Source: OJ L, 2024/2956, 2.12.2024

Current language: EN

Article 1 Definitions


Summary What does Article 1 of the ITS on register of information say?

This is a definitions article, establishing the precise meaning of three key terms used throughout the regulation.

It lays the conceptual groundwork for understanding how ICT third-party relationships are structured and categorised, particularly in the context of maintaining the register of information required under DORA.

The three terms defined — direct ICT third-party service provider, ICT service supply chain, and rank — are foundational to the obligations set out in the subsequent articles.

Important points:

  • Understand that a "direct ICT third-party service provider" is the provider that has a contractual arrangement directly with the financial entity or with another entity on behalf of the group.
  • The "ICT service supply chain" captures the full sequence of contractual arrangements flowing from that direct provider down through any subcontractors.
  • "Rank" denotes where a given ICT third-party service provider sits within that supply chain, a concept that is operationalised further in Article 2.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

For the purposes of this Regulation, the following definitions apply:

  1. direct ICT third-party service provider’ means an ICT third-party service provider or ICT intra-group service provider that signed a contractual arrangement with:

    1. a financial entity to provide its ICT services directly to that financial entity;

    2. a financial or a non-financial entity to provide its services to other financial entities within the same group;

  2. ICT service supply chain’ means a sequence of contractual arrangements connected with the ICT service being provided by the direct ICT third-party service provider to the financial entity, starting with the direct ICT third-party service provider which has one or multiple other ICT third-party service providers as counterparties (subcontractors);

  3. rank’ means the position of an ICT third-party service provider in the ICT service supply chain.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod