Compliance Library Blog Product Sign In

EU-DORA

Regulation (EU) 2022/2554 — Digital Operational Resilience Act

EU Version 1.0 606 obligations

Transparency Obligations

50

Chapter I — General Provisions

Article 2. Scope

2 obligations

Chapter II — ICT Risk Management

Article 6. ICT risk management framework

1 obligation

Chapter III — ICT-Related Incident Management, Classification and Reporting

Article 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber threats

3 obligations

Article 20. Harmonisation of reporting content and templates

1 obligation

Article 22. Supervisory feedback

1 obligation

Chapter IV — Digital Operational Resilience Testing

Chapter V — Managing ICT Third-Party Risk

Article 28. General principles

2 obligations

Article 30. Key contractual provisions

2 obligations

Article 31. Designation of critical ICT third-party service providers

6 obligations

Article 32. Structure of the Oversight Framework

1 obligation

Article 33. Tasks of the Lead Overseer

2 obligations

Article 35. Powers of the Lead Overseer

3 obligations

Article 37. Request for information

1 obligation

Article 38. General investigations

8 obligations

EU-DORA-38-02 Transparency

Provide records, data, procedures and materials for examination

Critical ICT third-party service providers must provide access to and allow examination of records, data, procedures and

EU-DORA-38-03 Transparency

Allow copying and extraction of materials

Critical ICT third-party service providers must allow the Lead Overseer to take or obtain certified copies of, or extrac

EU-DORA-38-04 Transparency

Respond to summons for explanations

Representatives of critical ICT third-party service providers must respond to summons for oral or written explanations o

EU-DORA-38-05 Transparency

Provide telephone and data traffic records upon request

Critical ICT third-party service providers must provide records of telephone and data traffic when requested by the Lead

EU-DORA-38-06 Transparency

Inform competent authorities before investigation start

The Lead Overseer must inform competent authorities of financial entities using the ICT services of the critical ICT thi

EU-DORA-38-07 Transparency

Communicate investigation information to JON

The Lead Overseer must communicate to the Joint Oversight Network (JON) all information transmitted to competent authori

EU-DORA-38-09 Transparency

Include penalty information in investigation authorization

The written authorization for investigations must indicate the periodic penalty payments provided for in Article 35(6) f

EU-DORA-38-10 Transparency

Include legal remedies and review rights in investigation decision

The Lead Overseer's investigation decision must specify the subject matter, purpose, penalty payments under Article 35(6

Article 39. Inspections

2 obligations

Article 42. Follow-up by competent authorities

7 obligations

Chapter VI — Information-Sharing Arrangements

Chapter VII — Competent Authorities

Article 47. Cooperation with structures and authorities established by Directive (EU) 2022/2555

2 obligations

Article 48. Cooperation between authorities

1 obligation

Article 54. Publication of administrative penalties

4 obligations

Chapter VIII — Delegated Acts

Chapter IX — Transitional and Final Provisions

Article 61. Amendments to Regulation (EU) No 909/2014

1 obligation

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started