The European Supervisory Authorities (EBA, EIOPA and ESMA) will jointly hold a public event on the upcoming Digital Operational Resilience Act (DORA).
The ESAs are particularly interested in the submission of potential concerns and areas of attention related to the policy mandates and related matters within and beyond 12 months of the entry into force of the DORA, especially – as quoted:
+ RTS on ICT risk management framework (RMF) (Article 15);
+ RTS on simplified ICT RMF (Article 16(3));
+ RTS to further specify the detailed content of the policy in relation to the contractual arrangements on the use of ICT services supporting critical or important functions provided by TPPs (Article 28(10));
+ RTS to specify elements when sub-contracting critical or important functions Article 30(5));
+ Two RTS on incident reporting (Articles 18(3) and 20(a));
+ ITS to establish the templates for the Register of information (Article 28(9)); and
+ By 30.09.2023, the input to the European Commission’s Call for advice on criticality criteria (Article 31(6)). 3
As policy development is still in its infancy, ESA staff will not answer specific questions on policy mandates.
If you want to join the technical discussion on DORA, please register at https://ec.europa.eu/eusurvey/runner/Joint_ESAs_Public_Event_on_DORA until 31 January 2023.