Source: OJ L, 2024/1502, 30.5.2024

Current language: DE

Artikel 4 Kritikalität oder Bedeutung der Funktionen


Summary What does Article 4 of the Criteria for designating critical service providers say?

This brief article addresses one specific criterion from the broader two-step designation framework established across this regulation.

Notably, as explained in Article 1, criterion (c) of Article 31(2) of DORA has no standalone "step 1" assessment — instead, it relies on the step 1 findings from the other criteria.

Article 4 therefore deals exclusively with the "step 2" assessment for that criterion, focusing on whether the ICT services provided by the third-party provider are of a critical nature to the activities of the financial entities they serve.

Important points:

  • The ESAs are required to assess whether the ICT services supporting critical or important functions of financial entities are themselves of a critical nature to those financial entities' activities.
  • This article applies only at step 2, with no independent step 1 threshold to meet — making it unique within this regulation's assessment framework.
  • The ESAs carry the obligation here, not the financial entities themselves.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Bei der Prüfung des in Artikel 31 Absatz 2 Buchstabe c der Verordnung (EU) 2022/2554 festgelegten Kriteriums führen die Europäischen Aufsichtsbehörden ihre Bewertung anhand des folgenden Unterkriteriums der „Stufe 2“ durch:

  1. Unterkriterium 3.1: Die letztlich vom selben IKT-Drittdienstleister erbrachten IKT-Dienstleistungen zur Unterstützung kritischer oder wichtiger Funktionen von Finanzunternehmen sind für die Tätigkeiten der Finanzunternehmen von kritischer Bedeutung.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod