The final report on the Regulatory Technical Standard (RTS) on Subcontracting introduces helpful guidance and addresses several key points raised by industry during the consultation period. However, certain provisions remain concerning. The scope of application continues to be overly broad, imposing all the requirements in the RTS on all information and communication technology (ICT) subcontractors that provide ICT services supporting critical or important functions, which risks unnecessary complexity. A more focused application of the requirements to subcontractors that effectively underpin the primary ICT service would allow for a more proportionate and risk-based approach to third-party risk management. Furthermore, the timeline for implementation is insufficient given the scale of changes required. The RTS introduces substantial new obligations that will necessitate updates to existing contractual and operational frameworks. To ensure smooth and effective compliance, a minimum implementation period of two years from the finalisation of the RTS is essential.
Recommendations for Regulatory Technical Standards on Subcontracting under the Digital Operational Resilience Act
Related items
:focal())
Strengthening connectivity through the Digital Networks Act
The Digital Networks Act (DNA) can help the EU build a more coherent connectivity framework for businesses operating across borders. Today, fragmented rules and complex compliance obligations continue to hold back innovation and Europe’s competitiveness.
To this end, the DNA must reduce – not add to – regulatory complexity, ensure legal certainty and avoid duplication with existing EU legislation. It should support investment in next-generation networks while avoiding duplication with existing EU frameworks. Clear scope will be essential to prevent unintended overlap with cloud, content delivery networks or private networks.
Read more on how the DNA can support Europe’s digital transition and long-term competitiveness.
:focal())
A year of giving back
Intel has called Ireland home since 1989, investing more than €30 billion and supporting 4,900 jobs. Alongside this long-term commitment, the company is helping strengthen local communities through its Signature Charity initiative. For the past 16 years, the Intel Foundation and Intel employees have selected a charity each year to support through volunteering and fundraising. In 2025, Intel Ireland chose Teach Tearmainn, the only organisation in County Kildare dedicated to supporting women and children experiencing domestic violence and abuse. Through fun runs, cycling events, a triathlon, a giving campaign, employee-led fundraising and recycling initiatives, Intel employees raised €80,000 for the charity – the company’s largest charity donation to date. These efforts show how long-term investment, employee engagement and community partnerships can help deliver meaningful support where it is needed most. Read the full story on Invested in Europe.
:focal())
Strengthening Europe’s cybersecurity framework through simplification
The review of the Cybersecurity Act (CSA 2.0) is an opportunity to build a more coherent, outcome-oriented EU cybersecurity framework. While the proposal recognises fragmentation across the Single Market, further simplification is needed to reduce overlaps and support effective compliance.
A harmonised approach to risk assessment and supervision can strengthen resilience while avoiding duplicative obligations. Certification and supply-chain measures should remain risk-based, objective, technical and aligned with international standards. Structured industry engagement and clear designation thresholds under the ICT Supply Chain Framework and a secure-by-design approach to policymaking will be essential to support cybersecurity and global interoperability. Read more on how CSA 2.0 can strengthen resilience across the Single Market.
Policy priorities
Insights and advocacy driving Europe’s policy agenda. Our priorities support growth, innovation and a stronger transatlantic economy.
Membership
Connecting business and policymakers to strengthen the voice of American companies in Europe.