On 22nd February 2024 the European Commission adopted two delegated acts under the Regulation on Digital Operational Resilience (DORA). These are the first of a series to complement and complete the EU regulatory framework linked to DORA.
The adopted acts are:
Commission Delegated Regulation supplementing Regulation (EU) 2022/2554 by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities. This sets out a two-step approach which ‘should be undertaken to filter the population of ICT third-party service providers and identify the most critical ICT third-party service providers’.
Commission Delegated Regulation supplementing Regulation (EU) 2022/2554 by determining the amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers and the way in which those fees are to be paid. Each critical ICT third-party service provider will need to pay an annual oversight fee. This act sets out the process for determining the fee that ‘should be imposed on each critical ICT third-party service provider’.
The European Parliament and Council will now scrutinise the delegated acts. They have a period of three months to raise objections, which they can extend for another three months. The acts will start applying after the period elapses and no objection is raised.
What is DORA?
The Digital Operational Resilience Act (DORA) is an EU regulation that will apply from 17 January 2025.
DORA is defined as follows:
The Digital Operational Resilience Act enhances the overall conduct of information and communication technologies (ICT) risk management, establishes testing rules for ICT systems and increases financial supervisors’ awareness of cyber risks through an EU harmonized incident reporting scheme.






