{"id":16561,"date":"2024-09-04T06:00:38","date_gmt":"2024-09-04T06:00:38","guid":{"rendered":"https:\/\/letslaw.es\/?p=16561"},"modified":"2024-09-03T07:49:19","modified_gmt":"2024-09-03T07:49:19","slug":"dora-regulation","status":"publish","type":"post","link":"https:\/\/letslaw.es\/en\/dora-regulation\/","title":{"rendered":"DORA Regulation: procurement requirements for third-party suppliers"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">On 16 January 2023, Regulation 2022\/2554 of the European Parliament and of the Council, known as DORA, entered into force. Financial institutions and ICT providers must comply with DORA by 17 January 2025.<\/span><\/p>\n<p><a title=\"DORA regulation\" href=\"https:\/\/letslaw.es\/en\/dora-regulation-digital-operational-resilience-financial-sector\/\"><span style=\"font-weight: 400;\">DORA<\/span><\/a><span style=\"font-weight: 400;\"> aims <\/span><b>to strengthen digital operational resilience in the EU financial sector and ensure its resilience to disruptions<\/b><span style=\"font-weight: 400;\">. Financial institutions must have specific capabilities, mechanisms and policies in place to manage and report serious ICT-related incidents.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">DORA covers EU financial institutions and ICT service providers. ESAs can designate third party providers according to criteria and impact. In addition to updating regulations, DORA introduces new obligations in four pillars to improve system security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Entities must have an ICT risk management framework in place in accordance with Chapter V of the Regulation, under the responsibility of the management body. This body defines strategies, assesses risks and can be held accountable for non-compliance.<\/span><\/p>\n<p><b>DORA requires reporting of ICT incidents with procedures for monitoring, classification and communication to the authorities<\/b><span style=\"font-weight: 400;\">. Entities must send an initial notification, an interim and a final report on the causes of the incident, which the competent authority will share with the specified recipients.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">DORA requires annual digital operational resilience testing, including vulnerability assessments and, for critical roles, penetration testing. ICT providers must also be involved to address vulnerabilities.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Finally, third party risk management in relation to ICT, detailed in Chapter V, Section I, also applies to suppliers. Financial institutions should manage this risk by negotiating agreements, conducting audits and setting performance targets in areas such as integrity, accessibility and security.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">But with reference to the providers, according to Article 31, they are designated by the European Supervisory Authorities through the Joint Committee and on the recommendation of the Supervisory Forum, which shall:<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">a) designate third-party providers of ICT services that are essential for financial institutions, following an assessment taking into account the criteria specified in paragraph 2;<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">b) designate as lead supervisor for each critical third-party ICT service provider the European Supervisory Authority that is responsible, in accordance with Regulation (EU) No 1093\/2010, Regulation (EU) No 1094\/2010 or Regulation (EU) No 1095\/2010, for the financial institutions that collectively have the largest share of total assets of the total asset value of all financial institutions using the services of the relevant critical third-party ICT service provider, as reflected in the sum of the individual balance sheets of those financial institutions.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">The designation referred to in paragraph 1.a) of the above Article is based on certain criteria set out in point 2 of the same Article, as follows:<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">a) the systemic impact on the stability, continuity or quality of the provision of financial services in the event of a potential large-scale operational failure of the third-party ICT service provider concerned affecting the provision of its services, taking into account the number of financial institutions and the total value of assets of the financial institutions served by the third-party ICT service provider concerned;<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">b) the systemic nature or importance of the financial institutions relying on the third-party ICT service provider concerned, assessed according to the following parameters:<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">i) the number of global systemically important entities (G-SIIs) or other systemically important entities (O-SIIs) relying on the relevant third-party ICT service provider,<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">ii) the interdependence between the G-SIIs or O-SIIs referred to in subparagraph (i) and other financial entities, including situations where the G-SIIs or O-SIIs provide financial infrastructure services to other financial entities;<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">c) the reliance of financial institutions on the services provided by the relevant third party ICT service provider in relation to critical or important functions of financial institutions that ultimately involve the same third party ICT service provider, regardless of whether financial institutions use such services directly or indirectly, through outsourcing arrangements;<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">d) the degree of substitutability of the third-party ICT service provider, taking into account the following parameters:<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">i) the lack of real alternatives, even partial, due to the limited number of third party ICT service providers active in a specific market, or the market share of the third party ICT service provider concerned, or the complexity or technical difficulty involved, inter alia in relation to proprietary technologies, or the specific characteristics of the organisation or the activity of the third party ICT service provider,<\/span><\/i><\/p>\n<p><i><span style=\"font-weight: 400;\">ii) difficulties related to the partial or full migration of the relevant data and workloads from the third party ICT service provider concerned to another, because of the significant financial, time or other resource costs that the migration process could entail, or because of the increased ICT or other operational risks to which the financial institution could be exposed through such migration.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">In short, DORA, which became applicable on 16 January 2023, strengthens digital operational resilience in the EU financial sector. It imposes new responsibilities on financial institutions and ICT providers <\/span><b>to manage incidents, conduct resilience testing and monitor third party risks<\/b><span style=\"font-weight: 400;\">. The European Supervisory Authorities are key in the selection and regulation of critical providers. Through four main pillars, DORA updates regulations to increase the security and stability of the sector.<\/span><\/p>\n<div class=\"cyp_post_formulario\"><h2>Contact Us<\/h2>\n<div class=\"wpcf7 no-js\" id=\"wpcf7-f3074-o1\" lang=\"es-ES\" dir=\"ltr\" data-wpcf7-id=\"3074\">\n<div class=\"screen-reader-response\"><p role=\"status\" aria-live=\"polite\" aria-atomic=\"true\"><\/p> <ul><\/ul><\/div>\n<form action=\"\/en\/wp-json\/wp\/v2\/posts\/16561#wpcf7-f3074-o1\" method=\"post\" class=\"wpcf7-form init wpcf7-acceptance-as-validation\" aria-label=\"Formulario de contacto\" novalidate=\"novalidate\" data-status=\"init\">\n<fieldset class=\"hidden-fields-container\"><input type=\"hidden\" name=\"_wpcf7\" value=\"3074\" \/><input type=\"hidden\" name=\"_wpcf7_version\" value=\"6.1.5\" \/><input type=\"hidden\" name=\"_wpcf7_locale\" value=\"es_ES\" \/><input type=\"hidden\" name=\"_wpcf7_unit_tag\" value=\"wpcf7-f3074-o1\" \/><input type=\"hidden\" name=\"_wpcf7_container_post\" value=\"0\" \/><input type=\"hidden\" name=\"_wpcf7_posted_data_hash\" value=\"\" \/><input type=\"hidden\" name=\"_wpcf7_recaptcha_response\" value=\"\" \/>\n<\/fieldset>\n<div class=\"campo_nombre\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-name\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Name\" value=\"\" type=\"text\" name=\"your-name\" \/><\/span><\/div>\n<div class=\"campo_telefono\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-phone\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-tel wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-tel datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Phone\" value=\"\" type=\"tel\" name=\"your-phone\" \/><\/span><\/div>\n<div class=\"campo_email\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-email\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-email wpcf7-validates-as-required wpcf7-text wpcf7-validates-as-email datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Email\" value=\"\" type=\"email\" name=\"your-email\" \/><\/span><\/div>\n<div class=\"campo_asunto\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-asunto\"><input size=\"40\" maxlength=\"400\" class=\"wpcf7-form-control wpcf7-text wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Subject\" value=\"\" type=\"text\" name=\"your-asunto\" \/><\/span><\/div>\n<div class=\"campo_mensaje\" style=\"width:100%\"> <span class=\"wpcf7-form-control-wrap\" data-name=\"your-mensaje\"><textarea cols=\"40\" rows=\"10\" maxlength=\"2000\" class=\"wpcf7-form-control wpcf7-textarea wpcf7-validates-as-required datos-contacto2\" aria-required=\"true\" aria-invalid=\"false\" placeholder=\"Message\" name=\"your-mensaje\"><\/textarea><\/span><\/div>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"\" type=\"hidden\" name=\"cyp_form_url\" \/>\n<input class=\"wpcf7-form-control wpcf7-hidden\" value=\"cyp_zonaweb\" type=\"hidden\" name=\"zonaweb\" \/>\n<span class=\"wpcf7-form-control-wrap recaptcha\" data-name=\"recaptcha\"><span data-sitekey=\"6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" class=\"wpcf7-form-control wpcf7-recaptcha g-recaptcha\"><\/span>\r\n<noscript>\r\n\t<div class=\"grecaptcha-noscript\">\r\n\t\t<iframe loading=\"lazy\" src=\"https:\/\/www.google.com\/recaptcha\/api\/fallback?k=6LfbCuUpAAAAAGu5f0__hms_y9Kscc_NCNdDGnEJ\" frameborder=\"0\" scrolling=\"no\" width=\"310\" height=\"430\">\r\n\t\t<\/iframe>\r\n\t\t<textarea name=\"g-recaptcha-response\" rows=\"3\" cols=\"40\" placeholder=\"Aqu\u00ed la respuesta de reCAPTCHA\">\r\n\t\t<\/textarea>\r\n\t<\/div>\r\n<\/noscript>\r\n<\/span>\n<div style=\"width:100%\">\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important;margin-bottom:15px !important\">\nBy clicking on \"Send\" you accept our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup_ingles\">+ Info<\/a>\n<\/p>\n<p class=\"form-input-check\" style=\"color:#444444 !important;padding:0px !important;margin:0px !important;font-size:12px !important\">\n<span class=\"wpcf7-form-control-wrap\" data-name=\"checkbox-173\"><span class=\"wpcf7-form-control wpcf7-checkbox wpcf7-exclusive-checkbox\"><span class=\"wpcf7-list-item first last\"><label><input type=\"checkbox\" name=\"checkbox-173\" value=\"\" \/><span class=\"wpcf7-list-item-label\"><\/span><\/label><\/span><\/span><\/span> I agree to receive outlined commercial communications from LETSLAW, S.L. in accordance with the provisions of our <a href=\"https:\/\/letslaw.es\/en\/privacy-policy\/\" target=\"_blank\">Privacy Policy<\/a> - <a href=\"javascript:\/\/\" class=\"cyp_legal_popup\">+ Info<\/a>\n<\/p>\n<\/div>\n<div class=\"vc_col-sm-12 botton-datos-contacto\"><input class=\"wpcf7-form-control wpcf7-submit has-spinner\" type=\"submit\" value=\"Send\" \/><\/div><input type='hidden' class='wpcf7-pum' value='{\"closepopup\":false,\"closedelay\":0,\"openpopup\":false,\"openpopup_id\":0}' \/><div class=\"wpcf7-response-output\" aria-hidden=\"true\"><\/div>\n<\/form>\n<\/div>\n<div>","protected":false},"excerpt":{"rendered":"<p>Financial institutions and ICT providers must comply with DORA by 17 January 2025.<\/p>\n","protected":false},"author":55,"featured_media":16559,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[258],"tags":[],"class_list":["post-16561","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-law"],"_links":{"self":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/comments?post=16561"}],"version-history":[{"count":4,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16561\/revisions"}],"predecessor-version":[{"id":16565,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/posts\/16561\/revisions\/16565"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media\/16559"}],"wp:attachment":[{"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/media?parent=16561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/categories?post=16561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/letslaw.es\/en\/wp-json\/wp\/v2\/tags?post=16561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}