Skip to main content
European Banking Authority logo
  • Extranet
  • Log in
  • About us
    Back

    About us

    The EBA is an independent EU Authority.  We play a key role in safeguarding the integrity and robustness of the EU banking sector to support financial stability in the EU.

    Learn more
      • Mission, values and tasks
      • Organisation and governance
        • Governance structure and decision making
        • EBA within the EU institutional framework
        • Internal organisation
        • Accountability
      • Legal and policy framework
        • EBA regulation and institutional framework
        • Compliance with EBA regulatory products
      • Sustainable EBA
      • Diversity and inclusion
      • Careers
        • Vacancies
        • Meet our team
      • Budget
      • Procurement
    Close menu panel
  • Activities
    Back

    Activities

    To contribute to the stability and effectiveness of the European financial system, the EBA develops harmonised rules for financial institutions, promotes convergence of supervisory practices, monitors, and advises on the impact of financial innovation and the transition to sustainable finance.

    Start here
      • Single Rulebook
      • Implementing Basel III in Europe
      • Supervisory convergence
        • Supervisory convergence
        • Supervisory disclosure
        • Peer Reviews
        • Mediation
        • Breach of Union Law
        • Colleges
        • Training
      • Direct supervision and oversight
        • Markets in Crypto-assets
        • Digital operational resilience Act
      • Information for consumers
        • National competent authorities for consumer protection
        • How to complain
        • Personal finance at the EU level
        • Warnings
        • Financial education
        • National registers and national authorities responsible for handling complaints related to credit servicers
        • Frauds and scams
      • Research Workshops
      • Ad hoc activities
        • Our response to Covid-19
        • Brexit
    Close menu panel
  • Risk and data analysis
    Back

    Risk and data analysis

    To ensure the orderly functioning and stability of the financial system in the European Union, we monitor and analyse risks and vulnerabilities relevant for the regulation of banks and investment firms. We also facilitate information sharing among authorities and institutions through supervisory reporting and data disclosure.

    Learn more
      • Risk analysis
        • 2024 EU wide transparency exercise
        • EU-wide stress testing
        • Risk monitoring
        • Thematic analysis
      • Remuneration and diversity analysis
      • Reporting frameworks
        • Reporting Time Traveller
        • DPM data dictionary
      • Data
        • Registers and other list of institutions
        • Guides on data
        • Aggregate statistical data
        • Secondary reporting: data from Competent Authorities to the EBA
        • Data analytics tools
    Close menu panel
  • Publications and media
    Back

    Publications and media

    Communicating to all our audiences in the most effective way and using the most appropriate channels is crucial for us. Through our publications, announcements, and participation in external events, we are committed to reaching out to all our stakeholders to report about our policies, activities, and initiatives.

    Learn more
      • Publications
        • Guidelines
        • Regulatory Technical Standards
        • Implementing Technical Standards
        • Reports
        • Consultation papers
        • Opinions
        • Decisions
        • Staff papers
        • Annual reports
      • Press releases
      • Speeches
      • Interviews
      • Events
      • Media centre
        • Media gallery
        • Media resources
    Close menu panel

Breadcrumb

  1. Home
  2. Single Rulebook Q&A
  3. 2024_7288 Applicability of Regulation (EU) 2022/2554 (DORA) to ICT services provided by financial entities.
Question ID
2024_7288
Legal act
Regulation (EU) No 2022/2554 (DORA Reg)
Topic
Other DORA topics
Article
30
COM Delegated or Implementing Acts/RTS/ITS/GLs/Recommendations
Not applicable
Article/Paragraph
N/A
Type of submitter
Credit institution
Subject matter
Applicability of Regulation (EU) 2022/2554 (DORA) to ICT services provided by financial entities.
Question

Clarification is needed on whether financial institutions providing ICT services to other financial institutions – regardless of whether these services are ancillary to regulated financial activities – can be qualified as ICT third-party service providers under Regulation (EU) 2022/2554. If they are, must their contractual relationships comply with the mandatory provisions outlined in Article 30 of the mentioned Regulation or are these requirements inapplicable since such entities are already authorised/licenced/registered? 

Background on the question
  • Several ICT service providers, who are already subject to supervision as financial entities, claim that they do not fall under the definition of third-party ICT service providers contained in DORA for the simple reason that they are already subject to financial service or, more broadly, banking supervision. On the basis of this position, they are not willing to comply with the requirements set out in Article 30 of the Regulation (EU) 2022/2554.

  • We have unsuccessfully rejected this position on the basis that DORA does not provide an exception for them given that:

    - the Recital no. 63 of the Regulation (EU) 2022/2554 states “in light of the evolving payment services market becoming increasingly dependent on complex technical solutions, and in view of emerging types of payment services and payment-related solutions, participants in the payment services ecosystem, providing payment-processing activities, or operating payment infrastructures, should also be considered to be ICT third-party service providers under this Regulation, with the exception of central banks when operating payment or securities settlement systems, and public authorities when providing ICT related services in the context of fulfilling State functions”; 

    - according to Recital no. 78 of the Regulation (EU) 2022/2554 “financial entities providing ICT services to other financial entities, while belonging to the category of ICT third-party service providers under this Regulation, should also be exempted from the Oversight Framework since they are already subject to supervisory mechanisms established by the relevant Union financial services law”;

    - EBA, within the Q&As on ESAs 2024 DORA Dry Run exercise on reporting of the registers of information (version dated 4 July 2024), in relation to the question on “What types of third-party provider should be considered ICT third-party providers?” (Q&A no. 74) replied that “The definition of ‘ICT services’ in Article 3(21) of Regulation (EU) 2022/2554 intentionally maintains a broad scope. Recital (35) of Regulation (EU) 2022/2554 indeed clarifies that, with the aim of maintaining a high level of digital operational resilience, the definition of ICT services should be understood in a broad manner to the extent such services encompass digital and data services provided through ICT systems on an ongoing basis. Therefore, financial entities are responsible for undertaking such assessment for the services they rely on. Such assessment should be performed taking into account the clarification from DORA Recital (63), and without prejudice to sectoral regulations applicable on financial regulated services: in case a financial entity must be authorised/licenced/registered as financial entity to deliver a service, such service is therefore a regulated financial service and not an ICT service in the meaning of DORA Article 3(21)”; and

    - in last version of the Q&As (29 July 2024), EBA amended that question, specifying that “Given the number of questions received on the interpretation of ICT services and ICT service providers received from stakeholders requiring a legal interpretation, in order to provide legal certainty, the ESAs having liaised with the European Commission have agreed to respond to these questions via a formal Q&As in due course. For the time being, the financial entities are invited to register their contracts on a best effort basis taking into account that the Register of Information is also an ICT third-party risk management tool”.

Submission date
19/12/2024
Rejected publishing date
17/03/2025
Rationale for rejection

This question has been rejected because the matter it refers to has been answered in Q&A DORA030 (EIOPA 2999).

Status
Rejected question

Footer

EUROPEAN BANKING AUTHORITY

Our mission is to contribute to the stability and effectiveness of the European financial system through simple, consistent, transparent, fair regulation and supervision that benefits all EU citizens.


UE logoAn agency of the EU

EU Agencies Network logoEU Agencies Network

EMAS logoSustainable EBA

Contact us

  • Contacts
  • Ask a general question
  • Send a press query
  • Ask a regulatory question
  • File a complaint
  • Whistleblower reports

Stay up to date with our work

  • Subscribe to our email alerts
  • News & press RSS feed

Follow us on Social media

  • Bluesky
  • LinkedIn
  • X
  • YouTube

Find out about us

  • The EBA at a glance
  • Vacancies
  • Privacy policy
  • Legal notice
  • Cookies policy
  • Frauds and scams

Explore related sites

  • EIOPA
  • ESMA
  • ESRB
  • CEBS archive