Compliance Library Blog Product Sign In

EU-DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

EU Version 1.0 606 obligations

Reporting Obligations

50

Chapter I — General Provisions

Article 1. Subject matter

2 obligations

Chapter II — ICT Risk Management

Article 5. Governance and organisation

4 obligations

Article 6. ICT risk management framework

1 obligation

Article 11. Response and recovery

2 obligations

Article 13. Learning and evolving

2 obligations

Article 16. Simplified ICT risk management framework

1 obligation

Chapter III — ICT-Related Incident Management, Classification and Reporting

Article 17. ICT-related incident management process

1 obligation

Article 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber threats

9 obligations

EU-DORA-19-01 Reporting

Report major ICT-related incidents to competent authority

Financial entities must report major ICT-related incidents to the relevant competent authority as specified in Article 4

EU-DORA-19-02 Reporting

Report major ICT incidents to ECB (significant credit institutions)

Credit institutions classified as significant must report major ICT-related incidents to the relevant national competent

EU-DORA-19-08 Reporting

Submit initial notification within prescribed time limits

Financial entities must submit an initial notification to the relevant competent authority within the time limits specif

EU-DORA-19-09 Reporting

Submit intermediate reports upon status changes

Financial entities must submit intermediate reports after the initial notification when the incident status changes sign

EU-DORA-19-10 Reporting

Submit final report after root cause analysis completion

Financial entities must submit a final report when root cause analysis is completed (regardless of mitigation implementa

EU-DORA-19-12 Reporting

Provide incident details to specified recipients timely

Competent authorities must timely provide details of major ICT-related incidents to EBA/ESMA/EIOPA, ECB, CSIRTs, resolut

EU-DORA-19-14 Reporting

Notify European System of Central Banks on payment system issues

The ECB must notify members of the European System of Central Banks on issues relevant to the payment system.

EU-DORA-19-16 Reporting

Urgently transmit CSD incident details to host Member State

Competent authorities must urgently transmit details of major ICT-related incidents to relevant authorities in host Memb

EU-DORA-19-18 Reporting

Immediately transmit reports to ECB (national authorities)

National competent authorities designated under Directive 2013/36/EU must immediately transmit major ICT-related inciden

Article 21. Centralisation of reporting of major ICT-related incidents

2 obligations

Article 22. Supervisory feedback

3 obligations

Chapter IV — Digital Operational Resilience Testing

Article 26. Advanced testing of ICT tools, systems and processes based on TLPT

2 obligations

Chapter V — Managing ICT Third-Party Risk

Article 28. General principles

1 obligation

Article 30. Key contractual provisions

1 obligation

Article 31. Designation of critical ICT third-party service providers

1 obligation

Article 32. Structure of the Oversight Framework

3 obligations

Article 35. Powers of the Lead Overseer

4 obligations

Article 42. Follow-up by competent authorities

1 obligation

Article 44. International cooperation

1 obligation

Chapter VI — Information-Sharing Arrangements

Article 45. Information-sharing arrangements on cyber threat information and intelligence

1 obligation

Chapter VII — Competent Authorities

Article 53. Notification duties

2 obligations

Chapter VIII — Delegated Acts

Article 57. Exercise of the delegation

2 obligations

Chapter IX — Transitional and Final Provisions

Article 58. Review clause

3 obligations

Article 61. Amendments to Regulation (EU) No 909/2014

1 obligation

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started