Operational and systemic exposure arising from dependence on a single ICT third-party service provider or a small group of non-substitutable providers.
Defined in / by
Last updated: 22 August 2026.
What does "Concentration risk" mean under DORA?
Operational and systemic exposure arising from dependence on a single ICT third-party service provider or a small group of non-substitutable providers.
Last updated: 22 August 2026.
DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.
Checked