ESMA has proposed more than 20 policy requirements under the Digital Operational Resilience Act (DORA), which entered into force on 16 January 2023 and will apply as of 17 January 2025. The document requires financial entities to strengthen their information and communication technology (ICT) security.
The requirements are set out in various instruments, including Regulatory Technical Standards (RTS), Implementing Technical Standards (ITS), and Commission Delegated Regulations (CDR). Specific articles address incident reporting and cooperation between European Supervisory Authorities (ESAs) and Competent Authorities (CAs).
The policy requirements apply to over 20 types of financial entities, with 12 under the remit of ESMA. These entities must review the new requirements and integrate them into their operational resilience strategies.
The material does not specify a deadline for compliance, but financial entities should prepare for incident notification and ensure their reporting frameworks align with the outlined standards.
Further details include provisions for ICT risk management, oversight of critical third-party providers, and incident reporting criteria, as outlined in DORA Articles 5-44.