- Criteria for when ICT third-party providers may be designated as critical under DORA oversight.
References and citations
- RTS on due diligence, monitoring, audit/access rights, use of certifications/audit reports, and exit planning in contractual arrangements.
- RTS specifying elements to determine and assess when subcontracting ICT services supporting critical or important functions.
- Official announcement of critical ICT provider designations; useful for monitoring and updating critical provider status in third-party risk programs.
- ICT third-party risk strategy, register of information, oversight framework, and cooperation provisions (including linkages to NIS2 cooperation structures).