DORA outlines requirements for:
- ICT risk management;
- Incident reporting;
- Digital operational resilience testing;
- Information sharing; and
- Third-party risk management.
It also covers:
- Contractual arrangements between financial entities and ICT third-party service providers;
- An oversight framework for critical ICT third-party service providers; and
- Cooperation among supervisory authorities, and supervision/enforcement rules.
Additional technical details will be provided by the European supervisory authorities (EBA, EIOPA, ESMA). Until then, refer to the DORA regulation for comprehensive information on expected requirements.