Tracker details
This tracker is current as of 1 September 2026 and will be updated from time to time. It was prepared by Jet Francke, Floor van de Swaluw and Lars Peeters, from Osborne Clarke, The Netherlands.
If you have any questions, kindly get in touch with them or reach out to your local DORA expert at Osborne Clarke.
Please note: The tracker is provided for general information purposes only. It has been produced with care, but may contain errors. Updates are published at... This tracker is not intended and should not be used as a substitute for legal advice. Specific legal advice should be taken before acting on any of the topics covered. This tracker covers DORA only.
For more information, see our DORA page.
About the measures
Level 1 measures consist of the Digital Operational Resilience Act (DORA) itself: Regulation (EU) 2022/2554.
Level 2 measures specify certain aspects of DORA, expressed as:
- A Commission-delegated Act
- RTS: Regulatory Technical Standards
- ITS: Implementing Technical Standards.
Level 3 measures are provided by the various authorities to ensure consistent interpretation throughout EU member states. They include guidelines and Q&A documents.
Authorities:
- AFM: Stichting Autoriteit Financiële Markten
- DNB: De Nederlandsche Bank
- EC: European Commission
- ESMA: European Securities and Markets Authority
- EBA: European Banking Authority
- EIOPA: European Insurance and Occupational Pensions Authority
- ESAs: European Supervisory Authorities (EBA, ESMA and EIOPA, acting jointly through the Joint Committee).
Commission delegated acts - Level 2 measures
Ordered by first DORA reference
| Legal reference DORA Article(s) | Description | Status | Authority |
| 31(6) | Criteria for designation of critical ICT third-party service providers. | Published in OJEU. Applies per June 2024. | EC |
| 43(2) | Amount and method of payment of oversight fees. | Published in OJEU. Applies per June 2024. | EC |
Regulatory Technical Standards - Level 2 measures
Ordered by first DORA reference
| Legal reference DORA Article(s) | Description | Status | Authority |
| 15(4) | ICT risk management tools, methods, processes and policies. | Published in OJEU. Applies per July 2024. | ESAs |
| 16(3) | Simplified ICT risk-management review framework. | Published in OJEU. Applies per July 2024. | ESAs |
| 18(4) | Classification criteria and materiality thresholds for major ICT-related incidents and significant cyber threats. | Published in OJEU. Applies per July 2024. | ESAs |
| 20(3) | Content and time limits for the initial notification of, and intermediate and final report of major ICT-related incidents, and the content of the voluntary notification for significant cyber threats. | Published in OJEU. Applies per March 2025. | ESAs |
| 26(11) | Criteria for identifying financial entities required to perform threat-led penetration testing (TLPT), the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation need for the implementation of TLPT and for the facilitation of mutual recognition. | Published in OJEU. Applies per July 2025. | ESAs |
| 28(10) | Detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers. | Published in OJEU. Applies per July 2024. | ESAs |
| 30(5) | Elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions. | Published in OJEU. Applies per July 2025. | ESAs |
| 41(2) | Harmonisation of conditions enabling the conduct of the oversight activities. | Published in OJEU. Applies per March 2025. | ESAs |
Implementing Technical Standards - Level 2 measures
Ordered by first DORA reference
| Legal reference DORA Article(s) | Description | Status | Authority |
| 20(4) | Standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat. | Published in OJEU. Applies per March 2025. | ESAs |
| 28(9) | Standard templates for the register of information. | Published in OJEU. Applies per December 2024. | ESAs |
Guidelines
ESA Guidelines
Ordered by first DORA reference
| Legal reference DORA Article(s) | Description | Status | Authority |
| 11(11) | On the estimation of aggregated annual costs and losses caused by major ICT-related incidents including a common template for the submission. | Joint Guidelines June 2024. | ESAs |
| 2(4)(a) | On the oversight cooperation and information exchange between the ESAs and the competent authorities. | Joint Guidelines November 2024. | ESAs |
AFM Guidance
Ordered chronologically
| Legal reference DORA Article(s) | Description | Status | Authority |
| DORA update 1 | Getting ready for the arrival of DORA | Published in July 2023. | AFM |
| DORA update 2 | Management of ICT risk for third-party providers | Published in December 2023. | AFM |
| DORA update 3 | ICT risk management | Published in January 2024. | AFM |
| DORA update 4 | Management, classification and reporting of ICT-related incidents | Published in June 2024. | AFM |
| DORA update 5 | Explanation of testing Digital Operational Resilience | Published in September 2024. | AFM |
| DORA update 6 | What to expect with regard to DORA supervision (Q1 2025) | Published in January 2025. | AFM |
| DORA update 7 | The sector is making progress, but some areas require attention | Published in August 2026. | AFM |
DNB Reporting Guidance
Ordered chronologically
| Description | Status | Authority |
| Reporting DORA registers of information in April 2025. | Published on 26 February 2025. | DNB |
| Reporting DORA registers of information. | Published on 25 March 2025. | DNB |
| Reporting DORA registers of information in March 2026. | Published on 3 February 2026. | DNB |
ICT related questions
ICT risk management
Ordered by first DORA reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 3(22) | Critical or important functions | What is the level of engagement required for an ICT service to be considered as “support[ing] critical or important functions”? | Answer published on 27 June 2024. | EIOPA QA 2750 |
| 3(28) | EU Subcontractors | DORA Article 3(28) excludes natural persons from the definition of 3rd country subcontractors, does the same apply to EU Subcontractors? | Answer published 17 December 2024. | ESMA QA 2378 |
| 6(10) | Scope of the Regulation | Why are the outsourcing requirements of Article 28(3) RTS (S)RMF concerning the simplified ICT risk management framework (Art. 16 DORA) more stringent than those of the regular ICT risk management framework? Would an alignment of Art. 6(10) DORA and Art. 28(3) RTS (S)RMF concerning this point be feasible? | Answer published. | EIOPA QA 3450 |
| 8(7) | Connection of technologies, applications or systems | What does DORA mean by connecting technologies, applications or systems? | Answer published on 24 July 2025. | EIOPA QA 2996 |
| 16 | ICT risk management (standard vs simplified depending on type of entity) | Is a small and non-interconnected investment firm (Art. 12 (1) IFR (Regulation (EU) 2019/2033)) that also holds a licence as a crowdfunding service provider according to Art. 12 ECSPR (Regulation (EU) 2020/1503) obligated to apply Art. 5-15 DORA or is it allowed to use the simplified ICT risk management framework of Art. 16 DORA? | Answer published on 17 December 2025. | ESMA QA 2292 |
ICT-related incidents
Ordered by first DORA reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 3(8) | Classification of phishing-attacks as a reportable major ICT-related incident | Can individual phishing incidents that target the customers of a financial entity in their “private sphere” be subsumed under “compromises the security of the network and information systems” pursuant to Article 3 No. 8 of Regulation (EU) 2022/2554 and can they therefore constitute a major ICT-related incident that must be reported pursuant to Article 19 (1) of Regulation (EU) 2022/2554? | Answer published on 6 February 2026. | EBA QA 7613 |
| 3(21) | Types of "telephone services" included under the definition of "ICT Services" | Which types of telephone services fall within the scope of the definition of "ICT services"? | Answer published on 6 February 2026. | EBA QA 7539 |
| 18(3) | Critical Services Affected | Are all three of the components of article 6 of the Delegated Act on the Classification of Major Incidents are cumulatively required to trigger the criteria on Critical Services Affected? | Answer published on 11 December 2024. | EBA QA 7047 |
| 18(4)(c) | Staff costs | Do imputed staff costs count as part of staff costs in accordance with Article 18(1)(f) of Regulation (EU) 2022/2554 in conjunction with Article 7(1)(c) Delegated Regulation (EU) 2024/1772 and Article 4(e) Delegated Regulation (EU) 2025/301 and must, therefore, be reported as part of gross direct and indirect costs and losses of an incident? | Answer published on 14 November 2025. | EBA QA 7439 |
| 19 | Duplicate ICT Incident Reporting | Is duplicate incident reporting via the ECB SSM Cyber Incident Reporting Framework required, alongside DORA incident reporting under Article 19? | Answer published on 11 December 2024. | EBA QA 7050 |
| 19(4), 20(a) | Understanding of time limits of intermediate reports for major related ICT-incidents. | Is our standing of Article 6 of the RTS correct, that an institution should submit more than one intermediate report for a major ICT-incident, if that incident continues over the 72 hours threshold for the initial intermediate report? | Answer published on 15 April 2024. | ESMA QA 2158 |
ICT third-party risk management
Ordered by DORA reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 3(21) | Definition and scope of ICT services | What is the correct reading of Article 3 (21) and Recital 63, Article 2 and Article 58(2) of Regulation (EU) No. (EU) 2022/2554 (DORA Reg) in combination with the COM/2023/0365 European Commission Report on the review of Directive 2015/2366/EU? | Answer published on 14 November 2025. | EBA QA 7290 |
| 13 | Separate and dedicated network for the administration of ICT assets | Does the requirement for a 'separate and dedicated network for the administration of ICT assets' refer to a physically separate network, a logically segmented one ? Could you please clarify what is meant by 'administration of ICT assets' in the context , does this refer only to manual administrative activities, or does it also include automated processes. | Answer published on 20 November 2025. | EIOPA QA 3347 |
| 28 | Financial entities and resellers | According to point 107 of the Q&A: "If the reseller is not providing the ICT service on an ongoing basis, it should not be considered an ICT TPP." Given this statement, how should we treat the effective service provider? Additionally, based on the clarification provided in the Q&A, does this imply that in case of reselling without new services from the reseller : all the remediation process should end? | Answer published on 20 November 2025. | EIOPA QA 3300 |
| 28 | Scope of the Regulation | Does an ICT provider’s NIS2 status (including classification as a critical or essential entity) in any way limit the applicability of DORA Articles 28–30 for a financial entity, particularly regarding the requirement to include DORA-aligned contractual provisions and obtain the cooperation needed for ICT third-party risk management? | Answer published on 1 June 2026. | EIOPA QA 3501 |
| 28(3) | Scope of Register of Information for Contractual Arrangement on the use of ICT Services Provided by ICT Third-party Service Providers | According to Article 28(3) of DORA, must an EU parent bank, which has subsidiaries both within and outside the EU, maintain the register of information regarding all contractual arrangements for the use of ICT services only for subsidiaries that are subject to DORA (financial entities established in the EU), or does this requirement extend to subsidiaries established outside the EU for which DORA does not apply? | Answer published on 25 July 2025. | EBA QA 7098 |
| 28(5) | Definition of appropriate information security standards and highest quality information security standards | What are the standards Article 28(5) is referring to? | Answer published on 8 August 2025. | EIOPA QA 3200 |
| 30(3)(e) | Key contractual provisions | Is it in line with Article 30(3)(e)(i) of Regulation (EU) 2022/2554 (DORA), in conjunction with Article 8 of Commission Delegated Regulation (EU) 2024/1773, to appoint an independent third party to perform a regular joint audit of a third-party ICT service provider that supports critical or important functions, and would such an arrangement satisfy DORA requirements such that individual audits by each financial entity would not be required under normal circumstances in situation, when final selection of the audit company will be approved by the General Meeting of ICT service provider, which is composed of representatives of financial entities that are the sole owners of this ICT service provider? | Answer published on 20 November 2025. | EIOPA QA 3392 |
Q&A - Level 3 measures (ctd)
Register of information questions
Ordered by first DORA reference and QA reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 28 | Functions identification | Could a same Function Identifier in field B_06.01.0010 be linked to multiple options/values (including the value ‘support functions’) in field B_06.01.0020? What is the meaning of ‘linked’ in the instruction of the field B_06.01.0020? | Answer published on 28 March 2025. | EIOPA QA 3076 |
| 28 | Major ISPs concern about divulging sub-contractors | We were approached by representatives of the major ISPs in AT. They expressed concern about divulging their sub-contractors, as the information is currently not public and could be actionable by potential attackers. Should these sub-contractors indeed be disclosed by the ISPs to a large number of financial undertakings? | Answer published on 24 July 2025. | EIOPA QA 3210 |
| 28 | Reporting Templates | We have a question on FAQ#74 in the DORA preparations document "Frequently asked question on reporting of the registers of information (updated on 19 March 2025)". FAQ 74 is very helpful in understanding how to complete B.02.01, B.02.03, B.05.02 for the mentioned situation. However we are unclear what should be included in B.02.02. We see there is a mention of examples being available (FAQ#35 for dry run) but the link doesn't appear to work (just goes back to the overall EBA preparations page, within which we don't see an examples file). Can you clarify whether for example both contracts mentioned in FQA 74 that are to be included in separate rows in B.02.03 should also be reported as two separate row in B.02.02, and if not which contract arrangement number should be used etc.? | Answer published on 20 November 2025. | EIOPA QA 3302 |
| 28 | Register of Contracts | If a contract that is included in the ROI as at 31-Mar-2025 is terminated between 1-Apr-2025 and 31-Dec-2025, should it be included in the ROI reported as at 31-Dec-2025 with a reason (B_02.02.0090) filled in? If yes, should the contract be included in the ROI report as at 31-Dec-2026? | Answer published on 20 November 2025. | EIOPA QA 3393 |
| 28 | Reporting | In the situation where we have 2 entries in B.01.02 with different C0100 currencies and there is an intra-group contracts between them, which currency should be used in B.02.01 C0040? Should it be the currency of the buyer of ICT services or the currency or the supplier? | Answer published. | EIOPA QA 3480 |
| 28(1-3) | Obligation to maintain a register of information for FEs exempt under article 16 | Are financial entities, which according to article 16(1) in DORA are excluded from application of Articles 5 to 15, also are excluded from application of article 28 of DORA? | Answer published on 8 August 2025. | EBA QA 7388 |
| 28(3) | Register of Information | Is the list of the type of ICT services in Annex III of the draft Implementing Technical Standards on the standard templates for the purposes of the register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers an exhaustive list? Can an out-of-scope financial entity – such as a micro or SME insurance intermediary - be considered as an ICT third party provider if they provide ICT services that are described in the Annex III of the ESA ITS on information register, to an in scope financial entity - such as an insurer? Can an out-of-scope financial entity – such as a micro or SME insurance intermediary - be considered as an ICT third party provider if they provide ICT services that are NOT described in the Annex III of the ESA ITS on information register, to an in scope financial entity - such as an insurer? | Answer published on 8 August 2025. | EIOPA QA 3199 |
| 28(3) | Identification of ICT Service Providers | Can the ESAs confirm there is no expectation to capture within the Register of Information the ICT subcontractors of non-ICT service providers? | Answer published on 8 August 2025. | EBA QA 7089 |
| 28(3) | Annual Report on new arrangements on the use of ICT Services | Does Article 28(3) DORA require a separate and specific communication in addition to the Register of Information, or whether the communication of such data is already fulfilled through the annual submission of the same Register, constituting a single compliance obligation? In the event that a separate communication is required in addition to the annual submission of the Register of Information, what is the meaning of the term 'categories of third-party ICT service providers'? | Answer published on 14 August 2025. | EBA QA 7309 |
| 28(3) | How to fill the refPeriod field of the parameters.csv file for the DORA register of information | As part of the DORA register of information packaging process, we are required to include a parameters.csv file that contains a refPeriod field. Could you please confirm what specific date should be used for the refPeriod? | Answer published on 8 August 2025. | EBA QA 7387 |
| 28(9) | Parent company that is not a financial entity itself maintaining the register of information | Is a parent company that is not a financial entity itself required to maintain the information register? | Answer published on 28 March 2025. | EIOPA QA 2990 |
| 28(9) | Template specific instructions – field B_01.02.0050 (Hierarchy of the financial entity within the group) | What does ‘where applicable’ mean in the title of data field B_02.01.0050? What should be reported in this field in case the entity that is being reported in this template is not a financial entity (i.e., option 22, 23, or 24 was selected in field B_01.02.0040 for the entity type)? | Answer published on 28 March 2025. | EBA QA 7277 |
| 28(9) | Template specific instructions - field B_01.02.0060 (LEI of the direct parent undertaking of the financial entity) | What should be reported in case the financial entity does not have a direct parent undertaking (for example, is the parent undertaking itself) or reports the register on an individual basis? | Answer published on 28 March 2025 | EBA QA 7278 |
| 28(9) | Template specific instructions – field B_02.02.0130 (Country of the governing law of the contractual arrangement) | How to report field B_02.02.0130 where the ICT service is not supporting a critical or important function considering that according to the data model this data field is a primary key? | Answer published on 28 March 2025. | EBA QA 7279 |
| 28(9) | Template specific instructions – field B_02.02.0130 (Country of the governing law of the contractual arrangement) | How to report field B_02.02.0150 where the ICT service is not related to storage of data (B_02.02.0140 = 'No')? | Answer published on 28 March 2025. | EBA QA 7280 |
| 28(9) | Template specific instructions – field B_02.02.0160 (Location of management of the data) | How to report data field B_02.02.0160 where the ICT service is not based or does not foresee data processing? | Answer published on 28 March 2025. | EBA QA 7281 |
| 28(9) | Template specific instructions – field B_04.01.0040 (Identification code of the branch) | How to report data field B_04.01.0040 if the financial entity is not a branch? | Answer published on 28 March 2025. | EBA QA 7282 |
| 28(9) | Template specific instructions – field B_05.01.0020 (Type of code to identify the ICT third-party service provider) | How to report type of identification code in data field B_05.01.0020 when using codes other than LEI or EUID? | Answer published on 28 March 2025. | EBA QA 7283 |
| 28(9) | Template specific instructions – field B_05.02.0060 (Identification code of the recipient of sub-contracted ICT services) | How to report data field B_05.02.0060 if the ICT third-party service provider is a direct provider (rank =1)? | Answer published on 28 March 2025. | EBA QA 7284 |
| 28(9) | Template specific instructions – primary keys | How to report data fields in case of missing values? | Answer published on 28 March 2025. | EBA QA 7285 |
| 28(9) | Part 2 – Template specific instructions to template B_06.01 | Data point B_06.01.0050 is missing from the official ITS templates. Is this data point no longer applicable? | Answer published on 28 March 2025. | EBA QA 7313 |
Q&A - Level 3 measures (ctd)
General DORA questions
Ordered by first DORA reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 2 | Quantitative criteria for the identification of insurance and reinsurance undertakings | For the identification of insurance and reinsurance undertakings the RTS on TLPT specifies quantitative criteria in Article 2(2)(g) that must be met in a cumulative way. Additionally, in the last subparagraph of Article 2(2) of the RTS on TLPT further quantitative criteria are given. In order to foster supervisory convergence and to avoid different understandings of legal requirements that lead to inconsistent practices in the identification of undertakings required to perform TLPT, we suggest to clarify how to apply these criteria. | Answer published on 20 November 2025. | EIOPA QA 3371 |
| 2(3) | Applicability of DORA and TFR Requirements to VASPs Not Classified as CASPs Under MiCAR | Do the requirements of the Digital Operational Resilience Act (DORA) apply to Virtual Asset Service Providers (VASPs) that are not classified as Crypto-Asset Service Providers (CASPs) under the Markets in Crypto-Assets Regulation (MiCAR) as of December 30, 2024 and are benefiting from the MiCAR transition period?" | Answer published on 8 December 2024. | ESMA QA 2364 |
| 3(22) | Definition of "function" |
| Answer published on 28 March 2025. | EIOPA QA 2959 |
| 11, 16 | Microenterprises and risk management framework (RMF) |
| Answer published on 11 December 2024. | ESMA QA 2219 |
| 31(8) | Exemption for Non-EU ICT Intra-group Service Providers | Is it accurate to interpret that an ICT intra-group service provider established outside the EU (non-EU country), providing critical services to an EU-based financial institution (parent undertaking), falls within the exemption outlined in Article 31(8) of DORA, thereby exempting the need for establishing a subsidiary within the EU? | Answer Published on 11 December 2024. | EBA QA 7096 |
| 54 | Obligation of competent authorities to publish decisions relating to administrative measures | Can competent authorities in DORA publish decisions relating to administrative penalties and remedial measures, or can they only publish decisions on administrative penalties? | Answer published on 27 June 2024. | EIOPA QA 2790 |
Q&A - Level 3 measures (ctd)
Other DORA topics
Ordered by first DORA reference and Q&A reference
| Legal reference DORA Article(s) | Topic | Question (summary) | Status | Reference |
| 2 | Direct agreements between AIF and ICT service provider | According to article 2 par 1 of DORA AIFM is in scope of DORA, AIF is not defined as financial entity. There are situations when agreement is concluded directly between AIF and ICT service provider. It is obvious that the agreement in such situation should contain elements listed in article 30 of DORA and the risk assessment should be performed by AIFM. But shall such agreement also be:
| Answer published on 26 February 2025. | ESMA QA 2447 |
| 2 | Regulated activities and other non-regulated activities | If a company has both DORA regulated activities and other - non-regulated - activities, does DORA apply to those other non-regulated activities as well? If so, is there a minimum % that the DORA regulated activities should be of the overall company activities for the non-regulated activities to be regulated by DORA as well? | Answer published on 20 November 2025. | EIOPA QA 3193 |
| 2 | Scope and Territorial Applicability | Scope and Territorial Applicability of DORA Does DORA apply exclusively to entities operating within the EU? Consider the following examples for clarification: Example 1: An organization headquartered in an EU Member State, such as Spain, operates branches in non-EU countries (e.g., New Zealand, Japan). Would the requirements of DORA extend to these branches? Example 2: An organization headquartered in an EU Member State, such as France, has legal entities conducting activities within the scope of DORA outside the EU (e.g., in the United States, Canada, or Mexico). Would the requirements of DORA apply to these legal entities? | Answer published on 20 November 2025. | EIOPA QA 3195 |
| 2(k) | Does DORA also apply to non-EU AIFM? | The regulation applies to managers of alternative investment funds according to Article 2, point (k) of DORA. According to Article 3, (point 44), of DORA a manager of alternative investment funds is defined as “a manager of alternative investment funds as defined in Article 4(1), point (b), of Directive 2011/61/EU”. According to Article 4(1), point (b), of Directive 2011/61/EU (AIFM Directive) “AIFMs’ means legal persons whose regular business is managing one or more AIFs”. We are of the understanding that Article 4(1), point (b), does not exclude non-EU AIFM. EU AIFM and non-EU AIFM are defined in Article 4(1), point (L) and point (ab). Since DORA only refers to article 4(1), point (b), of the AIFM Directive and not to article 4(1), point (L), we are wondering if DORA applies to both EU and non-EU AIFM as the definition implies. | Answer published on 27 May 2025 2025. | ESMA QA 2547 |
| 2(1) | Application of DORA to AIFMs which have chosen to opt-in to the application of the AIFMD but whose asset under management is below the thresholds as provided for by Article 3(2) of AIFMD | Are sub-threshold alternative investment fund managers (AIFMs) as referred to in Article 3(2) of Directive 2011/61/EU (“AIFMD”), which have chosen to opt-in to the application of the AIFMD according to Article 3(4) of that Directive, captured within the scope of application of Regulation (EU) 2022/2554 (“DORA”) under Articles 2(1)(k) and 2(3)(a) of DORA, if the thresholds regarding assets under management (“AuM”) referred to under Article 3(2) of AIFMD are not exceeded by such AIFM? | Answer published on 3 December 2024. | ESMA QA 2356 |
| 2(1)(a), (n) and (o) | 2(1)(a), (n) and (o) | Is Regulation (EU) 2022/2554 (DORA) applicable to third-country branches in an EU country, if in the third country where their head office is established they would qualify as entities listed under under Article 2(1)(a), (n) or (o)? | Answer published 17 December 2025. | EIOPA QA 3097 |
| 2(1)(o) | "Ancillary insurance intermediaries" within the scope of DORA | Are ancillary insurance intermediaries falling under Article 1(3) of Directive EU 2016/97 on insurance distribution (IDD) within the scope of Article 2(1)(o) DORA? | Answer published on 22 January 2025. | EIOPA QA 3074 |
| 2(3)(e) | Scope of application of DORA for intermediaries | Considering that insurance and reinsurance intermediaries and ancillary insurance intermediaries are not obliged by law to setup a dedicated legal entity to carry out insurance distribution and therefore some of them may have a principal professional activity other than insurance distribution, how should the calculation of the thresholds defined in DORA Article 2(3) point (e) for exclusion of those intermediaries which are micro, small or medium enterprises be interpreted? | Answer published on 17 December 2025. | EIOPA QA 3350 |
| 3(7) | EUC, EULA and Shadow IT | For complying with the regulatory provisions envisaged by the DORA Regulation, Financial Entities should consider End User Computing (EUC) tools, End User License Agreements (EULA), and the conditions of Shadow IT. Would it be possible to obtain the regulatory references for these areas? | Answer published on 11 February 2024. | ESMA QA 2103 |
| 3(21) | Provision of services by the financial entity in line with its regulatory framework | Based on the definition of DORA Article 3(21), what types of services should be considered ICT services? | Answer published 22 January 2025. | EIOPA QA 2999 |
| Critical and important functions | Is there a detailed list of critical or important functions from a DORA perspective? | Answer published on 17 December 2025. | EIOPA QA 2622 | |
| 3(22) | Critical or important functions | Is the term “critical or important function” as defined in DORA to be understood as being equivalent to “critical or important functions or activities” under the Solvency II regime? If not, which functions are to be considered as critical or important for insurance companies? | Answer published on 27 June 2024. | EIOPA QA 2749 |
| 3(44) | AIFMs and scope of application of Articles 2(1)(k) and 2(3)(a) DORA | Which alternative investment fund managers (AIFMs) are captured within the scope of application of DORA under Articles 2(1)(k) and 2(3)(a) of DORA? | Answer published on 27 June 2024. | EIOPA QA 2734 |
| 3(60),(63) and (64) | Thresholds of Micro, Small and Medium enterprises | Is it possible for an entity to have two different size classifications – one under DORA and one under Commission Recommendation 2002/361/EC? | Answer published on 27 June 2024. | EIOPA QA 2787 |
| 3(60-64) | Scope of Group | It is not defined in DORA how to calculate whether you meet the 250FTE criterium. We found guidance from the EC in 2003/361/EC on how to calculate whether a firm is small/medium/large and how to consider linked entities and parent entities, but we are not sure if this is the guidance to follow. Can you please provide clarity on these matters? | Answer published on 10 April 2026. | EIOPA QA 3100 |
| 5 | Application of DORA for outsourced critical services that are not ICT | In the scenario where a UK financial services firm, or an offshore financial services firm (e.g. in Guernsey), provides services to an EU financial services firm. For example, in the scenario where an EU financial services firm outsourced its fund management to a UK asset management firm to manage a fund. Would the EU firm be expected to have sought reassurance from the UK fund manager that the UK firm is also compliant with DORA? | Answer published on 12 February 2024. | ESMA QA 2107 |
| 12(3) | Meaning of "recovering backed-up data using own systems" | What does DORA mean by "recovering backed-up data using own systems"? What does "own systems" mean? What is the source ICT system? The productive system whose data is backed-up or the system where the backed-up data is stored? | Answer published on 20 November 2025. | EIOPA QA 2991 |
| 13(1)(c) | Elaboration on the meaning of a separated and dedicated network for ICT asset administration | In the "RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework"; How should we read: ''A separate and dedicated network for ICT asset administration, along with strict prohibition of direct internet access[...]''? (article 13, paragraph 1, sub (c)). A separate and dedicated network could be on-premises, but is a virtual-LAN sufficient? or is it enough to have it in the regular production-LAN with other systems? and what if the CMDB is in a cloud environment? is it then a de facto separated and dedicated network or not? | Answer published on 25 July 2025. | EBA QA 7178 |
| 13(6) | Digital operational training | I would like to know if the requirement regarding the digital operational training should be conducted periodically, in a frequent manner? | Answer published on 20 November 2025. | EIOPA QA 3380 |
| 28(6), 30(3)(e) | Audit frequency limitations | As DORA requires financial entities to pre-determine the frequency of audits and inspections on the basis of a risk-based approach, are financial entities not permitted to agree on a maximum audit frequency (e.g. once per year) with their ICT third-party service providers? | Answer published on 18 September 2025. | ESMA QA 2646 |
| 28(9) | The scope of the regulation described in Article 6 mismatches what is presented as an option in the Annex I, Part 2 of the same regulation | Do financial entities must include non-financial entities within the same group in the Register of Information? If not, why is there an option to do so? | Answer published on 25 July 2025. | EBA QA 7297 |
| Recital 63 | Public authorities exemptions | Is the exemption for public authorities as quoted in recital 63 sentence 3 last half-sentence meant to be a general exemption for all public authorities as defined under art. 3 no. 65 DORA when providing ICT related services in the context of fulfilling State functions, or is the exemption limited to payment services and payment-related solutions? | Answer published on 6 February 2026. | EBA QA 7466 |