INFORMATION TECHNOLOGY
Legislative Decree no. 23 of 10 March 2025, which coordinates national legislation with the provisions of Regulation (EU) 2022/2554 DORA, has been published in the Official Gazette.
On 11 March 2025, Legislative Decree no. 23 of 10 March 2025 was published in the Official Gazette no. 58, which coordinates national legislation with the provisions of Regulation (EU) 2022/2554, known as the Digital Operational Resilience Act (DORA), which aims to strengthen the digital operational resilience of the banking, financial and insurance sector through a homogeneous regulatory framework in the European Union.
The decree - in force and applicable from 12 March 2025 - is divided into several key provisions, including:
The decree identifies the Bank of Italy, the National Commission for Society and the Stock Exchange (Consob), the Institute for the Supervision of Insurance (IVASS) and the Pension Funds Supervisory Commission (COVIP) as the competent authorities for compliance with the obligations imposed by the DORA Regulation on the entities supervised by the same authorities, according to their respective supervisory powers (hereinafter, collectively, the "DORA Supervisory Authorities"). In addition, the Bank of Italy is the competent authority for compliance with the obligations imposed by the DORA Regulation on Cassa depositi e prestiti S.p.A., financial intermediaries and Bancoposta. The Commissione Nazionale per le Società e la Borsa (CONSOB) is the DORA competent authority for investment firms and financial markets, the Institute for the Supervision of Insurance (IVASS) is the DORA competent authority for insurance and reinsurance companies and COVIP is the competent authority for pension institutions.
The decree - in force and applicable from 12 March 2025 - is divided into several key provisions, including:
- Identification of competent authorities: National authorities responsible for supervising financial entities on digital operational resilience are designated.
- Allocation of supervisory and investigative powers: The powers conferred on the authorities to ensure compliance with the DORA Regulation are specified.
- Sanctioning system: the sanctioning system for violations of the provisions of the DORA Regulation is outlined;
- Integration with reference to the obligations of the DORA Regulation of various regulations in the banking, financial and insurance sectors.
The decree identifies the Bank of Italy, the National Commission for Society and the Stock Exchange (Consob), the Institute for the Supervision of Insurance (IVASS) and the Pension Funds Supervisory Commission (COVIP) as the competent authorities for compliance with the obligations imposed by the DORA Regulation on the entities supervised by the same authorities, according to their respective supervisory powers (hereinafter, collectively, the "DORA Supervisory Authorities"). In addition, the Bank of Italy is the competent authority for compliance with the obligations imposed by the DORA Regulation on Cassa depositi e prestiti S.p.A., financial intermediaries and Bancoposta. The Commissione Nazionale per le Società e la Borsa (CONSOB) is the DORA competent authority for investment firms and financial markets, the Institute for the Supervision of Insurance (IVASS) is the DORA competent authority for insurance and reinsurance companies and COVIP is the competent authority for pension institutions.