EU DORA Guidelines for ICT Service Providers: What You Should Know

Key EU DORA Requirements for Third-Party ICT Providers.

  1. Robust Information Security Standards 2. Transparency in Audits and Evaluations 3.Strong Contractual Agreements 4.Ongoing Training 5.Digital Operational Resilience Testing 6.Exit Plans

1. High Information Security Standards:

2. Audits:

3. Contractual Agreements: 

  • A clear and comprehensive description of all services that the ICT service provider will offer.
  • Explicit details on whether subcontracting of ICT services is allowed, and under what conditions.
  • The locations where the contracted and/or subcontracted services will be delivered, including where data will be stored and processed.
  • Provisions addressing the availability, authenticity, integrity, and confidentiality of data protection, including personal data.
  • For ‘Critical’ ICT service providers, there is a mandate to establish and test business contingency plans and to implement necessary ICT security measures, tools, and policies.

4. Training Programes: 

5. Digital Operational Resilience Testing:

Leave a Comment