DORA Now in Force in the EU

Cadwalader, Wickersham & Taft LLP
Contact

Cadwalader, Wickersham & Taft LLP

 

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (“DORA”), which establishes a uniform set of requirements relating to the security of network and information systems supporting financial system participants’ business processes, is now live as of 17 January 2025, without any transitional provision.

A wide range of rules applicable for managing ICT risks, including risks linked to ICT third-party service providers, is now in force. DORA applies to nearly all financial entities regulated in the EU, with very few exemptions for smaller institutions. For the first time, it also covers major unregulated ICT third-party service providers; a significant shift in European financial regulation.

In particular, DORA requires financial firms to:

  • have internal governance and control frameworks that ensure they manage all ICT risks effectively;
  • have a robust ICT risk management framework that enables them to address ICT risk;
  • report major ICT-related incidents and notify significant cyber threats to their competent authorities;
  • carry out digital operational resilience testing (see Digital Operational Resilience Testing);
  • manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework; and
  • share information and intelligence about cyber threats and vulnerabilities.

DORA also lays down rules for the establishment and conduct of a new oversight framework for critical ICT third-party service providers (which includes many of the large technology companies) when they provide services to the firm.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Cadwalader, Wickersham & Taft LLP

Written by:

Cadwalader, Wickersham & Taft LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Cadwalader, Wickersham & Taft LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide