Digital concept of graphs

Topic: Digital operational resilience in financial services dora

 Subscribe to Digital operational resilience in financial services dora

Published in OJ: Commission Delegated Regulation (EU) 2025/532 supplementing DORA with regard to RTS specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions

July 21, 2025

On 2 July 2025, there was published in the Official Journal of the EU (OJ), Commission Delegated Regulation (EU) 2025/532 of 24 March 2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions.

Do your technology and outsourcing contracts properly address liability for cyber incidents?

July 01, 2025

Most incidents handled by our Norton Rose Fulbright cyber team originate from the customer’s service provider. In many cases it is the service provider’s systems, infrastructure and environment which proves to be the most vulnerable to cyber breaches and security issues.

Global Regulation Tomorrow Plus: EMEA insights series: Episode 21: Update from Italy on MiCA, DORA, CRD 6 and AI

June 04, 2025

In the latest episode of our EMEA insights series, Maria Beatrice Gilesi of our Milan office discusses recent communications from the Italian regulators regarding MiCA, DORA, CRD 6 and AI.

Commission opens infringement procedures against Member States for failing to transpose DORA

April 02, 2025

On 27 March 2025, the European Commission issued a press release stating that it was taking action against several EU Member States that have failed to notify the Commission of measures they have adopted to transpose EU Directives into their national laws.

Commission adopts DORA RTS specifying the elements that a financial entity has to determine when subcontracting ICT services

April 02, 2025

On 24 March 2025, the European Commission adopted a draft Delegated Regulation supplementing the Regulation on digital operational resilience for the financial sector (DORA) with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions.

Asset management: Risk allocation and liability profiles in technology contracts and outsourcings for asset managers

March 19, 2025

Increased regulatory burdens on asset management businesses have resulted in additional cost pressures. However, regulation has also required more pricing transparency, which has led to an increasingly competitive market, with investors demanding either ultra-low cost or increasingly bespoke investment solutions.

Further DORA delegated acts published in OJ

February 27, 2025

On 20 February 2025, the following was published in the Official Journal of the EU (OJ).

ESAs provide a roadmap towards the designation of CTPPs under DORA

February 27, 2025

On 18 February 2025, the European Supervisory Authorities (ESAs) issued a roadmap to the designation of critical ICT third-party service providers (CTPPs) under the Digital Operational Resilience Act (DORA).

DORA delegated act published in OJ

February 27, 2025

On 13 February 2025, there was published in the Official Journal of the EU (OJ), Commission Delegated Regulation (EU) 2025/295 of 24 October 2024 supplementing the Regulation on digital operational resilience for the financial sector with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities.

DORA Delegated Regulation on TLPT

February 27, 2025

On 13 February 2025, the European Commission adopted a draft Delegated Regulation supplementing the Regulation on digital operational resilience for the financial sector with regard to regulatory technical standards