Skip to main content
Triangular Patterns
MFSA Issues Two Circulars on ICT Risk DORAFinTechTelecoms, Media & Technology

MFSA Issues Two Circulars on ICT Risk

On the 16th of January 2025, the MFSA published a circular on the register of information-reporting-timelines for MFSA-authorised persons. Subsequently, on the 17th of January 2025, the MFSA published another circular outlining several resources uploaded to its website to assist compliance with Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (“DORA”). The circular issued on 16th of January 2025 focuses on the Register of Information required under Article 28(3) of DORA. This register mandates financial entities to document all contractual arrangements with ICT Third-Party Service Providers (“ICT TPPs”), ensuring transparency in…
Mamo TCV Advocates
20th January 2025
St James Cavalier Web Dome
DORA is Now in Force: What’s Next? DORAFinTechTelecoms, Media & Technology

DORA is Now in Force: What’s Next?

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (“DORA” or the “Act”) became enforceable as of 17th January 2025. DORA Resources As highlighted in various DORA insights by our Firm over the last few months (including a very useful overview of DORA itself), DORA represents a significant milestone in aligning the financial services sector with the EU’s digital finance strategy, offering a regulatory framework for operational resilience and ICT risk management. Designed to bolster operational resilience against increasingly sophisticated cyber threats, DORA ushers in a new era…
Key representing digital resilience
Status of DORA Regulatory Technical Standards (“RTS”) DORAFinTechTelecoms, Media & Technology

Status of DORA Regulatory Technical Standards (“RTS”)

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector ( “DORA”) establishes the EU legislative framework for enhancing digital resilience within the EU’s financial industry. Enforcement commences on 17th January 2025 and the EU Commission is tasked with issuing Regulatory Technical Standards (“RTS”) which supplement DORA. The EU Commission publishes the RTS in the Official Journal as Commission Delegated Regulations, but they are largely based on the input of the European Supervisory Authorities (“ESA”) which comprise of ESMA, EBA and EIOPA. The draft RTS submitted to the European…
Security Sign
Malta’s Draft Order Transposing the EU NIS 2 Directive Now Open for Public Consultation DORATelecoms, Media & Technology

Malta’s Draft Order Transposing the EU NIS 2 Directive Now Open for Public Consultation

The Ministry for Home Affairs, Security and Employment (MHSE) published the proposed Maltese draft order for the transposition of the EU Network and Information Systems Directive II (‘NIS 2’) on 6 September 2024. The draft order, titled ‘Measures For A High Common Level Of Cybersecurity Across The European Union (Malta) Order, 2024’ (the ‘Draft Order’) is currently open for public consultation until 7 October, seeking input for the effective implementation of the NIS 2 Directive in Malta, which must be transposed in national law by 17 October 2024. The Draft Order implements the NIS 2 Directive which significantly expands upon…
Mamo TCV Advocates
13th September 2024
Pier on Seashore in Malta
DORA: An Overview of the Maltese Legal Provisions Data Protection and PrivacyDORATelecoms, Media & Technology

DORA: An Overview of the Maltese Legal Provisions

On 16 July 2024, Legal Notice 166 of 2024 was published in Malta. This implemented the relevant provisions of DORA (full title being Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) 648/2012, (EU) 600/2014, (EU) No 909/2014 and (EU) 2016/1011) into Maltese law. The said provisions can now be found under the Malta Financial Services Authority Act (Digital Operational Resilience Act (DORA)) Regulations, 2024 (S.L. 330.20) – the ‘Maltese Regulations’. The Maltese Regulations shall come into force on…
Mamo TCV Advocates - DORA Services
Six Months Until DORA: Mamo TCV Advocates Launches Detailed Overview Banking & FinanceCapital MarketsDORAFinTechInsurance & Reinsurance

Six Months Until DORA: Mamo TCV Advocates Launches Detailed Overview

On the 17th of January 2025, the Digital Operational Resilience Act (DORA) will become applicable across the EU, including Malta. Maltese financial entities and ICT providers have 6 months to prepare for the new legal obligations that shall be imposed. In conjunction, on the 17th of January 2025, the Malta Financial Services Authority Act (Digital Operational Resilience Act (DORA)) Regulations, shall also come into force, further regulating the matter in Malta. We have recently launched our DORA microsite (www.doramalta.com) with easily understandable information which can serve as your reference point for available guidance. This document does not purport to give legal, financial…
Mamo TCV Advocates
17th July 2024