Skip to main content

DORA EU Legislation

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Digital and Operational Resilience Act’)
Regulatory Technical Standards
Regulatory Technical Standards (RTS) on ICT risk management framework and on simplified ICT risk management framework
RTS on criteria for the classification of ICT-related incidents
RTS to specify the policy on ICT services supporting critical or important functions provided by ICT third-party service providers (TPPs)
Implementing Technical Standards (ITS) to establish the templates for the register of information
RTS and ITS on the content, format, templates and timelines for reporting major ICT-related incidents and significant cyber threats
RTS on the harmonization of conditions enabling the conduct of the oversight activities
RTS specifying the criteria for determining the composition of the joint examination team (JET)
RTS on threat-led penetration testing (TLPT)
Joint Regulatory Technical Standards on subcontracting ICT services supporting critical or important functions

DORA Maltese Legislation

Malta Financial Services Authority Act (Digital Operational Resilience Act (DORA)) Regulations, 2024
Data Reporting Services (Amendment) Regulations, 2024

Stay updated with our latest insights

European Blockchain Sandbox
Telecoms, Media & Technology

European Blockchain Sandbox 3rd Cohort & Best Practices Webinar

The selection process for the third and final cohort of the European Blockchain Sandbox has been completed and the final twenty selected use cases have now been announced. Moreover, the European Blockchain Sandbox will soon be publishing the second cohort’s Best Practices Report which shall contain an overview of the regulatory best practices identified. The Report will be launched during a public webinar to be held on the 29th April 2025 at 14:00 CET, wherein the public is invited to ask any questions they may have regarding the Report. In conjunction, the award for the Most Innovative Regulator for the…
Rejected!
DORA

European Commission Rejects Draft Regulatory Technical Standards on ICT Subcontracting

The European Commission has communicated its rejection of the draft Regulatory Technical Standards (RTS) on subcontracting ICT services supporting critical or important functions supplementing the Digital Operational Resilience Act (DORA).  In its communication, the Commission held that the European Supervisory Authorities (ESAs) exceeded their mandate under Article 30(5) of DORA (which came into effect on 17 January 2025) by introducing requirements not specifically linked to the conditions for subcontracting in Article 5 of the RTS. The Commission has made it clear that Article 5 and the related recital 5 of the draft RTS must be omitted from the draft RTS…
EU AI Act
Telecoms, Media & Technology

EU AI Act: Banned AI Practices from 2 February 2025

The EU AI Act becomes applicable across the EU, including Malta, on 2 August, 2026 (you may read our general overview here). However, the AI Act’s general provisions and the provisions on prohibited AI practices that present an unacceptable level of risk, will come into force as early as 2 February 2025. With this deadline fast approaching, organisations subject to the AI Act must ensure compliance accordingly. AI Literacy By 2 February 2025, providers and deployers of AI systems, including those based in Malta, must take steps to guarantee an adequate level of AI literacy among their staff and any…
Triangular Patterns
DORA
MFSA Issues Two Circulars on ICT Risk
St James Cavalier Web Dome
DORA
DORA is Now in Force: What’s Next?
European Blockchain Sandbox
FinTech
European Blockchain Sandbox & MDIA Joint Webinar

Join our mailing list

Get in touch by sending us a message or by contacting us directly.