EBA - Amendments to its Guidelines on ICT and security risk management measures in the context of DORA application

EBA narrowed down the scope of its existing Guidelines on ICT and security risk management measures, due to the application of harmonised ICT risk management requirements under the Digital Operational Resilience Act (DORA) from 17 January 2025 In particular, the EBA has narrowed down:

- the entity scope of the Guidelines to only those that are covered by DORA, namely credit institutions, payment institutions, account information service providers, exempted payment institutions and exempted e-money institutions; and

- the scope of the Guidelines to the requirements on relationship management of the payment service users in relation to the provision of payment services