Compliance Library Blog Product Sign In

EU-DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

EU Version 1.0 606 obligations

Documentation Obligations

38

Chapter I — General Provisions

Chapter II — ICT Risk Management

Article 6. ICT risk management framework

1 obligation

Article 8. Identification

5 obligations

Article 9. Protection and prevention

3 obligations

Article 11. Response and recovery

2 obligations

Article 12. Backup policies and procedures, restoration and recovery procedures and methods

2 obligations

Article 14. Communication

3 obligations

Article 16. Simplified ICT risk management framework

1 obligation

Chapter III — ICT-Related Incident Management, Classification and Reporting

Article 17. ICT-related incident management process

1 obligation

Article 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber threats

1 obligation

Article 21. Centralisation of reporting of major ICT-related incidents

6 obligations

Chapter IV — Digital Operational Resilience Testing

Chapter V — Managing ICT Third-Party Risk

Article 28. General principles

4 obligations

Article 30. Key contractual provisions

3 obligations

Article 33. Tasks of the Lead Overseer

1 obligation

Article 34. Operational coordination between Lead Overseers

1 obligation

Article 36. Exercise of the powers of the Lead Overseer outside the Union

1 obligation

Article 38. General investigations

1 obligation

Article 39. Inspections

1 obligation

Chapter VI — Information-Sharing Arrangements

Chapter VII — Competent Authorities

Article 47. Cooperation with structures and authorities established by Directive (EU) 2022/2555

1 obligation

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started