EBA logo

EBA E-mail alert November 14, 2025

Final Q&As

Question ID: 2024_7290

Topic
ICT third-party risk management
Subject matter
Definition and scope of ICT services

What is the correct reading of Article 3 (21) and Recital 63, Article 2 and Article 58(2) of Regulation (EU) No. (EU) 2022/2554 (DORA Reg) in combination with  the COM/2023/0365 European Commission Report on the review of Directive 2015/2366/EU ?

Question ID: 2025_7439

Topic
ICT-related incidents (management / classification / reporting)
Subject matter
Staff costs

Do imputed staff costs count as part of staff costs in accordance with Article 18(1)(f) of Regulation (EU) 2022/2554 in conjunction with Article 7(1)(c) Delegated Regulation (EU) 2024/1772 and Article 4(e) Delegated Regulation (EU) 2025/301 and must, therefore, be reported as part of gross direct and indirect costs and losses of an incident?

Question ID: DORA038

Topic
Other DORA topics
Subject matter
Meaning of "recovering backed-up data using own systems"
Receiving ESA
EIOPA

When restoring backup data using own systems, financial entities shall use ICT systems that are physically and logically segregated from the source ICT system. What does DORA mean by "recovering backed-up data using own systems"? What does "own systems" mean? What is the source ICT system? The productive system whose data is backed-up or the system where the backed-up data is stored?

 

Question ID: DORA138

Topic
Digital operational resilience testing
Subject matter
Applicability of DORA and TFR Requirements to VASPs Not Classified as CASPs Under MiCAR
Receiving ESA
ESMA

Do the requirements of the Digital Operational Resilience Act (DORA) apply to Virtual Asset Service Providers (VASPs) that are not classified as Crypto-Asset Service Providers (CASPs) under the Markets in Crypto-Assets Regulation (MiCAR) as of December 30, 2024 and are benefiting from the MiCAR transition period?"

Question ID: DORA238

Topic
Other DORA topics
Subject matter
Application of DORA to non-EU AIFM
Receiving ESA
ESMA

The regulation applies to managers of alternative investment funds according to Article 2, point (k) of DORA. According to Article 3, (point 44), of DORA a manager of alternative investment funds is defined as “a manager of alternative investment funds as defined in Article 4(1), point (b), of Directive 2011/61/EU”.
According to Article 4(1), point (b), of Directive 2011/61/EU (AIFM Directive) “AIFMs’ means legal persons whose regular business is managing one or more AIFs”. We are of the understanding that Article 4(1), point (b), does not exclude non-EU AIFM. EU AIFM and non-EU AIFM are defined in Article 4(1), point (L) and point (ab). Since DORA only refers to article 4(1), point (b), of the AIFM Directive and not to article 4(1), point (L), we are wondering if DORA applies to both EU and non-EU AIFM as the definition implies.

Question ID: DORA186

Topic
Other DORA topics
Subject matter
Direct agreements between AIF and ICT service provider
Receiving ESA
ESMA

According to Article 2 par 1 of DORA AIFM is in scope of DORA, AIF is not defined as financial entity. There are situations when agreement is concluded directly between AIF and ICT service provider. It is obvious that the agreement in such situation should contain elements listed in Article 30 of DORA and the risk assessment should be performed by AIFM. But shall such agreement also be:
- included in the register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers according to Article 28 par 3 and
- notified to competent authority in a timely manner prior of the conclusion of the agreement if the agreement supports critical or important functions?

You can edit or cancel your subscription at any time. This is a test version of the newsletter.
Please do not reply to this message. If you have questions, please visit our contact page.
Please refer to EBA’s Legal notice regarding the handling of your personal data.
© European Banking Authority - https://www.eba.europa.eu