• About Us
  • List Your Firm
  • Legal Awards
  • Contact Us
Login | My Posts
Lawyers In Malta - Maltese Legal Portal
ADVERTISEMENT
  • Home
  • Law Firms
  • About Malta
    • Maltas Legal System
    • Economy Malta
    • Business in Malta
    • Live and do business in Malta
  • Publications
No Result
View All Result
  • Home
  • Law Firms
  • About Malta
    • Maltas Legal System
    • Economy Malta
    • Business in Malta
    • Live and do business in Malta
  • Publications
No Result
View All Result
Lawyers In Malta - Maltese Legal Portal
No Result
View All Result
Home Articles

DORA: the MFSA’s expectations in terms of minimum preparations

by Ganado Advocates
February 22, 2024
in Articles
Reading Time: 3 mins read
The MFSA’s expectations in terms of minimum preparations
Share on FacebookShare on TwitterShare on LinkedIn

By: Ganado Advocates 

The target date of 17 January 2025 has by now become synonymous with compliance by financial firms with Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector (“DORA” and the “Amending Directive”).

DORA applies to EU financial firms (the umbrella term “financial entities” is used), such as banks, insurance companies, payment and e-money institutions and investment firms and to third party service providers of ICT services which contract with these financial entities. DORA also captures providers of critical information to the financial services sector such as credit rating, critical benchmarking and data reporting services as well as financial market infrastructure providers such as central securities depositories, central counterparties and trading venues.[1]

Broadly, DORA consists of requirements in five main areas:

  • ICT risk management.
  • ICT incident reporting.
  • Digital operational resilience testing.
  • ICT third-party risk management.
  • Information intelligence and sharing.

On the 5 September 2023, the MFSA issued an update to its Circular on DORA and the Amending Directive which it had published in January 2023 (the “Circular Update”).[2] The MFSA reminds entities in scope that the obligations on financial entities in terms of the ICT-related areas outlined above “will change when compared to the obligations emanating from ICT-related provisions within the current applicable Acts, Regulations, Rules and/or sector-specific Guidelines.”

The Circular Update is one of the several and varied means through which the MFSA is keeping in touch with the industry in relation to this important regulatory compliance milestone. The MFSA expects the relevant entities to keep abreast with ongoing updates and highlights the following upcoming developments:

  • The Public Consultation on the national implementation of the Regulation and the national transposition of the Amending Directive, planned to be issued by the MFSA in Quarter 4, 2023.
  • The European Supervisory Authorities (ESAs) Joint Committee public consultation on the second set of Technical Standards.

Both consultations are intended for interested stakeholders to share their views with the MFSA and the ESAs as applicable.

In addition, in its Circular Update, the MFSA is taking the opportunity to emphasize what it considers to be the “minimum” in terms of level of preparations towards compliance with DORA. Amongst others, the MFSA expects that any relevant entity:

  • has duly informed Board and management and key function holders of requirements emanating from DORA;
  • keeps itself abreast with updates on the development of Technical Standards;
  • is duly aware of new reporting requirements and/or changes to existing reporting requirements as specified by DORA;
  • has duly discussed and planned for possible new compliance costs
  • has carried out a gap analysis between its present relevant strategies, policies, procedures, plans, systems, tools and the requirements of DORA;
  • has formally adopted a transition plan towards compliance with DORA; and
  • if applicable, has engaged in discussions with external auditors, consultants and ICT Third Party Service Providers.

A cursory look at the MFSA’s expectations above brings to light the role to be played by the Board and management of relevant entities to ensure through their respective role and functions that DORA compliance is on track. DORA compliance needs to be embedded in agendas, discussions and priorities. Although the 17 January 2025 may appear to be a long way off, awareness, preparedness, gap analysis and action plans are key.

___________

[1] https://ganado.com/news/countdown-to-dora-the-regulation-applies-from-17-january-2025/

[2] https://www.mfsa.mt/wp-content/uploads/2023/09/Update-and-Benchmarking-Exercise-on-Regulation-EU-2022-2554-on-Digital-Operational-Resilience.pdf

Supervisory ICT Risk and Cybersecurity Circulars

Author: Catherine Formosa (Senior Associate, Ganado Advocates)

Tags: Digital Transformation
Previous Post

Consumers’ right to withdraw from off-premises contracts already performed

Next Post

The General Court sheds light on the notion of ‘Detriment to a Trademark’s Reputation’

Next Post
Trademark’s Reputation

The General Court sheds light on the notion of ‘Detriment to a Trademark’s Reputation’

Find a Lawyer

List you Law firm

Want to be a part of our
Law Directory? 

Submit Interest

Popular Tags

AML/CFT regime Anti-money laundering Artificial Intelligence Aviation Blockchain Brexit Business Citizenship by Investment in Malta Commercial Contracts compet Consumer Protection corp Corporate Law Court of a appeal Covid 19 Debt Collection Digital Transformation Economy em Employment Law EU Family Law Financial Services GDPR Human Rights iGaming Malta Immigration Insurance Law Intellectual Property International Law Investments Litigation and Arbitration Malta MPRP Malta Permanent Residency Program Malta Permanent Residency Program (MPRP) Malta real estate Malta SDA real estate Public Contract Real estate in Malta Shipping and Maritime Malta Tax law Malta Trademarks Trusts Virtual Financial Assets Whistleblowing

A Premium Legal Portal Connecting Lawyers with Clients

Facebook Instagram Linkedin Xing

USEFUL LINKS

Contact Us
Terms & Conditions
Careers at Sedinvest
Advocates in Malta

USEFUL LINKS

Chamber of Advocates
Search for Lawyers in Malta
Why Lawyers in Malta
Malta Lawyers
Lawyers in Malta

NEWSLETTER

loader

Email Address*

© 2024 Lawyers in Malta. All Rights Reserved.

Developed by Wizzweb

No Result
View All Result
  • Law Firms
  • About Malta
    • Maltas Legal System
    • Economy Malta
    • Business in Malta
    • Live and do business in Malta
  • Publications
  • About Us
  • List Your Firm

© 2024 Lawyers in Malta - All rights Reserved.