EU-DORA
Regulation (EU) 2022/2554 — Digital Operational Resilience Act
- Ch. I — General Provisions
- Art. 1. Subject matter (8)
- Art. 2. Scope (4)
- Art. 3. Definitions ref
- Art. 4. Proportionality principle (3)
- Ch. II — ICT Risk Management
- Art. 5. Governance and organisation (37)
- Art. 6. ICT risk management framework (23)
- Art. 7. ICT systems, protocols and tools (4)
- Art. 8. Identification (10)
- Art. 9. Protection and prevention (17)
- Art. 10. Detection (7)
- Art. 11. Response and recovery (23)
- Art. 12. Backup policies and procedures, restoration and recovery procedures and methods (19)
- Art. 13. Learning and evolving (16)
- Art. 14. Communication (4)
- Art. 15. Further harmonisation of ICT risk management tools, methods, processes and policies (10)
- Art. 16. Simplified ICT risk management framework (13)
- Ch. III — ICT-Related Incident Management, Classification and Reporting
- Art. 17. ICT-related incident management process (9)
- Art. 18. Classification of ICT-related incidents and cyber threats (7)
- Art. 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber threats (18)
- Art. 20. Harmonisation of reporting content and templates (7)
- Art. 21. Centralisation of reporting of major ICT-related incidents (9)
- Art. 22. Supervisory feedback (6)
- Art. 23. Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions (2)
- Ch. IV — Digital Operational Resilience Testing
- Art. 24. General requirements for the performance of digital operational resilience testing (8)
- Art. 25. Testing of ICT tools and systems (3)
- Art. 26. Advanced testing of ICT tools, systems and processes based on TLPT (14)
- Art. 27. Requirements for testers for the carrying out of TLPT (9)
- Ch. V — Managing ICT Third-Party Risk
- Art. 28. General principles (26)
- Art. 29. Preliminary assessment of ICT concentration risk at entity level (7)
- Art. 30. Key contractual provisions (24)
- Art. 31. Designation of critical ICT third-party service providers (16)
- Art. 32. Structure of the Oversight Framework (11)
- Art. 33. Tasks of the Lead Overseer (18)
- Art. 34. Operational coordination between Lead Overseers (4)
- Art. 35. Powers of the Lead Overseer (19)
- Art. 36. Exercise of the powers of the Lead Overseer outside the Union (15)
- Art. 37. Request for information (15)
- Art. 38. General investigations (10)
- Art. 39. Inspections (8)
- Art. 40. Ongoing oversight (7)
- Art. 41. Harmonisation of conditions enabling the conduct of the oversight activities (5)
- Art. 42. Follow-up by competent authorities (14)
- Art. 43. Oversight fees (3)
- Art. 44. International cooperation (2)
- Ch. VI — Information-Sharing Arrangements
- Art. 45. Information-sharing arrangements on cyber threat information and intelligence (3)
- Ch. VII — Competent Authorities
- Art. 46. Competent authorities (17)
- Art. 47. Cooperation with structures and authorities established by Directive (EU) 2022/2555 (7)
- Art. 48. Cooperation between authorities (2)
- Art. 49. Financial cross-sector exercises, communication and cooperation (5)
- Art. 50. Administrative penalties and remedial measures (14)
- Art. 51. Exercise of the power to impose administrative penalties and remedial measures (9)
- Art. 52. Criminal penalties (2)
- Art. 53. Notification duties (2)
- Art. 54. Publication of administrative penalties (8)
- Art. 55. Professional secrecy (4)
- Art. 56. Data Protection (3)
- Ch. VIII — Delegated Acts
- Art. 57. Exercise of the delegation (3)
- Ch. IX — Transitional and Final Provisions
- Art. 58. Review clause (7)
- Art. 59. Amendments to Regulation (EC) No 1060/2009 (5)
- Art. 60. Amendments to Regulation (EU) No 648/2012 (7)
- Art. 61. Amendments to Regulation (EU) No 909/2014 (6)
- Art. 62. Amendments to Regulation (EU) No 600/2014 (3)
- Art. 63. Amendment to Regulation (EU) 2016/1011 (4)
- Art. 64. Entry into force and application (1)
Chapter I — General Provisions
Chapter II — ICT Risk Management
Article 12. Backup policies and procedures, restoration and recovery procedures and methods
7 obligations
EU-DORA-12-13
Requirement
Ensure geographical distance of secondary processing site
The secondary processing site must be located at a geographical distance from the primary processing site to ensure that
EU-DORA-12-14
Requirement
Ensure secondary site can maintain continuity of critical functions
The secondary processing site must be capable of ensuring the continuity of critical or important functions identically
EU-DORA-12-15
Requirement
Ensure immediate accessibility of secondary processing site
The secondary processing site must be immediately accessible to the financial entity's staff to ensure continuity of cri
EU-DORA-12-16
Requirement
Determine recovery time and recovery point objectives based on function criticality
Financial entities must determine recovery time and recovery point objectives for each function, taking into account whe
EU-DORA-12-17
Requirement
Ensure time objectives meet agreed service levels in extreme scenarios
Recovery time objectives must ensure that, in extreme scenarios, the agreed service levels are met.
EU-DORA-12-18
Requirement
Perform necessary checks to ensure data integrity during recovery
When recovering from an ICT-related incident, financial entities must perform necessary checks, including any multiple c
EU-DORA-12-19
Requirement
Perform checks when reconstructing data from external stakeholders
Financial entities must perform checks when reconstructing data from external stakeholders, in order to ensure that all
Article 13. Learning and evolving
16 obligations
EU-DORA-13-01
Requirement
Establish Threat Intelligence Capabilities
Financial entities must establish and maintain capabilities and staff to gather information on vulnerabilities and cyber
EU-DORA-13-02
Requirement
Conduct Post-Incident Reviews After Major ICT Incidents
Financial entities must implement post ICT-related incident reviews after any major ICT-related incident that disrupts t
EU-DORA-13-03
Reporting
Report Post-Incident Review Changes to Authorities
Financial entities (except microenterprises) must communicate to competent authorities, upon request, the changes implem
EU-DORA-13-04
Requirement
Evaluate Response Promptness in Post-Incident Reviews
Post ICT-related incident reviews must determine whether established procedures were followed and actions were effective
EU-DORA-13-05
Requirement
Evaluate Forensic Analysis Quality in Post-Incident Reviews
Post ICT-related incident reviews must assess the quality and speed of performing forensic analysis, where deemed approp
EU-DORA-13-06
Requirement
Evaluate Internal Incident Escalation Effectiveness
Post ICT-related incident reviews must assess the effectiveness of incident escalation within the financial entity.
EU-DORA-13-07
Requirement
Evaluate Communication Effectiveness in Post-Incident Reviews
Post ICT-related incident reviews must assess the effectiveness of both internal and external communication during incid
EU-DORA-13-08
Risk Management
Incorporate Lessons into ICT Risk Assessment Process
Financial entities must continuously incorporate lessons derived from digital operational resilience testing (Articles 2
EU-DORA-13-09
Risk Management
Review ICT Risk Management Framework Components
Financial entities must use findings from lessons learned to form the basis for appropriate reviews of relevant componen
EU-DORA-13-10
Monitoring
Monitor Digital Operational Resilience Strategy Implementation
Financial entities must monitor the effectiveness of the implementation of their digital operational resilience strategy
EU-DORA-13-11
Monitoring
Map ICT Risk Evolution Over Time
Financial entities must map the evolution of ICT risk over time and analyze the frequency, types, magnitude and evolutio
EU-DORA-13-12
Reporting
Senior ICT Staff Annual Reporting to Management Body
Senior ICT staff must report at least yearly to the management body on the findings from lessons learned incorporation (
EU-DORA-13-13
Requirement
Develop ICT Security Awareness Programmes
Financial entities must develop ICT security awareness programmes and digital operational resilience training as compuls
EU-DORA-13-14
Requirement
Include Third-Party Service Providers in Training Schemes
Financial entities must, where appropriate, include ICT third-party service providers in their relevant training schemes
EU-DORA-13-15
Monitoring
Monitor Technological Developments Continuously
Financial entities (except microenterprises) must continuously monitor relevant technological developments to understand
EU-DORA-13-16
Requirement
Keep Updated with Latest ICT Risk Management Processes
Financial entities (except microenterprises) must keep up-to-date with the latest ICT risk management processes to effec
Article 14. Communication
2 obligations
EU-DORA-14-01
Documentation
Crisis Communication Plans for ICT Incidents
Financial entities must establish and maintain crisis communication plans that enable responsible disclosure of at least
EU-DORA-14-02
Documentation
Internal Staff Communication Policies
Financial entities must implement communication policies for internal staff as part of their ICT risk management framewo