BETA


Events

2021/03/17
   EP - Committee draft report
Documents
2021/03/09
   PT_PARLIAMENT - Contribution
Documents
2021/02/22
   ES_PARLIAMENT - Contribution
Documents
2020/12/17
   EP - Committee referral announced in Parliament, 1st reading
2020/12/16
   CZ_CHAMBER - Contribution
Documents
2020/10/15
   EP - KELLEHER Billy (Renew) appointed as rapporteur in ECON
2020/09/24
   EC - Document attached to the procedure
2020/09/24
   EC - Document attached to the procedure
2020/09/24
   EC - Document attached to the procedure
2020/09/24
   EC - Legislative proposal published
Details

PURPOSE: to lay down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities with a view to achieving a high level of digital operational resilience for the financial sector.

PROPOSED ACT: Regulation of the European Parliament and of the Council.

ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council.

BACKGROUND: this proposal is part of the Digital Finance package, a package of measures to further enable and support the potential of digital finance in terms of innovation and competition while mitigating the risks. The digital finance package includes a new Strategy on digital finance for the EU financial sector with the aim to ensure that the Union’s financial services legislation is fit for the digital age, and contributes to a future-ready economy that works for the people, including by enabling the use of innovative technologies. The Union has a stated and confirmed policy interest in developing and promoting the uptake of transformative technologies in the financial sector, including blockchain and distributed ledger technology (DLT).

This package also includes a proposal for a pilot regime on distributed ledger technology market infrastructures, a proposal on crypto-asset markets, and a proposal to clarify or amend certain related EU financial services rules.

The use of digital, or Information and Communication Technologies (ICT) has in the last decades gained a pivotal role in finance, assuming today critical relevance in the operation of typical daily functions of all financial entities. Digitalisation covers, for instance, payments, which have increasingly moved from cash and paper-based methods to the use of digital solutions.

However, digital, or Information and Communication Technologies (ICT), gives rise to opportunities as well as risks. Risks include an increased threat to cyber attacks and ICT disruptions.

ICT risks pose challenges to the operational resilience, performance and stability of the EU financial system. The absence of detailed and comprehensive rules on digital operational resilience at EU level has led to the proliferation of national regulatory initiatives (e.g. on digital operational resilience testing) and supervisory approaches (e.g. addressing ICT third-party dependencies).

This situation fragments the single market, undermines the stability and integrity of the EU financial sector, and jeopardises the protection of consumers and investors.

It is therefore necessary to put in place a detailed and comprehensive framework on digital operational resilience for EU financial entities.

CONTENT: this proposal aims to put into place a comprehensive framework which shall enhance digital risk management. In particular, it seeks to strengthen and streamline the financial entities’ conduct of ICT risk management, establish a thorough testing of ICT systems, increase supervisors’ awareness of cyber risks and ICT-related incidents faced by financial entities, as well as introduce powers for financial supervisors to oversee risks stemming from financial entities’ dependency on ICT third-party service providers.

Scope of the Regulation

To ensure consistency around the ICT risk management requirements applicable to the financial sector, the proposed Regulation shall cover a range of financial entities regulated at Union level, namely inter alia: (i) credit institutions, (ii) payment institutions, (iii) electronic money institutions, (iv) investment firms, crypto-asset service providers, (v) central securities depositories, (vi) central counterparties, (vii) trading venues, (viii) trade repositories, (ix) credit rating agencies, (x) crowdfunding service providers.

Such a coverage facilitates a homogenous and coherent application of all components of the risk management on ICT-related areas, while safeguards the level playing field among financial entities in respect of their regulatory obligations on ICT risk.

Governance related requirements

As this proposed Regulation is designed to better aligning financial entities’ business strategies and the conduct of the ICT risk management, the management body shall be required to maintain a crucial, active role in steering the ICT risk management framework and shall pursue the respect of a string cyber hygiene.

ICT risk management requirements

Digital operational resilience is rooted in a set of key principles and requirements on ICT risk management framework, in line with the joint ESAs technical advice. These requirements, inspired from relevant international, national and industry-set standards, guidelines and recommendations, revolve around specific functions in ICT risk management (identification, protection and prevention, detection, response and recovery, learning and evolving and communication). To keep pace with a quickly evolving cyber threat landscape, financial entities are required to set-up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.

ICT-related incident reporting

The proposal shall create a consistent incident reporting mechanism that will help reduce administrative burdens for financial entities and strengthen supervisory effectiveness. The reporting shall be processed using a common template and following a harmonised procedure as developed by the ESAs.

Digital operational resilience testing

The capabilities and functions included in the ICT risk management framework need to be periodically tested for preparedness and identification of weaknesses, deficiencies or gaps, as well as the prompt implementation of corrective measures. This proposal allows for a proportionate application of digital operational resilience testing requirements depending on the size, business and risk profiles of financial entities.

Information sharing

To raise awareness on ICT risk, minimise its spread, support financial entities’ defensive capabilities and threat detection techniques, the proposed Regulation shall allow financial entities to set-up arrangements to exchange amongst themselves cyber threat information and intelligence. All voluntary information sharing arrangements between financial entities that this Regulation promotes would be conducted in trusted environments in full respect of Union data protection rules.

Budgetary implications

As the current Regulation foresees an enhanced role for the ESAs by means of powers granted upon them to adequately oversee critical ICT third-party providers, the proposal would entail the deployment of increased resources, in particular to fulfil the oversight missions (such as onsite and online inspections and audits exercises) and the use of staff possessing specific ICT security expertise.

The scale and distribution of these costs will depend on the extent of the new oversight powers and the (precise) tasks to be performed by the ESAs.

The estimated total cost impact is approximately EUR 30.19 million for the period 2022 - 2027. Therefore, no impact on EU budget appropriations is foreseen (except for the additional staff), as these costs will be fully funded by fees.

Documents

Activities

History

(these mark the time of scraping, not the official date of the change)

docs/4
date
2021-05-26T00:00:00
docs
title: PE693.603
type
Amendments tabled in committee
body
EP
events/1/body
EP
docs/0
date
2020-09-24T00:00:00
docs
summary
type
Legislative proposal
body
EC
docs/4
date
2021-03-09T00:00:00
docs
url: http://www.connefof.europarl.europa.eu/connefof/app/exp/COM(2020)0595 title: COM(2020)0595
type
Contribution
body
PT_PARLIAMENT
events/0
date
2020-09-24T00:00:00
type
Legislative proposal published
body
EC
docs
summary
procedure/title
Old
Digital operational resilience for the financial sector
New
Digital finance: Digital Operational Resilience Act (DORA)
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
docs/0
date
2020-09-24T00:00:00
docs
summary
type
Legislative proposal
body
EC
docs/3
date
2021-03-17T00:00:00
docs
url: https://www.europarl.europa.eu/sides/getDoc.do?type=COMPARL&mode=XML&language=EN&reference=PE689.801 title: PE689.801
type
Committee draft report
body
EP
docs/4
date
2021-03-17T00:00:00
docs
url: https://www.europarl.europa.eu/sides/getDoc.do?type=COMPARL&mode=XML&language=EN&reference=PE689.801 title: PE689.801
type
Committee draft report
body
EP
docs/4/docs/0/url
Old
https://www.europarl.europa.eu/sides/getDoc.do?type=COMPARL&mode=XML&language=EN&reference=PE689.801
New
https://www.europarl.europa.eu/doceo/document/ECON-PR-689801_EN.html
events/0
date
2020-12-17T00:00:00
type
Committee referral announced in Parliament, 1st reading
events/0
date
2020-09-24T00:00:00
type
Legislative proposal published
body
EC
docs
summary
events/1
date
2020-12-17T00:00:00
type
Committee referral announced in Parliament, 1st reading/single reading
body
EP
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
docs/3
date
2021-03-17T00:00:00
docs
url: https://www.europarl.europa.eu/sides/getDoc.do?type=COMPARL&mode=XML&language=EN&reference=PE689.801 title: PE689.801
type
Committee draft report
body
EP
committees/0/shadows/5
name
GUSMÃO José
group
GUE/NGL
abbr
Confederal Group of the European United Left
docs/4
date
2021-02-22T00:00:00
docs
url: http://www.connefof.europarl.europa.eu/connefof/app/exp/COM(2020)0595 title: COM(2020)0595
type
Contribution
body
ES_PARLIAMENT
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
docs/3
date
2020-12-16T00:00:00
docs
url: http://www.connefof.europarl.europa.eu/connefof/app/exp/COM(2020)0595 title: COM(2020)0595
type
Contribution
body
CZ_CHAMBER
events/1
date
2020-12-17T00:00:00
type
Committee referral announced in Parliament, 1st reading/single reading
body
EP
procedure/Legislative priorities
  • title: Joint Declaration 2021 url: https://oeil.secure.europarl.europa.eu/oeil/popups/thematicnote.do?id=2066000&l=en
procedure/dossier_of_the_committee
  • ECON/9/04230
procedure/stage_reached
Old
Preparatory phase in Parliament
New
Awaiting committee decision
commission
  • body: EC dg: Financial Stability, Financial Services and Capital Markets Union commissioner: MCGUINNESS Mairead
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
otherinst
  • name: European Economic and Social Committee
procedure/other_consulted_institutions
European Economic and Social Committee
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0
type
Responsible Committee
body
EP
committee_full
Economic and Monetary Affairs
committee
ECON
associated
False
rapporteur
name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
shadows
committees/0/shadows/2
name
RZOŃCA Bogdan
group
European Conservatives and Reformists Group
abbr
ECR
committees/2/opinion
False
committees/0/rapporteur
  • name: KELLEHER Billy date: 2020-10-15T00:00:00 group: Renew Europe group abbr: Renew
committees/0/shadows/0
name
FITZGERALD Frances
group
Group of European People's Party
abbr
EPP
committees/1/opinion
False
committees/0/shadows
  • name: KRAH Maximilian group: Identity and Democracy abbr: ID
docs/0
date
2020-09-24T00:00:00
docs
title: SEC(2020)0307
type
Document attached to the procedure
body
EC
docs/0
date
2020-09-24T00:00:00
docs
type
Legislative proposal
body
EC
docs/0/docs/0
url
https://eur-lex.europa.eu/smartapi/cgi/sga_doc?smartapi!celexplus!prod!DocNumber&lg=EN&type_doc=SECfinal&an_doc=2020&nu_doc=0307
title
EUR-Lex
docs/1
date
2020-09-24T00:00:00
docs
title: SEC(2020)0307
type
Document attached to the procedure
body
EC
events/0/summary
  • PURPOSE: to lay down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities with a view to achieving a high level of digital operational resilience for the financial sector.
  • PROPOSED ACT: Regulation of the European Parliament and of the Council.
  • ROLE OF THE EUROPEAN PARLIAMENT: the European Parliament decides in accordance with the ordinary legislative procedure and on an equal footing with the Council.
  • BACKGROUND: this proposal is part of the Digital Finance package, a package of measures to further enable and support the potential of digital finance in terms of innovation and competition while mitigating the risks. The digital finance package includes a new Strategy on digital finance for the EU financial sector with the aim to ensure that the Union’s financial services legislation is fit for the digital age, and contributes to a future-ready economy that works for the people, including by enabling the use of innovative technologies. The Union has a stated and confirmed policy interest in developing and promoting the uptake of transformative technologies in the financial sector, including blockchain and distributed ledger technology (DLT).
  • This package also includes a proposal for a pilot regime on distributed ledger technology market infrastructures, a proposal on crypto-asset markets, and a proposal to clarify or amend certain related EU financial services rules.
  • The use of digital, or Information and Communication Technologies (ICT) has in the last decades gained a pivotal role in finance, assuming today critical relevance in the operation of typical daily functions of all financial entities. Digitalisation covers, for instance, payments, which have increasingly moved from cash and paper-based methods to the use of digital solutions.
  • However, digital, or Information and Communication Technologies (ICT), gives rise to opportunities as well as risks. Risks include an increased threat to cyber attacks and ICT disruptions.
  • ICT risks pose challenges to the operational resilience, performance and stability of the EU financial system. The absence of detailed and comprehensive rules on digital operational resilience at EU level has led to the proliferation of national regulatory initiatives (e.g. on digital operational resilience testing) and supervisory approaches (e.g. addressing ICT third-party dependencies).
  • This situation fragments the single market, undermines the stability and integrity of the EU financial sector, and jeopardises the protection of consumers and investors.
  • It is therefore necessary to put in place a detailed and comprehensive framework on digital operational resilience for EU financial entities.
  • CONTENT: this proposal aims to put into place a comprehensive framework which shall enhance digital risk management. In particular, it seeks to strengthen and streamline the financial entities’ conduct of ICT risk management, establish a thorough testing of ICT systems, increase supervisors’ awareness of cyber risks and ICT-related incidents faced by financial entities, as well as introduce powers for financial supervisors to oversee risks stemming from financial entities’ dependency on ICT third-party service providers.
  • Scope of the Regulation
  • To ensure consistency around the ICT risk management requirements applicable to the financial sector, the proposed Regulation shall cover a range of financial entities regulated at Union level, namely inter alia: (i) credit institutions, (ii) payment institutions, (iii) electronic money institutions, (iv) investment firms, crypto-asset service providers, (v) central securities depositories, (vi) central counterparties, (vii) trading venues, (viii) trade repositories, (ix) credit rating agencies, (x) crowdfunding service providers.
  • Such a coverage facilitates a homogenous and coherent application of all components of the risk management on ICT-related areas, while safeguards the level playing field among financial entities in respect of their regulatory obligations on ICT risk.
  • Governance related requirements
  • As this proposed Regulation is designed to better aligning financial entities’ business strategies and the conduct of the ICT risk management, the management body shall be required to maintain a crucial, active role in steering the ICT risk management framework and shall pursue the respect of a string cyber hygiene.
  • ICT risk management requirements
  • Digital operational resilience is rooted in a set of key principles and requirements on ICT risk management framework, in line with the joint ESAs technical advice. These requirements, inspired from relevant international, national and industry-set standards, guidelines and recommendations, revolve around specific functions in ICT risk management (identification, protection and prevention, detection, response and recovery, learning and evolving and communication). To keep pace with a quickly evolving cyber threat landscape, financial entities are required to set-up and maintain resilient ICT systems and tools that minimize the impact of ICT risk.
  • ICT-related incident reporting
  • The proposal shall create a consistent incident reporting mechanism that will help reduce administrative burdens for financial entities and strengthen supervisory effectiveness. The reporting shall be processed using a common template and following a harmonised procedure as developed by the ESAs.
  • Digital operational resilience testing
  • The capabilities and functions included in the ICT risk management framework need to be periodically tested for preparedness and identification of weaknesses, deficiencies or gaps, as well as the prompt implementation of corrective measures. This proposal allows for a proportionate application of digital operational resilience testing requirements depending on the size, business and risk profiles of financial entities.
  • Information sharing
  • To raise awareness on ICT risk, minimise its spread, support financial entities’ defensive capabilities and threat detection techniques, the proposed Regulation shall allow financial entities to set-up arrangements to exchange amongst themselves cyber threat information and intelligence. All voluntary information sharing arrangements between financial entities that this Regulation promotes would be conducted in trusted environments in full respect of Union data protection rules.
  • Budgetary implications
  • As the current Regulation foresees an enhanced role for the ESAs by means of powers granted upon them to adequately oversee critical ICT third-party providers, the proposal would entail the deployment of increased resources, in particular to fulfil the oversight missions (such as onsite and online inspections and audits exercises) and the use of staff possessing specific ICT security expertise.
  • The scale and distribution of these costs will depend on the extent of the new oversight powers and the (precise) tasks to be performed by the ESAs.
  • The estimated total cost impact is approximately EUR 30.19 million for the period 2022 - 2027. Therefore, no impact on EU budget appropriations is foreseen (except for the additional staff), as these costs will be fully funded by fees.
docs/0/docs/1
url
https://eur-lex.europa.eu/smartapi/cgi/sga_doc?smartapi!celexplus!prod!DocNumber&lg=EN&type_doc=COMfinal&an_doc=2020&nu_doc=0595
title
EUR-Lex
events/0/docs/1
url
https://eur-lex.europa.eu/smartapi/cgi/sga_doc?smartapi!celexplus!prod!DocNumber&lg=EN&type_doc=COMfinal&an_doc=2020&nu_doc=0595
title
EUR-Lex