Skip to main content
DORARegulation (EU) 2022/2554

Article 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats

DORA Art. 19, Chapter III

1. Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 in accordance with paragraph 4 of this Article. Where a financial entity is subject to supervision by more than one national competent authority referred to in Article 46, Member States shall designate a single competent authority as the relevant competent authority respo

1081 words in the official text.

Across the acts

  • This provision citesNIS2

    Without prejudice to the reporting pursuant to the first subparagraph by the financial entity to the relevant competent authority, Member States may additionally determine that some or all financial entities shall also provide the initial notification and each report referred to in paragraph 4 of this Article using the templates referred to in Article 20 to the competent authorities or the computer security incident response teams (CSIRTs) designated or established in accordance with Directive (EU) 2022/2555.

    See it on the crossover map
  • This provision citesNIS2

    Member States may determine that those financial entities that on a voluntary basis notify in accordance with the first subparagraph may also transmit that notification to the CSIRTs designated or established in accordance with Directive (EU) 2022/2555.

    See it on the crossover map
  • This provision citesNIS2Article 3

    competences: (a) EBA, ESMA or EIOPA; (b) the ECB, in the case of financial entities referred to in Article 2(1), points (a), (b) and (d); (c) the competent authorities, single points of contact or CSIRTs designated or established in accordance with Directive (EU) 2022/2555; (d) the resolution authorities, as referred to in Article 3 of Directive 2014/59/EU, and the Single Resolution Board (SRB) with respect to entities referred to in Article 7(2) of Regulation (EU) No 806/2014 of the European Parliament and of the Cou

    See it on the crossover map

Sits inside (1)

Recitals matched by wording (2)

These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.

Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.

DORA 32022R2554

Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.

See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.