the European Supervisory Authorities (<a href=\"https:\/\/finance.ec.europa.eu\/regulation-and-supervision\/european-system-financial-supervision_en\" target=\"_blank\" rel=\"noopener\" class=\"external\">ESAs<\/a>) based on prescribed criteria that in turn are based on the registers of information prepared by the financial undertakings. ICT third-party service providers themselves may also apply for a review of their designation as critical.&nbsp;&nbsp;<\/p><p class=\"wp-block-paragraph\">The annually updated list of critical third-party ICT service providers was first published on November 18, 2025:<\/p><p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.esma.europa.eu\/sites\/default\/files\/2025-11\/List_of_designated_CTPPs.pdf\" target=\"_blank\" rel=\"noopener\" class=\"external\">List_of_designated_CTPPs.pdf&nbsp;<\/a><\/p><h2 class=\"wp-block-heading\">Lead Overseer<\/h2><p class=\"wp-block-paragraph\">The Lead Overseer subsequently conducts the monitoring of the critical ICT third-party service providers that have been allocated to it. Dependent on the extent of usage of critical ICT third-party service providers by the respective supervised financial undertakings, measures in terms of their total assets, the European Banking Authority (EBA) or the European Insurance and Occupational Pensions Authority (EIOPA) or the European Securities and Markets Authority (ESMA) acts as the Lead Overseer (LO). <\/p><p class=\"wp-block-paragraph\">The Lead Overseer assesses the third-party service providers&rsquo; management of ICT risks. For conducting this duty it has the power to request information, to conduct general investigations and on-site Inspections, to make recommendations and to request information about the measures taken on the basis of such recommendations by the ICT third-party service providers.<\/p><h2 class=\"wp-block-heading\">Specific players in the Oversight Framework<\/h2><p class=\"wp-block-paragraph\">Lead Overseers are assisted by Joint Examination Teams (JETs) in conducting their activities, that staff members of competent authorities also work in.<\/p><p class=\"wp-block-paragraph\">The coordination between the Lead Overseers takes place in the Joint Oversight Network. <\/p><p class=\"wp-block-paragraph\">An Oversight Forum has been established that is a Subcommittee of the Joint Committee of the three European Supervisory Authorities, of which representatives of competent authorities are also members. Its duties are to assist and advise on the activities of the Joint Committee of the European Supervisory Authorities, including the preparation of the designation and naming of critical ICT third-party service providers, preparing draft joint positions and draft common acts of the Joint Committee, the annual assessment of monitoring activities or the promotion of coordination measures to increase the digital operational resilience of financial undertakings.<\/p><h2 class=\"wp-block-heading\">Follow-up by competent authorities<\/h2><p class=\"wp-block-paragraph\">Risks that have been determined in the recommendations of the Lead Overseers to critical ICT third-party service providers are communicated by the competent authorities to financial undertakings that use these critical ICT third-party service providers. <\/p><p class=\"wp-block-paragraph\">The supervised entities subsequently take this information into account in their managing of ICT third-party risk. In the event that this is not done adequately from the perspective of the competent authorities, as a last resort they may instruct the partial or complete suspension of services by the critical ICT third-party service providers.<\/p><h2 class=\"wp-block-heading\" id=\"dora-dienstleister\">Questions and Answers<\/h2><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39b87a167bf\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39b87a167bf\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39b87a167bf\">        <span>With the DORA regime applying, critical ICT third-party service providers are subject to the provisions of the new Oversight Framework. As a result, are supervised financial undertakings that make use of such critical ICT third-party service providers no longer required to review or monitor them?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39b87a167bf\" class=\"collapse\" aria-labelledby=\"heading-6a39b87a167bf\">    <div class=\"card-body\"><p>Financial undertakings continue to remain fully responsible for the monitoring of ICT third-party service providers.<\/p>\n<p>They are supported in doing so by the Oversight Framework established in the context of digital operational resilience, for example by being informed by the Austrian Financial Market Authority (FMA) about risks that have been determined in the recommendations by Lead Overseers to critical ICT third-party service providers. Subsequently financial undertakings take these risks into account in the management of ICT third-party risk.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39b87a1689d\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39b87a1689d\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39b87a1689d\">        <span>What is the difference between the Oversight Framework and supervisory tasks?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39b87a1689d\" class=\"collapse\" aria-labelledby=\"heading-6a39b87a1689d\">    <div class=\"card-body\"><p>The Oversight Framework relates exclusively to the management of ICT risks of critical ICT third-party service providers and differs from the supervision of financial undertakings. In this regard, see Article 33(2) and (3) DORA.<\/p>\n<p>Operation of a critical ICT third-party service for example does not require a licence. Since a licence is not required, it can also not be withdrawn e.g. in the event of the recommendations handed down by the Lead Overseer failing to be implemented.<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39b87a1694d\">    <h3 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39b87a1694d\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39b87a1694d\">        <span>Are cloud service providers also within the scope of the Oversight Framework?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h3>  <\/div>  <div id=\"collapse-heading-6a39b87a1694d\" class=\"collapse\" aria-labelledby=\"heading-6a39b87a1694d\">    <div class=\"card-body\"><p>The Oversight Framework in the European Union created by DORA applies for all ICT third-party service providers, and therefore also for cloud service providers, providing that they have been identified and designated as critical ICT third-party service providers. (Recital 20 DORA)<\/p>    <\/div>  <\/div><\/div><div class=\"card\">  <div class=\"card-header\" id=\"heading-6a39b87a169ea\">    <h2 class=\"mb-0\">      <button class=\"btn btn-link btn-block text-left p-0 d-flex align-items-center justify-content-between\" type=\"button\" data-toggle=\"collapse\" data-target=\"#collapse-heading-6a39b87a169ea\" aria-expanded=\"false\" aria-controls=\"collapse-heading-6a39b87a169ea\">        <span>Is there a document explaining the monitoring framework for critical third-party ICT service providers?<\/span>        <i class=\"fa-solid fa-chevron-down text-primary\" aria-hidden=\"true\"><\/i>      <\/button>    <\/h2>  <\/div>  <div id=\"collapse-heading-6a39b87a169ea\" class=\"collapse\" aria-labelledby=\"heading-6a39b87a169ea\">    <div class=\"card-body\"><p><u>Please refer to the &sbquo;<a href=\"https:\/\/www.eba.europa.eu\/sites\/default\/files\/2025-07\/32044d65-455e-4fff-82d0-aa0d8ac2799f\/JC%202025%2029%20%20DORA%20Oversight%20Guide.pdf\" target=\"_blank\" rel=\"noopener\" data-auth=\"NotApplicable\" class=\"external\">Guide on oversight activities<\/a>&lsquo; prepared by the ESAs.<\/u><\/p>    <\/div>  <\/div><\/div><p class=\"wp-block-paragraph\">The contents on this website as well as hyperlinks to third party websites serve the purpose of providing general and non-binding information. These &ldquo;Questions and Answers&rdquo; do not constitute the FMA&rsquo;s binding interpretation and in particular do not constitute interpretation within the scope of the question and answer processes (Q&amp;As) of the three European Supervisory Authorities (EBA &ndash; European Banking Authority, ESMA &ndash; European Securities and Markets Authority, and EIOPA &ndash; European Insurance and Occupational Pensions Authority). All information on this website is provided without any guarantee, especially with regard to its up-to-dateness, completeness and correctness, and the FMA, including its employees or the persons responsible for this website, assume no liability whatsoever for the content; in addition, the FMA neither guarantees nor assumes liability for the use of hyperlinks or content that can be accessed via them.<\/p><h2 class=\"wp-block-heading\">Legal bases<\/h2><p class=\"wp-block-paragraph\">Information regarding the legal bases for DORA can be found on the FMA&rsquo;s <a href=\"https:\/\/fma.gv.at\/dora-digitale-operationale-resilienz-im-finanzsektor\/#dora-law\" target=\"_blank\" rel=\"noreferrer noopener\">&ldquo;<\/a><a href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/\" target=\"_blank\" rel=\"noreferrer noopener\">DORA &ndash; Digital Operational Resilience in the Financial Sector&rdquo;<\/a> web page.<\/p><section class=\"page-teaser\"><div class=\"container\"><div class=\"row\"><div class=\"col-12 custom-height\"><h2>Further Information about DORA<\/h2><hr><\/div><\/div><div class=\"row\"><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Landingpage-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/\">DORA &ndash; Digital operational resilience in the financial sector<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1700\" height=\"716\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2.jpg 1700w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-320x135.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-640x270.jpg 640w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Cover-DORA-Webseite-1700x716-DORA-IKT-Risikomanagement-2-1536x647.jpg 1536w\" sizes=\"auto, (max-width: 1700px) 100vw, 1700px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-ict-risk-management\/\">DORA &ndash; ICT Risk Management<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-IKT-bezogene-Vorfaelle-2-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-ict-related-incidents\/\">DORA &ndash; ICT-related incidents<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Testen-der-digitalen-operationalen-Resilienz-3-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-digital-operational-resilience-testing\/\">DORA &ndash; Digital operational resilience testing<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Management-des-IKT-Drittparteienrisikos-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-managing-of-ict-third-party-risk\/\">DORA &ndash; Managing of ICT third-party risk<\/a><\/h3><\/div><hr><\/div><\/div><div class=\"mb-4 col-lg-4\"><div class=\"inner\"><div class=\"content-text d-flex flex-column\"><div class=\"img-wrap\"><img loading=\"lazy\" decoding=\"async\" width=\"1320\" height=\"440\" src=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2.jpg\" class=\"attachment-full size-full wp-post-image\" alt=\"\" srcset=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2.jpg 1320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2-320x107.jpg 320w, https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Informationsaustausch-2-640x213.jpg 640w\" sizes=\"auto, (max-width: 1320px) 100vw, 1320px\"><\/div><h3><a class=\"stretched-link\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-exchange-of-information-and-contingency-exercises\/\">DORA &ndash; Exchange of information and contingency exercises<\/a><\/h3><\/div><hr><\/div><\/div><\/div><\/div><\/section>\n","protected":false},"excerpt":{"rendered":"<p>The Digital Operational Resilience Act&nbsp;(DORA) creates an oversight framework for the ongoing monitoring of the activities of information and communication &#8230;<\/p>\n","protected":false},"author":20,"featured_media":50889,"parent":52247,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"landing-page.php","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-160749","page","type-page","status-publish","has-post-thumbnail","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich\" \/>\n<meta property=\"og:description\" content=\"The Digital Operational Resilience Act&nbsp;(DORA) creates an oversight framework for the ongoing monitoring of the activities of information and communication ...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/\" \/>\n<meta property=\"og:site_name\" content=\"FMA \u00d6sterreich\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-26T07:52:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1320\" \/>\n\t<meta property=\"og:image:height\" content=\"440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@FMA_AT\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/\",\"name\":\"DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\",\"datePublished\":\"2024-07-23T13:09:18+00:00\",\"dateModified\":\"2025-11-26T07:52:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2024\\\/07\\\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg\",\"width\":1320,\"height\":440},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/dora-oversight-framework-of-critical-ict-third-party-service-providers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cross-sectoral topics\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DORA \u2013 Digital operational resilience in the financial sector\",\"item\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/cross-sectoral-topics\\\/dora\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"DORA \u2013 Oversight framework of critical ICT third-party service providers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\",\"name\":\"FMA \u00d6sterreich\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#organization\",\"name\":\"FMA - Finanzmarktaufsicht\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2017\\\/05\\\/FMA_Logo_Twitter_400x400.png\",\"contentUrl\":\"https:\\\/\\\/www.fma.gv.at\\\/wp-content\\\/uploads\\\/2017\\\/05\\\/FMA_Logo_Twitter_400x400.png\",\"width\":400,\"height\":400,\"caption\":\"FMA - Finanzmarktaufsicht\"},\"image\":{\"@id\":\"https:\\\/\\\/www.fma.gv.at\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/FMA_AT\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/","og_locale":"en_US","og_type":"article","og_title":"DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich","og_description":"The Digital Operational Resilience Act&nbsp;(DORA) creates an oversight framework for the ongoing monitoring of the activities of information and communication ...","og_url":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/","og_site_name":"FMA \u00d6sterreich","article_modified_time":"2025-11-26T07:52:42+00:00","og_image":[{"width":1320,"height":440,"url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@FMA_AT","twitter_misc":{"Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/","url":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/","name":"DORA \u2013 Oversight framework of critical ICT third-party service providers - FMA \u00d6sterreich","isPartOf":{"@id":"https:\/\/www.fma.gv.at\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/#primaryimage"},"image":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg","datePublished":"2024-07-23T13:09:18+00:00","dateModified":"2025-11-26T07:52:42+00:00","breadcrumb":{"@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/#primaryimage","url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg","contentUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2024\/07\/Header-DORA-Webseite-1320x440-DORA-Ueberwachungsrahmen-kritischer-IKT-Drittdienstleister-2.jpg","width":1320,"height":440},{"@type":"BreadcrumbList","@id":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/dora-oversight-framework-of-critical-ict-third-party-service-providers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.fma.gv.at\/en\/"},{"@type":"ListItem","position":2,"name":"Cross-sectoral topics","item":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/"},{"@type":"ListItem","position":3,"name":"DORA \u2013 Digital operational resilience in the financial sector","item":"https:\/\/www.fma.gv.at\/en\/cross-sectoral-topics\/dora\/"},{"@type":"ListItem","position":4,"name":"DORA \u2013 Oversight framework of critical ICT third-party service providers"}]},{"@type":"WebSite","@id":"https:\/\/www.fma.gv.at\/en\/#website","url":"https:\/\/www.fma.gv.at\/en\/","name":"FMA \u00d6sterreich","description":"","publisher":{"@id":"https:\/\/www.fma.gv.at\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.fma.gv.at\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.fma.gv.at\/en\/#organization","name":"FMA - Finanzmarktaufsicht","url":"https:\/\/www.fma.gv.at\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.fma.gv.at\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2017\/05\/FMA_Logo_Twitter_400x400.png","contentUrl":"https:\/\/www.fma.gv.at\/wp-content\/uploads\/2017\/05\/FMA_Logo_Twitter_400x400.png","width":400,"height":400,"caption":"FMA - Finanzmarktaufsicht"},"image":{"@id":"https:\/\/www.fma.gv.at\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/FMA_AT"]}]}},"toolset-meta":[],"publishpress_future_action":{"enabled":false,"date":"2026-06-30 00:34:34","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"translation_priority","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/160749","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/comments?post=160749"}],"version-history":[{"count":9,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/160749\/revisions"}],"predecessor-version":[{"id":21646497,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/160749\/revisions\/21646497"}],"up":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/pages\/52247"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/media\/50889"}],"wp:attachment":[{"href":"https:\/\/www.fma.gv.at\/en\/wp-json\/wp\/v2\/media?parent=160749"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}