Article 3: Definitions
DORA Art. 3, Chapter I
For the purposes of this Regulation, the following definitions shall apply: (1) ‘digital operational resilience’ means the ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to addres
2066 words in the official text.
Across the acts
- This provision citesNIS2
ancial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions; (2) ‘network and information system’ means a network and information system as defined in Article 6, point 1, of Directive (EU) 2022/2555; (3) ‘legacy ICT system’ means an ICT system that has reached the end of its lifecycle (end-of-life), that is not suitable for upgrades or fixes, for technological or commercial reasons, or is no longer supported by its supplier or by an ICT third-p
See it on the crossover map - This provision citesNIS2
n ICT third-party service provider, but that is still in use and supports the functions of the financial entity; (4) ‘security of network and information systems’ means security of network and information systems as defined in Article 6, point 2, of Directive (EU) 2022/2555; (5) ‘ICT risk’ means any reasonably identifiable circumstance in relation to the use of network and information systems which, if materialised, may compromise the security of the network and information systems, of any technology dependent tool or
See it on the crossover map
Sits inside (1)
Defines (65)
- digital operational resilience
- network and information system
- legacy ICT system
- security of network and information systems
- ICT risk
- information asset
- ICT asset
- ICT-related incident
- operational or security payment-related incident
- major ICT-related incident
- major operational or security payment-related incident
- cyber threat
- significant cyber threat
- cyber-attack
- threat intelligence
- vulnerability
- threat-led penetration testing (TLPT)
- ICT third-party risk
- ICT third-party service provider
- ICT intra-group service provider
- ICT services
- critical or important function
- critical ICT third-party service provider
- ICT third-party service provider established in a third country
- subsidiary
- group
- parent undertaking
- ICT subcontractor established in a third country
- ICT concentration risk
- management body
- credit institution
- institution exempted pursuant to Directive 2013/36/EU
- investment firm
- small and non-interconnected investment firm
- payment institution
- payment institution exempted pursuant to Directive (EU) 2015/2366
- account information service provider
- electronic money institution
- electronic money institution exempted pursuant to Directive 2009/110/EC
- central counterparty
- trade repository
- central securities depository
- trading venue
- manager of alternative investment funds
- management company
- data reporting service provider
- insurance undertaking
- reinsurance undertaking
- insurance intermediary
- ancillary insurance intermediary
- reinsurance intermediary
- institution for occupational retirement provision
- small institution for occupational retirement provision
- credit rating agency
- crypto-asset service provider
- issuer of asset-referenced tokens
- administrator of critical benchmarks
- crowdfunding service provider
- securitisation repository
- microenterprise
- Lead Overseer
- Joint Committee
- small enterprise
- medium-sized enterprise
- public authority
Recitals matched by wording (13)
- Recital 1
- Recital 2
- Recital 7
- Recital 12
- Recital 19
- Recital 22
- Recital 31
- Recital 35
- Recital 63
- Recital 67
- Recital 79
- Recital 102
- Recital 106
These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.
See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.