The Delegated Regulation specifies the requirements for and the contents of the policy on the use of ICT services supporting critical or important functions provided. The policy is a mandatory part of the ICT third-party risk strategy which some financial entities must adopt under Article 28(4) of DORA.
Author: European Commission
Status: Adopted / Published
Adoption date: 2024-03-13
Last updated: 08 Aug 2025
Category: Relevant legislation
Subcategory: Delegated Regulation