Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Chapter VII – Competent authorities
Article 46
Competent authorities
Without prejudice to the provisions on the Oversight Framework for critical ICT third-party service providers referred to in Chapter V, Section II, of this Regulation, compliance with this Regulation shall be ensured by the following competent authorities in accordance with the powers granted by the respective legal acts:
(a) for credit institutions and for institutions exempted pursuant to Capital Requirements Directive (CRD IV), the competent authority designated in accordance with Article 4 of that Directive, and for credit institutions classified as significant in accordance with Article 6(4) of Single Supervisory Mechanism Regulation (SSMR), the ECB in accordance with the powers and tasks conferred by that Regulation;
(b) for payment institutions, including payment institutions exempted pursuant to Payment Services Directive (PSD2), electronic money institutions, including those exempted pursuant to Electronic Money Directive (EMD2), and account information service providers as referred to in Article 33(1) of Payment Services Directive (PSD2), the competent authority designated in accordance with Article 22 of Payment Services Directive (PSD2);
(c) for investment firms, the competent authority designated in accordance with Article 4 of Directive (EU) 2019/2034 of the European Parliament and of the Council ;
(d) for crypto-asset service providers as authorised under the Regulation on markets in crypto-assets and issuers of asset-referenced tokens, the competent authority designated in accordance with the relevant provision of that Regulation;
(e) for central securities depositories, the competent authority designated in accordance with Article 11 of Central Securities Depositories Regulation (CSDR);
(f) for central counterparties, the competent authority designated in accordance with Article 22 of European Market Infrastructure Regulation (EMIR);
(g) for trading venues and data reporting service providers, the competent authority designated in accordance with Article 67 of Markets in Financial Instruments Directive (MiFID II), and the competent authority as defined in Article 2(1), point (18), of Markets in Financial Instruments Regulation (MiFIR);
(h) for trade repositories, the competent authority designated in accordance with Article 22 of European Market Infrastructure Regulation (EMIR);
(i) for managers of alternative investment funds, the competent authority designated in accordance with Article 44 of Alternative Investment Fund Managers Directive (AIFMD);
(j) for management companies, the competent authority designated in accordance with Article 97 of UCITS Directive (Investment Funds);
(k) for insurance and reinsurance undertakings, the competent authority designated in accordance with Article 30 of Solvency II Directive (Insurance);
(l) for insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries, the competent authority designated in accordance with Article 12 of Insurance Distribution Directive (IDD);
(m) for institutions for occupational retirement provision, the competent authority designated in accordance with Article 47 of IORP II Directive (Occupational Pensions);
(n) for credit rating agencies, the competent authority designated in accordance with Article 21 of Credit Rating Agencies Regulation (CRA Reg);
(o) for administrators of critical benchmarks, the competent authority designated in accordance with Articles 40 and 41 of Benchmarks Regulation (BMR);
(p) for crowdfunding service providers, the competent authority designated in accordance with Article 29 of Regulation (EU) 2020/1503;
(q) for securitisation repositories, the competent authority designated in accordance with Articles 10 and 14(1) of Regulation (EU) 2017/2402.