Skip to main content

Digital Operational Resilience Act (DORA)

Does DORA apply to me?

If you fall under any of the below then DORA is most likely applicable to you, subject to certain exemptions:

ICT Service Providers – any undertaking that provides ICT systems and services to financial entities on an ongoing basis, including hardware as a service, as well as hardware services that incorporate technical support through means of software or firmware update.

Financial entities – this includes a vast range of entities, including:

  • Credit institutions
  • Account information service providers
  • Investment firms
  • AIFMS
  • Cryptoasset service providers
  • Payment institutions
  • Central securities depositories
  • Credit rating agencies
  • Data reporting service providers
  • Insurance and reinsurance undertakings
  • Insurance intermediaries

Is your organisation well prepared for DORA?

The ‘Digital Operational Resilience Act’ or DORA (Regulation (EU) 2022/2554) seeks to enhance and improve ICT operational risk requirements across various financial sectors. What was once a piecemeal approach scattered amongst various laws is now being consolidated into one singular EU regulation. It will become applicable as of 17th January 2025.

If you think that DORA is applicable to you please ask for our assistance

Mamo TCV Advocates - DORA Services

UNDERSTANDING DORA

DORA at a glance

The financial sector is increasingly dependent on technology and on tech companies to deliver financial services. This makes financial entities vulnerable to cyber-attacks or incidents.

When not managed properly, ICT risks can lead to disruptions of financial services offered across borders. This in turn, can have an impact on other companies, sectors and even on the rest of the economy, which underlines the importance of the digital operational resilience of the financial sector.

This is where the Digital Operational Resilience Act, or DORA, comes into play.

WHAT WE BELIEVE IN

How can we help?

Our Reputation

Mamo TCV Advocates is a leading Maltese law firm with years of experience in the field of technology law. With clients ranging from world-famous multinational IT companies to individual service providers we can provide your organisation practical advice regardless of the situation you are in.

DORA Compliance

Over the past years we have carried out several legal audits and training sessions for our diverse portfolio of clients and we are now assisting clients with their various new DORA-related legal obligations. From rules relating to direct marketing to data retention obligations, we have you covered.

What we Offer

  • Assistance with identifying applicability of DORA.
  • Negotiation, vetting and amending of contracts between key stakeholders to ensure DORA compliance.
  • Assistance with reporting obligations.
  • Provision of comprehensive expert legal advice to facilitate compliance.

Key Contacts

Claude Micallef Grimaud
Antoine Camilleri

Stay updated with our latest insights

Furthering MiCAR in Malta by Chapter 647
FinTech

Fintech Insights #8 –
Furthering MiCAR in Malta by Chapter 647

Chapter 647 of the Laws of Malta, titled the Markets In Crypto-Assets Act (hereinafter referred to as “Chapter 647”), integrates all aspects of Regulation (EU) 2023/1114 of the European Parliament and Council on markets in crypto-assets (“MiCAR”). MiCAR regulates the issuers of asset-referenced tokens (“ARTs”), electronic money tokens (“EMTs”), other types of tokens, as well as the conduct of crypto asset service providers (“CASPs”). Malta’s presidential assent to Chapter 647 was given on the 5th of November 2024 through  Act No. XXXVI of 2024 (“Act 36 (2024)”); and it was promulgated on the same day. Similar to MiCAR, Act 36…
AI in Banking
Banking & Finance

AI in the Banking Sector – a Sword, a Shield or an Achilles’ Heel?

1. Introduction We are not only living in a digital age but also in an age where individuals and businesses increasingly depend on banks for their day-to-day activities. The convergence of these two factors is compounded with the increased use of artificial intelligence (AI) both generally and specifically in the banking sector. From a general perspective, AI start-ups in 2013 received USD 2 bn in investments globally which increased twelvefold in 2018 to USD 24 bn . The European Commission is also planning to invest a total of €112 mm in AI, quantum research and innovation . More specifically, recent…
Insurance & Reinsurance

Regulatory Compliance Quarterly Update | Q3 2024

We are pleased to issue the tenth edition of the Regulatory Compliance Quarterly Updates. These updates are intended to keep Maltese regulated entities informed of regulatory changes and developments taking place in the local financial services space. In this issue, we focus on the sector specific and cross-sectoral regulatory updates relating to investment services, CSPs, fintech, insurance undertakings and insurance intermediaries. Our tenth Regulatory Compliance Quarterly Update can be found here .The Regulatory Compliance Quarterly Update does not purport to give legal, regulatory,financial or tax advice. Should you require further information or assistance, please do not hesitate to contact Michael…
EU AI Act series
Investment Services & Funds
AI in Investment Services: MIFID Considerations
AI Act’s Impact on Businesses Operating Within the EU
Telecoms, Media & Technology
The AI Act’s Impact on Businesses Operating Within the EU
The EU AI Act
Telecoms, Media & Technology
The EU AI Act: A General Overview

Get in touch if you require any assistance