DORA regulation outlining process for identifying critical ICT third-parties published

It implements the specific assessment approach to be used by supervisory authorities and outlines fees payable by vendors designated as critical.

The designation of critical ICT third-party service providers in the delegated regulation follows the two step approach outlined in the Discussion Paper published in May 2023.

The intended effect of the minimum thresholds applied in Step 1 is to produce a sub-set of third party providers, whose services support critical or

The

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in