The ESAs announce timeline to collect information for the designation of critical ICT third-party service providers under the Digital Operational Resilience Act
The European Supervisory Authorities (EBA, EIOPA, and ESMA) have published a decision on the information that competent authorities must report to them for the designation of critical ICT third-party service providers under the Digital Operational Resilience Act (DORA). The decision requires competent authorities to report the registers of information on contractual arrangements of financial entities with ICT third-party service providers by 30 April 2025. Following the entry into force of DORA on 17 January 2025, the ESAs will start overseeing critical ICT third-party service providers offering services to financial entities in the EU. The first oversight activity is the designation of critical ICT third-party service providers. The decision provides a general framework for the annual reporting of necessary information, including timelines, frequency, and reference dates. The ESAs expect competent authorities to collect the registers of information from financial entities under their supervision in advance. Although the implementing technical standards on the registers of information have not yet been adopted, the ESAs note that the essential part of the requirements is publicly available. The ESAs have shared draft templates, data point models, and reporting technical packages to support the industry's preparations and have carried out a voluntary dry run exercise on reporting of registers of information. The ESAs will publish an updated reporting technical package in December 2024 and will hold an information workshop on 18 December 2024 for financial entities to learn more about preparing their registers of information.