DORA, Articles 31-44 (Oversight of Critical ICT Third-Party Service Providers)
Regulation (EU) 2022/2554, Arts. 31-44
In force since .
A sector security regimes rule binding public and private bodies.
- Private right of action
- No
- Obligation class
- Governance, Security, Reporting
As of .
What it requires
- It reaches you if you are an ICT third-party service provider that the European Supervisory Authorities designate as critical for financial entities under Article 31(1), point (a), after an assessment of the criteria in Article 31(2). It does not reach a financial entity providing ICT services to other financial entities, an ICT intra-group service provider, a provider subject to the oversight frameworks that support the tasks referred to in Article 127(2) of the Treaty on the Functioning of the European Union, or a provider that serves only financial entities active solely in one Member State from within that Member State (Article 31(8)). Your oversight duties run from the starting date notified with your designation, no later than one month after the notification (Article 31(5)), and the designation is not used until the Commission has adopted the delegated act specifying the criteria (Article 31(7)).
- If you are part of a group, designate one legal person as the coordination point for adequate representation and communication with the Lead Overseer, and notify the financial entities to which you provide services of your designation as critical (Article 31(4) and (5)).
- If you are established in a third country, establish a subsidiary in the Union within the 12 months following your designation, because financial entities may use your services only if you have, and notify the Lead Overseer of any changes to the structure of the management of that subsidiary (Article 31(12) and (13)).
- Cooperate in good faith with the Lead Overseer and assist it in the fulfillment of its tasks (Article 35(5)). Provide the information the Lead Overseer requires by simple request or by decision, including business or operational documents, contracts, policies, documentation, ICT security audit reports, ICT-related incident reports and information on the parties to whom you have outsourced operational functions or activities, and do not supply incorrect or misleading information, since you remain fully responsible if the information is incomplete, incorrect or misleading (Article 37).
- Submit to the investigations and the on-site inspections that the Lead Overseer orders by decision, including the examination of records, data and procedures, explanations from your representatives, and entry to your business premises, land or property (Articles 38 and 39).
- Where the Lead Overseer examines a planned subcontracting arrangement with a subcontractor established in a third country that concerns critical or important functions of a financial entity, transmit the information regarding subcontracting to the Lead Overseer using the template referred to in Article 41(1), point (b) (Article 35(1), point (d)(iv)).
- Within 60 calendar days of receiving the Lead Overseer's recommendations, notify the Lead Overseer of your intention to follow them or give a reasoned explanation for not following them (Article 42(1)). If a competent authority requires financial entities to suspend or terminate their use of your service, cooperate fully with the financial entities affected, in particular in the suspension or termination of their contractual arrangements (Article 42(9)).
Who enforces it
Enforcement body
The Lead Overseer appointed for each critical ICT third-party service provider under Article 31(1), point (b), which conducts the oversight of the provider under Article 33(1).
What this law does
Article 31(1) has the European Supervisory Authorities, through the Joint Committee and on recommendation from the Oversight Forum, designate the ICT third-party service providers that are critical for financial entities and appoint a Lead Overseer for each.
Article 31(2) bases the designation on the systemic impact of a large scale operational failure, the systemic character of the financial entities that rely on the provider, their reliance on it for critical or important functions, and its degree of substitutability.
Article 31(8) takes out of the designation financial entities providing ICT services to other financial entities, ICT intra-group service providers, providers subject to oversight frameworks that support the tasks referred to in Article 127(2) of the Treaty on the Functioning of the European Union, and providers that provide ICT services solely in one Member State to financial entities that are only active in that Member State.
Article 31(5) has the Lead Overseer notify the provider of the outcome of the assessment, lets the provider submit a reasoned statement within 6 weeks of the notification, and sets a starting date for oversight activities that is no later than one month after the notification of the designation. Article 31(7) provides that the designation is not used until the Commission has adopted a delegated act specifying the criteria in Article 31(2).
Article 31(4) requires critical ICT third-party service providers that are part of a group to designate one legal person as a coordination point to ensure adequate representation and communication with the Lead Overseer. Article 31(5) also requires the provider to notify the financial entities to which it provides services of its designation as critical.
Article 31(12) allows financial entities to use the services of a designated provider established in a third country only if it has established a subsidiary in the Union within the 12 months following the designation, and Article 31(13) requires that provider to notify the Lead Overseer of any changes to the structure of the management of the subsidiary.
Article 33(1) has the Lead Overseer conduct the oversight of the assigned critical ICT third-party service providers and act as their primary point of contact for all matters related to oversight.
Article 33(2) and (3) have the Lead Overseer assess whether each critical provider has comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk it may pose to financial entities, covering service security, availability, continuity, scalability and quality, physical security, risk management processes, governance, incident reporting, data portability, testing and audits.
Article 33(4) has the Lead Overseer adopt an individual oversight plan describing the annual oversight objectives and the main oversight actions planned for each critical provider, communicated to the provider yearly. Article 35(1) gives the Lead Overseer the powers to request information, to conduct general investigations and inspections, to request reports on the actions taken after its recommendations, and to issue recommendations on the areas referred to in Article 33(3).
Article 35(5) requires critical ICT third-party service providers to cooperate in good faith with the Lead Overseer and to assist it in the fulfillment of its tasks. Article 35(6) requires the Lead Overseer, after at least 30 calendar days from the provider's receipt of notification of the measures, to adopt a decision imposing a periodic penalty payment on a provider that wholly or partly fails to comply with the measures required under Article 35(1), points (a), (b) and (c).
Article 35(7) and (8) set the periodic penalty payment daily until compliance is achieved, for no more than six months, at up to 1 % of the average daily worldwide turnover of the critical provider in the preceding business year. Article 35(9) makes the penalty payments administrative in nature and enforceable, and allocates their amounts to the general budget of the European Union.
Article 37(1) lets the Lead Overseer, by simple request or by decision, require critical providers to provide all information necessary for its duties, including business or operational documents, contracts, policies, documentation, ICT security audit reports and ICT-related incident reports. Article 38(4) requires the representatives of critical providers to submit to investigations on the basis of a decision of the Lead Overseer.
Article 39(6) requires a critical provider to submit to on-site inspections ordered by decision of the Lead Overseer. Article 42(1) requires a critical provider, within 60 calendar days of receiving the Lead Overseer's recommendations, to notify the Lead Overseer of its intention to follow them or to provide a reasoned explanation for not following them.
Article 42(6) lets competent authorities, as a measure of last resort, require financial entities to suspend, in part or completely, the use or deployment of a service provided by a critical provider until the risks identified in the recommendations have been addressed, and where necessary to terminate the relevant contractual arrangements.
Article 42(9) requires a critical provider affected by such a decision to fully cooperate with the financial entities impacted, in particular in the suspension or termination of their contractual arrangements. Article 43(1) provides that the fee charged to a critical provider covers all costs derived from the execution of the oversight duties and is proportionate to its turnover. Article 64 applies the Regulation from .
When LexLint raises it
When your app profile says your app provides financial services.