Search
ESAs publish Report on the landscape of ICT third-party providers in the EU
The three European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) have today published an indicative overview of information and communication technology (ICT) third-party providers (TTP) as part of their preparations for the Digital Operational Resilience Act (DORA). The analysis aims to map the provision of ICT services by TPPs to financial entities in the European Union and to support the ESAs’ policy making process in light of the European Commission’s call for advice to further specify the criteria for critical ICT TPPs and to determine oversight fees.
Article 41
Harmonisation of conditions enabling the conduct of the oversight activitiesArticle 18
Classification of ICT-related incidents and cyber threatsRegulatory Technical Standards on ICT risk management framework and on simplified ICT risk management framework
The EBA launches consultation on its draft Guidelines on third-party risk management with regard to non-ICT related services
The European Banking Authority (EBA) today launched a public consultation on the draft Guidelines on the sound management of third-party risk. The draft Guidelines focus on third-party arrangements in relation to non-ICT related services provided by third-party service providers and their subcontractors with a particular focus on the provision of critical or important functions. These Guidelines revise and update the previous EBA Guidelines on outsourcing, published in 2019, in line with the Digital Operational Resilience Act (DORA). The consultation runs until 8 October 2025.
Article 15
Further harmonisation of ICT risk management tools, methods, processes and policiesESAs respond to the European Commission’s rejection of the technical standards on registers of information under the Digital Operational Resilience Act and call for swift adoption
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) today issued an Opinion on the European Commission’s (EC) rejection of the draft Implementing Technical Standards (ITS) on the registers of information under the Digital Operational Resilience Act (DORA). The ESAs raise concerns over the impacts and practicalities of the proposed EC changes to the draft ITS on the registers of information in relation to financial entities’ contractual arrangements with ICT third-party service providers.
Joint Technical Standards on major incident reporting
ESAs establish framework to strengthen coordination in case of systemic cyber incidents
The three European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) will establish the EU systemic cyber incident coordination framework (EU-SCICF), in the context of the Digital Operational Resilience Act (DORA), that will facilitate an effective financial sector response to a cyber incident that poses a risk to financial stability, by strengthening the coordination among financial authorities and other relevant bodies in the European Union, as well as with key actors at international level.
The EBA consults on revised Guidelines on internal governance
The European Banking Authority (EBA) today launched a consultation on its revised Guidelines on internal governance under the Capital Requirements Directive (CRD). The proposed revisions reflect the changes introduced in the CRD framework as well as in other relevant legislations, such as the Digital Operational Resilience Acts (DORA). The consultation runs until 7 November 2025 and is limited to the proposed changes.
Regulatory Technical Standards on criteria for the classification of ICT-related incidents
ESAs launch joint consultation on second batch of policy mandates under the Digital Operational Resilience Act
The European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) launched today a public consultation on the second batch of policy mandates under the Digital Operational Resilience Act (DORA). Today’s package includes four draft regulatory technical standards (RTS), one set of draft implementing technical standards (ITS) and two sets of guidelines (GL). These policy instruments aim to ensure a consistent and harmonised legal framework in the areas of major ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management and oversight over critical ICT third-party providers. The consultation runs until 4 March 2024.
Regulatory Technical Standards on the policy on ICT services supporting critical or important functions provided by ICT third-party service providers
Joint Regulatory Technical Standards on the harmonisation of conditions enabling the conduct of the oversight activities
The EBA releases technical package for its 3.5 reporting framework
The European Banking Authority (EBA) today published a technical package for version 3.5 of its reporting framework.