Compliance Library Blog Product Sign In

EU-DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

EU Version 1.0 606 obligations
Showing 51–75 of 606 obligations

Chapter I — General Provisions

Chapter II — ICT Risk Management

Article 12. Backup policies and procedures, restoration and recovery procedures and methods

7 obligations

Article 13. Learning and evolving

16 obligations

EU-DORA-13-01 Requirement

Establish Threat Intelligence Capabilities

Financial entities must establish and maintain capabilities and staff to gather information on vulnerabilities and cyber

EU-DORA-13-02 Requirement

Conduct Post-Incident Reviews After Major ICT Incidents

Financial entities must implement post ICT-related incident reviews after any major ICT-related incident that disrupts t

EU-DORA-13-03 Reporting

Report Post-Incident Review Changes to Authorities

Financial entities (except microenterprises) must communicate to competent authorities, upon request, the changes implem

EU-DORA-13-04 Requirement

Evaluate Response Promptness in Post-Incident Reviews

Post ICT-related incident reviews must determine whether established procedures were followed and actions were effective

EU-DORA-13-05 Requirement

Evaluate Forensic Analysis Quality in Post-Incident Reviews

Post ICT-related incident reviews must assess the quality and speed of performing forensic analysis, where deemed approp

EU-DORA-13-06 Requirement

Evaluate Internal Incident Escalation Effectiveness

Post ICT-related incident reviews must assess the effectiveness of incident escalation within the financial entity.

EU-DORA-13-07 Requirement

Evaluate Communication Effectiveness in Post-Incident Reviews

Post ICT-related incident reviews must assess the effectiveness of both internal and external communication during incid

EU-DORA-13-08 Risk Management

Incorporate Lessons into ICT Risk Assessment Process

Financial entities must continuously incorporate lessons derived from digital operational resilience testing (Articles 2

EU-DORA-13-09 Risk Management

Review ICT Risk Management Framework Components

Financial entities must use findings from lessons learned to form the basis for appropriate reviews of relevant componen

EU-DORA-13-10 Monitoring

Monitor Digital Operational Resilience Strategy Implementation

Financial entities must monitor the effectiveness of the implementation of their digital operational resilience strategy

EU-DORA-13-11 Monitoring

Map ICT Risk Evolution Over Time

Financial entities must map the evolution of ICT risk over time and analyze the frequency, types, magnitude and evolutio

EU-DORA-13-12 Reporting

Senior ICT Staff Annual Reporting to Management Body

Senior ICT staff must report at least yearly to the management body on the findings from lessons learned incorporation (

EU-DORA-13-13 Requirement

Develop ICT Security Awareness Programmes

Financial entities must develop ICT security awareness programmes and digital operational resilience training as compuls

EU-DORA-13-14 Requirement

Include Third-Party Service Providers in Training Schemes

Financial entities must, where appropriate, include ICT third-party service providers in their relevant training schemes

EU-DORA-13-15 Monitoring

Monitor Technological Developments Continuously

Financial entities (except microenterprises) must continuously monitor relevant technological developments to understand

EU-DORA-13-16 Requirement

Keep Updated with Latest ICT Risk Management Processes

Financial entities (except microenterprises) must keep up-to-date with the latest ICT risk management processes to effec

Article 14. Communication

2 obligations

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started