Skip to main content
DORARegulation (EU) 2022/2554

Article 13: Learning and evolving

DORA Art. 13, Chapter II

1. Financial entities shall have in place capabilities and staff to gather information on vulnerabilities and cyber threats, ICT-related incidents, in particular cyber-attacks, and analyse the impact they are likely to have on their digital operational resilience. 2. Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activ

524 words in the official text.

Sits inside (1)

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

DORA 32022R2554

Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.

See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.

Useful to someone you work with?

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.