Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · dora-2022-2554-42

DORA artikel 42: Follow-up by competent authorities

Structural tree: the article's own paragraphs, verbatim.

CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOfficial source

What this page is
Agent, DORA artikel 42
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Rule tree

  1. If: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Within 60 calendar days of the receipt of the recommendations issued by the Lead Overseer pursuant to Article 35(1), point (d), critical ICT third-party service providers shall either notify the Lead Overseer of their intention to follow the recommendations or provide a reasoned explanation for not following such recommendations. The Lead Overseer shall immediately transmit this information to the competent author…

    Paragraph 1

  2. If: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. The Lead Overseer shall publicly disclose where a critical ICT third-party service provider fails to notify the Lead Overseer in accordance with paragraph 1 or where the explanation provided by the critical ICT third-party service provider is not deemed sufficient. The information published shall disclose the identity of the critical ICT third-party service provider as well as information on the type and nature of…

    Paragraph 2

  3. If: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    The Lead Overseer shall notify the ICT third-party service provider of that public disclosure.

    Paragraph 3

  4. If: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    3. Competent authorities shall inform the relevant financial entities of the risks identified in the recommendations addressed to critical ICT third-party service providers in accordance with Article 35(1), point (d).

    Paragraph 4

  5. If: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    When managing ICT third-party risk, financial entities shall take into account the risks referred to in the first subparagraph.

    Paragraph 5

  6. If: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    4. Where a competent authority deems that a financial entity fails to take into account or to sufficiently address within its management of ICT third-party risk the specific risks identified in the recommendations, it shall notify the financial entity of the possibility of a decision being taken, within 60 calendar days of the receipt of such notification, pursuant to paragraph 6, in the absence of appropriate contra…

    Paragraph 6

  7. If: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    5. Upon receiving the reports referred to in Article 35(1), point (c), and prior to taking a decision as referred to in paragraph 6 of this Article, competent authorities may, on a voluntary basis, consult the competent authorities designated or established in accordance with Directive (EU) 2022/2555 responsible for the supervision of an essential or important entity subject to that Directive, which has been designat…

    Paragraph 7

  8. If: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    6. Competent authorities may, as a measure of last resort, following the notification and, if appropriate, the consultation as set out in paragraph 4 and 5 of this Article, in accordance with Article 50, take a decision requiring financial entities to temporarily suspend, either in part or completely, the use or deployment of a service provided by the critical ICT third-party service provider until the risks identifi…

    Paragraph 8

  9. If: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    7. Where a critical ICT third-party service provider refuses to endorse recommendations, based on a divergent approach from the one advised by the Lead Overseer, and such a divergent approach may adversely impact a large number of financial entities, or a significant part of the financial sector, and individual warnings issued by competent authorities have not resulted in consistent approaches mitigating the potentia…

    Paragraph 9

  10. If: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    8. Upon receiving the reports referred to in Article 35(1), point (c), competent authorities, when taking a decision as referred to in paragraph 6 of this Article, shall take into account the type and magnitude of risk that is not addressed by the critical ICT third-party service provider, as well as the seriousness of the non-compliance, having regard to the following criteria:

    Paragraph 10

  11. If: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    (a)

    Paragraph 11

  12. If: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    the gravity and the duration of the non-compliance;

    Paragraph 12

  13. If: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    (b)

    Paragraph 13

  14. If: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    whether the non-compliance has revealed serious weaknesses in the critical ICT third-party service provider’s procedures, management systems, risk management and internal controls;

    Paragraph 14

If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

The article text as read

  1. 11. Within 60 calendar days of the receipt of the recommendations issued by the Lead Overseer pursuant to Article 35(1), point (d), critical ICT third-party service providers shall either notify the Lead Overseer of their intention to follow the recommendations or provide a reasoned explanation for not following such recommendations. The Lead Overseer shall immediately transmit this information to the competent authorities of the financial entities concerned.
  2. 22. The Lead Overseer shall publicly disclose where a critical ICT third-party service provider fails to notify the Lead Overseer in accordance with paragraph 1 or where the explanation provided by the critical ICT third-party service provider is not deemed sufficient. The information published shall disclose the identity of the critical ICT third-party service provider as well as information on the type and nature of the non-compliance. Such information shall be limited to what is relevant and proportionate for the purpose of ensuring public awareness, unless such publication would cause disproportionate damage to the parties involved or could seriously jeopardise the orderly functioning and integrity of financial markets or the stability of the whole or part of the financial system of the Union.
  3. 3The Lead Overseer shall notify the ICT third-party service provider of that public disclosure.
  4. 43. Competent authorities shall inform the relevant financial entities of the risks identified in the recommendations addressed to critical ICT third-party service providers in accordance with Article 35(1), point (d).
  5. 5When managing ICT third-party risk, financial entities shall take into account the risks referred to in the first subparagraph.
  6. 64. Where a competent authority deems that a financial entity fails to take into account or to sufficiently address within its management of ICT third-party risk the specific risks identified in the recommendations, it shall notify the financial entity of the possibility of a decision being taken, within 60 calendar days of the receipt of such notification, pursuant to paragraph 6, in the absence of appropriate contractual arrangements aiming to address such risks.
  7. 75. Upon receiving the reports referred to in Article 35(1), point (c), and prior to taking a decision as referred to in paragraph 6 of this Article, competent authorities may, on a voluntary basis, consult the competent authorities designated or established in accordance with Directive (EU) 2022/2555 responsible for the supervision of an essential or important entity subject to that Directive, which has been designated as a critical ICT third-party service provider.
  8. 86. Competent authorities may, as a measure of last resort, following the notification and, if appropriate, the consultation as set out in paragraph 4 and 5 of this Article, in accordance with Article 50, take a decision requiring financial entities to temporarily suspend, either in part or completely, the use or deployment of a service provided by the critical ICT third-party service provider until the risks identified in the recommendations addressed to critical ICT third-party service providers have been addressed. Where necessary, they may require financial entities to terminate, in part or completely, the relevant contractual arrangements concluded with the critical ICT third-party service providers.
  9. 97. Where a critical ICT third-party service provider refuses to endorse recommendations, based on a divergent approach from the one advised by the Lead Overseer, and such a divergent approach may adversely impact a large number of financial entities, or a significant part of the financial sector, and individual warnings issued by competent authorities have not resulted in consistent approaches mitigating the potential risk to financial stability, the Lead Overseer may, after consulting the Oversight Forum, issue non-binding and non-public opinions to competent authorities, in order to promote consistent and convergent supervisory follow-up measures, as appropriate.
  10. 108. Upon receiving the reports referred to in Article 35(1), point (c), competent authorities, when taking a decision as referred to in paragraph 6 of this Article, shall take into account the type and magnitude of risk that is not addressed by the critical ICT third-party service provider, as well as the seriousness of the non-compliance, having regard to the following criteria:
  11. 11(a)
  12. 12the gravity and the duration of the non-compliance;
  13. 13(b)
  14. 14whether the non-compliance has revealed serious weaknesses in the critical ICT third-party service provider’s procedures, management systems, risk management and internal controls;

Lineage

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article42
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-42/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:71b4830c97ed6b2a7a8e0ac0eaee8f50fe50010acfc7d17f0c237e600304cb9d
scriptsha256:a26050dc78efa4f2410a3e877e36b0927a10a7052e6f33415a03f0c7f953e810
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:9b26b06ac28b137627bd3decf4a9cfc6ffc91074c43ec84c032227ff4809fcf4
versionagent-engine-1+legal-2026-08-25 / 9b26b06ac28b1376

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32022R2554 art. 42, Follow-up by competent authorities. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-42 (hämtad 2026-08-18, bevis sha256:aea71f35b1692d4d, bygge legal-2026-08-25).