DORARegulation (EU) 2022/2554
Definition: ICT third-party risk: ICT third-party risk
DORA Art. 3 (ICT third-party risk)
an ICT risk that may arise for a financial entity in relation to its use of ICT services provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing arrangements
Defines (1)
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.
See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.
Readers of this also ask
Useful to someone you work with?
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.