This delegated regulation defines oversight requirements for ICT third-party service providers under DORA. It mandates critical providers to submit detailed information on their operations, market impact, and security frameworks. It also addresses subcontracting, risk management, and compliance monitoring by competent authorities to support resilience across the financial sector.
Author: European Commission
Status: Adopted / Published
Adoption date: 2024-10-24
Last updated: 08 Aug 2025
Category: Relevant legislation
Subcategory: Delegated Regulation