Loading…
Loading…
DORA (Art. 15, 17, and 28) empowers the European Commission to adopt delegated regulations specifying the operational substance of three of its five pillars. The first batch — adopted as a package on 13 March 2024 — fills out the compliance obligations that financial entities must actually implement by 17 January 2025.
CDR 2024/1774 — ICT Risk Management Tools, Methods, Processes, and Policies (DORA Art. 15)
The most architecturally significant of the three. Specifies in mandatory technical detail:
a proportionality mechanism allowing reduced documentation burdens for entities below specified size thresholds; reduces the compliance barrier for smaller credit unions, payment firms, and asset managers while keeping the core resilience requirements
CDR 2024/1773 — ICT Third-Party Contractual Policy (DORA Art. 28)
Operationalises DORA's third-party risk pillar at the contract and policy level:
supporting critical or important functions (CIF) — not merely a checklist, but a board-approved strategic document
how concentration risk across providers is assessed, and exit/substitutability plans
portability, and termination triggers) must flow from this policy
financial entities must now meet detailed EU-mandated content standards
CDR 2024/1772 — ICT Incident Classification and Materiality Thresholds (DORA Art. 17)
Specifies the exact criteria for classifying an ICT incident as "major" — triggering the mandatory incident-reporting chain to supervisors:
duration of service disruption, geographical spread, economic impact
affected, duration in hours)
(contractual requirements) and the CTPP designation track (2025-11-18-eu-dora-ctpp- designation-article-31) creates a two-level oversight architecture: financial entities must impose Art. 30 contract terms on all CIF-supporting third parties, and the most systemic of those third parties (the 19 CTPPs) face direct ESA supervisory authority.
carves out a lighter-touch regime — but "simplified" still requires full risk identification, backup testing, and contractual policy. It is a scope reducer, not an exemption.
for what constitutes a notifiable event. Vendors of security/monitoring tools will need to calibrate detection outputs to these thresholds.
regime has already triggered re-negotiation waves in cloud/outsourcing agreements across EU financial entities through 2024-H2; most major hyperscalers had published DORA-aligned contract addenda by Q4 2024.
whether certain smaller crypto-asset service providers qualify requires regulatory guidance that was still being refined as of early 2025
national transposition differences across EU member states create residual ambiguity for financial entities also classified as essential/important entities under NIS2