Digital concept of graphs

Topic: Digital operational resilience in financial services dora

 Subscribe to Digital operational resilience in financial services dora

Commission opens infringement procedures against Member States for failing to transpose DORA

April 02, 2025

On 27 March 2025, the European Commission issued a press release stating that it was taking action against several EU Member States that have failed to notify the Commission of measures they have adopted to transpose EU Directives into their national laws.

Commission adopts DORA RTS specifying the elements that a financial entity has to determine when subcontracting ICT services

April 02, 2025

On 24 March 2025, the European Commission adopted a draft Delegated Regulation supplementing the Regulation on digital operational resilience for the financial sector (DORA) with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions.

Asset management: Risk allocation and liability profiles in technology contracts and outsourcings for asset managers

March 19, 2025

Increased regulatory burdens on asset management businesses have resulted in additional cost pressures. However, regulation has also required more pricing transparency, which has led to an increasingly competitive market, with investors demanding either ultra-low cost or increasingly bespoke investment solutions.

Further DORA delegated acts published in OJ

February 27, 2025

On 20 February 2025, the following was published in the Official Journal of the EU (OJ).

ESAs provide a roadmap towards the designation of CTPPs under DORA

February 27, 2025

On 18 February 2025, the European Supervisory Authorities (ESAs) issued a roadmap to the designation of critical ICT third-party service providers (CTPPs) under the Digital Operational Resilience Act (DORA).

DORA delegated act published in OJ

February 27, 2025

On 13 February 2025, there was published in the Official Journal of the EU (OJ), Commission Delegated Regulation (EU) 2025/295 of 24 October 2024 supplementing the Regulation on digital operational resilience for the financial sector with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities.

DORA Delegated Regulation on TLPT

February 27, 2025

On 13 February 2025, the European Commission adopted a draft Delegated Regulation supplementing the Regulation on digital operational resilience for the financial sector with regard to regulatory technical standards

Eurosystem updates TIBER-EU framework to align with DORA

February 27, 2025

On 11 February 2025, the Eurosystem updated its European framework for threat intelligence-based ethical red-teaming (TIBER-EU framework) to align with the regulatory technical standards (RTS) of the Digital Operational Resilience Act (DORA) on threat-led penetration testing (TLPT).

DORA: Commission rejects draft RTS on subcontracting ICT services supporting critical or important functions

February 17, 2025

On 31 January 2025, the European Commission (Commission) published a letter (dated 21 January 2025) it had sent to the Chair of the Joint Committee of the European Supervisory Authorities (ESAs).

EBA amends its Guidelines on ICT and security risk management measures in the context of DORA application

February 17, 2025

On 11 February 2025, the European Banking Authority (EBA) issued an updated version of its guidelines on ICT and security risk management measures which were built on the provisions of Article 74 of the Capital Requirements Directive IV and the Payment Services Directive 2.