DORARegulation (EU) 2022/2554
Definition: ICT third-party risk: ICT third-party risk
DORA Art. 3 (ICT third-party risk)
an ICT risk that may arise for a financial entity in relation to its use of ICT services provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing arrangements
Defines (1)
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.
See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.