Skip to main content
DORARegulation (EU) 2022/2554

Article 18: Classification of ICT-related incidents and cyber threats

DORA Art. 18, Chapter III

1. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria: (a) the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact; (b) the duration of the ICT-re

482 words in the official text.

Sits inside (1)

Recitals matched by wording (1)

These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

DORA 32022R2554

Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.

See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.