Consultation on the first batch of Digital Operational Resilience Act (DORA) policy products
The consultation includes four draft regulatory technical standards (RTS) and one set of draft implementing technical standards (ITS). These technical standards aim to ensure a consistent and harmonised legal framework in the areas of ICT risk management, major ICT-related incident reporting and ICT third-party risk management.
Consultation process
Comments to this consultation can be sent to the ESAs on these links:
- Consultation paper on RTS on ICT risk management framework (Art.15) and RTS on simplified ICT risk management framework (Art.16)
- Consultation paper on RTS on criteria for the classification of ICT-related incidents (Art.18.3)
- Consultation paper on ITS to establish the templates for the register of information (Art.28.9)
- Consultation paper on RTS to specify the policy on ICT services performed by ICT third-party providers (Art.28.10)
The deadline for the submission of comments is 11 September 2023. All contributions received will be published following the end of the consultation, unless requested otherwise.
A public hearing will be organised in the form of a webinar on 13 July 2023 from 09:00 to 18:00 CET. The ESAs invite interested stakeholders to register using the Registration form by 16:00 CET on 10 July 2023. The dial-in details will be communicated to the registered participants in due time.