Skip to content
IORP News
Menu
  • Home
  • Contact us
  • Subscribe
  • Newsroom
Menu

ESAs publish second batch of policy products under DORA

Posted on 17/07/2024 by IORP.EU

The three European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) published today the second batch of policy products under the Digital Operational Resilience Act (DORA). This batch consists of four final draft regulatory technical standards (RTS), one set of Implementing Technical Standards (ITS) and 2 guidelines, all of which aim at enhancing the digital operational resilience of the EU’s financial sector.

The package focuses on the reporting framework for ICT-related incidents (reporting clarity, templates) and threat-led penetration testing while also introducing some requirements on the design of the oversight framework, which enhance the digital operational resilience of the EU financial sector, thus also ensuring continuous and uninterrupted provision of financial services to customers and safety of their data.

The ESAs are publishing the following final draft technical standards:

  • RTS and ITS on the content, format, templates and timelines for reporting major ICT-related incidents and significant cyber threats;  
  • RTS on the harmonization of conditions enabling the conduct of the oversight activities;
  • RTS specifying the criteria for determining the composition of the joint examination team (JET); and
  • RTS on threat-led penetration testing (TLPT).

The set of guidelines include:

  • Guidelines on the estimation of aggregated costs/losses caused by major ICT-related incidents; and
  • Guidelines on oversight cooperation.

Go to the Policy Products

Next steps

The guidelines have already been adopted by the Boards of Supervisors of the three ESAs. The final draft technical standards have been submitted to the European Commission, which will now start working on their review with the objective to adopt these policy products in the coming months. The remaining RTS on Subcontracting will be published in due course.

Background 

The public consultation on all the above-mentioned technical standards and guidelines took place from 8 December 2023 to 4 March 2024. The ESAs received more than 364 responses from market participants (265 for the technical standards and 99 for the two guidelines), including a joint response from ESAs’ stakeholder groups. The RTS on JET has been consulted on separately from 18 April to 18 May and brought forward 9 responses from stakeholders. All these public consultations led to specific changes to the technical standards, ensuring simplification and streamlining of the requirements, greater proportionality and addressing sector-specific concerns.

As mandated by Article 20 of DORA the ESAs have consulted with the European Central Bank (ECB) and European Union Agency for Cybersecurity (ENISA) for the technical standards relating to incident reporting.

Subscribe
Notify of
guest
guest
0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Subscribe

Recent Posts

  • AEIP takes note of the European Commission’s Supplementary Pensions Package and calls for a proportionate, evidence-based approach to the IORP II review
  • EIOPA launches new set of consultations related to the Solvency II Review
  • EU Supervisory Authorities warn consumers of risks and limited protection for certain crypto-assets and providers
  • European supervisors tell financial institutions to stay alert to stability risks in uncertain and volatile times
  • EIOPA publishes factsheet on the asset allocation of occupational pension funds

Recent Comments

No comments to show.
https://www.novarca.com/

Archives

  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023

Categories

  • AEIP
  • EIOPA
  • NEWSROOM
  • Contact us
  • Newsroom
  • Privacy Policy
  • Subscribe
©2026 IORP News | Design: Newspaperly WordPress Theme
wpDiscuz