This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
Welcome to Reed Smith's viewpoints — timely commentary from our lawyers on topics relevant to your business and wider industry. Browse to see the latest news and subscribe to receive updates on topics that matter to you, directly to your mailbox.
| less than a minute read

DORA: Clarification on ICT services

The European Commission clarified whether EU financial entities can descope from DORA services received from financial entities, which include an ICT component.

Interpretation of the European Commission's response

If the services of a financial entity that would normally be considered an ICT service under DORA are a regulated financial service under the US, UK or EU laws (for example), such services should not be considered an ICT service under DORA. 

The logic to this clarification is based on the fact that such a service is already controlled by regulation elsewhere.

Having said that, the power of the determination is in the hands of the receiving financial entity.

Financial services may entail an ICT component. In the case that financial entities provide ICT services to other financial entities in connection to their financial services, the receiving financial entities should assess whether i) the services constitute an ICT service under DORA, and ii) whether the providing financial entities and the financial services they provide are regulated under Union law or any national legislation of a Member State or of a third country. In case both tests are positive, then the related ICT service should be considered to predominantly be a financial service and should not be treated as an ICT service within the meaning of DORA Article 3(21).


dora, financial services, cybersecurity, european commission, operational resilience, emerging technologies, fintech, supply chain