DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entities
DORA moves technology resilience in financial services from good practice into contractual and supervisory obligation.
It requires regulated entities to know their critical technology dependencies, hold specific terms in supplier contracts, test their resilience and report incidents. The significant shift is that your supplier's resilience becomes something you are answerable for, rather than something you hope about.
Checked against the primary source.
More on Regulation and law
- Regulatory scope is a security architecture questionThe rope follows the wire
- Incident reporting deadlines change response prioritiesThe clock starts with the incident
- Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties applyThree flaps, one outcome
- Breach notification and incident notification are different testsTwo holes, two different shapes
- Legal privilege does not make incident facts disappearIt seals the advice, not the facts
- Regulation can make suppliers part of your compliance systemTheir controls, on your sheet
