DORA
DORA Chapter V: ICT Third-Party Risk Management

DORA DORA-Art.31: Designation of critical ICT third-party service providers

The ESAs, through the Joint Committee, designate which ICT third-party service providers are critical, according to systemic impact, the importance of the institutions relying on them, reliance for critical or important functions and substitutability, and publish the list yearly; each designated provider gets a Lead Overseer and must tell the financial entities it serves of its designation. Designation does not cover financial entities that supply ICT services to other financial entities, providers under oversight supporting Article 127(2) TFEU tasks, intra-group providers, or providers serving only entities active in a single Member State (Art. 31(8)). For financial entities the duty is to track which of their providers are designated and reflect it in third-party risk management; a designated provider established in a third country may be used only if it has set up a Union subsidiary within 12 months of designation (Art. 31(12)).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 11 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 1 control

FedRAMP High · 1 control

  • SR-6 Supplier Assessments and Reviews (SR-6)

FedRAMP Moderate · 1 control

  • SR-6 Supplier Assessments and Reviews (SR-6)

ISO 27001:2022 · 1 control

  • 5.19 Information security in supplier relationships

ISO 27002:2022 · 1 control

  • 5.19 Information security in supplier relationships

NIS2 Directive · 1 control

  • Art.21.3 Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

SOC 2 · 1 control

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter V: ICT Third-Party Risk Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.31 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 11 it maps to, and the evidence behind each claim, over MCP and REST.