Skip to Primary Navigation

DORA regulation outlining process for identifying critical ICT third-parties published

Graphic of Earth by little dots, binary code and line.
Photo: Getty Images

It implements the specific assessment approach to be used by supervisory authorities and outlines fees payable by vendors designated as critical.

The designation of critical ICT third-party service providers in the delegated regulation follows the two step approach outlined in the Discussion Paper published in May 2023.

The intended effect of the minimum thresholds applied in Step 1 is to produce a sub-set of third party providers, whose services support critical or

The

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience