DORA: JC 2024 108 Report on the feasibility for further centralisation of reporting of major ICT-related incidents
The report assesses the feasibility of three different models: the baseline model, a model with enhanced data sharing arrangements and a fully centralised model. It considers the potential burden and cost reductions, as well as the efficiency and effectiveness gains that each model would bring for cross-sector supervisory practices.
European Banking Authority
EIOPA
ESMA
EU Digital Operational Resilience Act (DORA)
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011
European Parliament
Council of the European Union (the Council)
AWS User Guide to the Digital Operational Resilience Act (DORA)
This document provides information regarding the adoption of Amazon Web Services (AWS) cloud for entities who are subject to the forthcoming Digital Operational Resilience Act (DORA). This guide describes the roles that AWS and its customers play in managing operational resilience in and on AWS, describes the AWS Shared Responsibility Model, compliance frameworks, advanced tools, and security measures that customers can use to evaluate their compliance with applicable regulatory requirements; with an overview of the DORA regulatory requirements and guidance that regulated customers can consider when adopting AWS.
01/06/2024
AWS-User-Guide-to-the-Digital-Operational-Resilience-Act.pdf
White paper: Comprehensive Guide to the DORA EU regulation
This white paper is intended for professionals who are starting to learn about the European Union’s DORA regulation, and it presents the key elements to start a compliance project.
DORA documentation: What is required?
This article maps each relevant requirement from DORA with documents that are the best suited to cover those requirements.
Commission Delegated Regulation 2024/1772 Official Text
Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents
European Commission (the Commission)
13/03/2024
OJ_L_202401772_EN_TXT.pdf
Commission Delegated Regulation 2024/1773 Official Text
Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers
European Commission (the Commission)
13/03/2024
OJ_L_202401773_EN_TXT.pdf
Commission Delegated Regulation 2024/1774 Official Text
Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework
European Commission (the Commission)
13/03/2024
OJ_L_202401774_EN_TXT.pdf
Recording of the DORA Dry Run Summary workshop
European Banking Authority
18/12/2024
Commission Implementing Regulation (EU) 2024/2956
Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information
European Commission (the Commission)
29/11/2024
OJ_L_202402956_EN_TXT.pdf
Preparations for reporting of DORA registers of information
List of useful materials regarding DORA Register of Information
European Banking Authority
Data Model for DORA RoI
European Banking Authority
List of possible values for all data fields with drop downs
European Banking Authority
03/03/2025
List of possible values for all data fields with drop downs (updated 3 March 2025) (1).xlsx
Explanation of data quality feedback from Registers of information (RoI) validations by the ESAs
European Banking Authority
ESMA
EIOPA
20250210 - RoI validation feedback explanation.pdf
Frequently Asked Questions about DORA RoI
This document provides answers to theFAQs about the preparation and the reporting of the registers of information of contractual arrangements with the ICT third-party providers that financial entities need to maintain in accordance with Article 28(3) of DORA and as specified in the Commission Implementing Regulation (EU) 2024/2956 (ITS on the registers of information). The answers focus on the questions regarding the practical nature of the filling the templates as specified in the Commission Implementing Regulation (EU) 2024/2956, preparation of the reporting files, their submission to the ESAs.
European Banking Authority
ESMA
EIOPA
14/02/2025
20250214 - DORA RoI reporting FAQ.pdf
Report on the feasibility for further centralisation of reporting of major ICT-related incidents
This report contains a feasibility study on options to further centralise incident reporting under DORA, covering the aspects detailed in Article 21(1) of the said legislation, and all those additional elements that are considered useful for the correct contextualization and elaboration of the study
European Banking Authority
EIOPA
ESMA
17/01/2025
JC_2024_108_Report_on_the_feasibility_for_further_Centralisation_of_reporting_of_major_ICT_incidents (1).pdf