On 31 October 2023, the Dutch Central Bank (De Nederlandsche Bank, DNB) published a news update on the readiness of market parties under its supervision for the applicability of the Digital Operational Resilience Act (Regulation (EU) 2022/2554, DORA).

DORA entered into force on 17 January 2023 and will be applicable as of 17 January 2025. DNB emphasises that despite the fact that the European supervisors are still to publish further details on certain requirements, market participants should start preparing for the implementation of DORA.

DNB lists a number of steps that market participants can take to ensure that they are ready for DORA in time:

  • Ensure that they are fully compliant with the current legal framework. The current Q&A and DNB Good Practice Information Security, as well as existing guidance from the EBA and EIOPA, can be used for this purpose.
  • Directors and members of the supervisory body should bring their knowledge related to ICT risk management up to a minimum level and keep it up to date.
  • The ICT-related policies, processes, procedures and IT roles can be evaluated.
  • A gap analysis can be prepared, together with an activity plan. The analysis and plan can be sharpened when further details are published by supervisors.
  • Engage with service providers on the upcoming tightening of regulatory requirements focused on contracting, risk assessment and monitoring. Service providers will also need to tighten their practices.
  • Making agreements with critical third parties on receiving adequate assurance reports for the entire critical outsourcing chain. It appears that in practice, current COS/SOC reports are not always adequate.

In addition, DNB announces that it will update its Good Practice on information security in light of DORA.

The news update is available here.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Nikolai de Koning Nikolai de Koning

Nikolai de Koning is a financial services lawyer (advocaat) based in Amsterdam. Nikolai is experienced in financial services and banking law, as well as in data privacy (protection). He is experienced in advising on regulatory and compliance aspects relevant to financial…

Nikolai de Koning is a financial services lawyer (advocaat) based in Amsterdam. Nikolai is experienced in financial services and banking law, as well as in data privacy (protection). He is experienced in advising on regulatory and compliance aspects relevant to financial institutions, such as insurance companies, investment firms, clearing institutions and central counterparties. Nikolai also advises on Dutch licence and notification requirements and he assists companies in their licence or notification processes with the Dutch financial regulators. He also specialises in privacy issues arising out of online products, data protection and e-commerce.

Photo of Julia van der Grint Julia van der Grint

Julia van der Grint is a financial services lawyer based in Amsterdam.

She advises clients on a wide range of regulatory and compliance aspects relevant to financial institutions, such as investment firms, trading platforms, payment institutions, insurers, fund managers and clearing and settlement…

Julia van der Grint is a financial services lawyer based in Amsterdam.

She advises clients on a wide range of regulatory and compliance aspects relevant to financial institutions, such as investment firms, trading platforms, payment institutions, insurers, fund managers and clearing and settlement institutions. Julia has developed particular knowledge of blockchain and cryptocurrencies, and advises crypto-asset services providers, crypto exchanges, payments providers and financial institutions on the regulatory issues related to the deployment of these technologies. She also advises on Dutch licence application and notification requirements and assists companies in their licence or notification processes with the Dutch Authority for Financial Markets and the Dutch Central Bank. Additionally, she assists companies in their contacts with these supervisory authorities and represents companies in enforcement procedures.

In addition, she has previously advised banks, other financial institutions and corporates in an array of transactions, both domestic and cross-border. This includes, among others, advising lenders and lender-groups in corporate restructurings and other insolvency related matters.

Prior to joining the team as an associate, Julia gained experience with the Amsterdam office as a student worker.