Skip to main content
DORARegulation (EU) 2022/2554

Definition: ICT third-party risk: ICT third-party risk

DORA Art. 3 (ICT third-party risk)

an ICT risk that may arise for a financial entity in relation to its use of ICT services provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing arrangements

Defines (1)

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

DORA 32022R2554

Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.

See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.

Useful to someone you work with?

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.