As you know, the European Parliament adopted Directive 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector and amending a number of EU Parliamentary Directives. This Directive comes into force on January 17, 2025 (“DORA”). This means that companies have little time to adapt to new requirements.
However, DORA requirements are not limited to this directive. The European Securities and Markets Authority (ESMA) is developing additional requirements as part of the application of DORA.
Who does DORA apply to?
The list of entities subject to DORA is extensive and includes companies that may already have implemented a number of information security measures. In general, it is important to pay attention to DORA requirements for the following companies:
Requirements for Crypto Companies
Crypto companies should take into account that the implementation period for legislation on crypto assets and crypto activities (MICA) is 6-18 months (depending on the jurisdiction), starting from January 1, 2025. However, DORA applies to crypto companies as of January 17, 2025. Therefore, crypto companies will not have additional time to implement DORA.
Policies, Procedures, Processes
Companies must develop more than 20 information security policies and procedures, including policies on access control, ICT incident management, ICT business continuity, ICT asset management, vulnerability and patch management, data and system security, etc. DORA requires a comprehensive ICT risk management framework that addresses ICT risks quickly, efficiently and comprehensively.
Regular Operational Sustainability Review
Testing should be done in a risk-based manner rather than in a standardized manner. Companies will test the risks that are most relevant to their services and lines of business. This will help tailor cyber risk controls to your individual business needs. In the event of a cyber attack, companies will be required to record the incident and report it to the relevant regulator.
Requirements for ICT Suppliers
The system will also require companies to assess the risks associated with third-party services. Time is limited and processes need to be carefully designed. Business partners with whom API integration or other partnerships are implemented will likely require appropriate policies and evidence that information security processes are implemented at the proper level.
Certain third party ICT providers will be considered “critical” and subject to direct regulatory oversight by the lead supervisory authority. ICT providers need to assess the impact of DORA and determine whether they can be considered “critical”.
If an ICT supplier is not deemed critical, it will still have to review its contracts to ensure compliance with the mandatory DORA requirements and make any necessary updates. Companies subject to DORA will require their ICT providers to meet a number of requirements.
Continuous Monitoring
Once DORA is implemented, it is necessary to continue to monitor and evaluate the risk management system. Regular reviews and updates will help maintain a high level of information security and operational resilience.
Where to begin?
If you are subject to DORA and need assistance adapting to new legal requirements before the implementation deadline, our experts are ready to assist you. We are already developing DORA policies and procedures for clients. If you are an ICT provider and want to understand how DORA will impact you, we can help you conduct a DORA impact assessment.
Companies must be prepared to implement DORA in order to avoid fines and sanctions and avoid the loss of business partners. Internal audits should be conducted to determine which processes and systems already comply with the new requirements and which require improvement. Make sure you have all the necessary policies and procedures in place and that employees are trained to follow them.