Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Recital 37
(37) Account information service providers, referred to in Article 33(1) of Payment Services Directive (PSD2), are explicitly included in the scope of this Regulation, taking into account the specific nature of their activities and the risks arising therefrom. In addition, electronic money institutions and payment institutions exempted pursuant to Article 9(1) of Electronic Money Directive (EMD2) of the European Parliament and of the Council and Article 32(1) of Payment Services Directive (PSD2) are included in the scope of this Regulation even if they have not been granted authorisation in accordance Electronic Money Directive (EMD2) to issue electronic money, or if they have not been granted authorisation in accordance with Payment Services Directive (PSD2) to provide and execute payment services. However, post office giro institutions, referred to in Article 2(5), point (3), of Capital Requirements Directive (CRD IV) of the European Parliament and of the Council , are excluded from the scope of this Regulation. The competent authority for payment institutions exempted pursuant to Payment Services Directive (PSD2), electronic money institutions exempted pursuant to Electronic Money Directive (EMD2) and account information service providers as referred to in Article 33(1) of Payment Services Directive (PSD2), should be the competent authority designated in accordance with Article 22 of Payment Services Directive (PSD2).