Article 29: Preliminary assessment of ICT concentration risk at entity level
DORA Art. 29, Chapter V
1. When performing the identification and assessment of risks referred to in Article 28(4), point (c), financial entities shall also take into account whether the envisaged conclusion of a contractual arrangement in relation to ICT services supporting critical or important functions would lead to any of the following: (a) contracting an ICT third-party service provider that is not easily substitut
378 words in the official text.
Sits inside (1)
Cites (1)
Cited by (1)
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.
See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.
Readers of this also ask
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.