Regulation (EU) 2022/2554
DORA, whole
CELEX 32022R2554
The financial sector's own resilience law, written to sit inside NIS2 and to reach past the banks to the technology providers they depend on. The walk runs from governance to third-party oversight.
Assembling the DORA graph...
Every provision of DORA
The whole act as plain links, grouped as it is grouped. Each one opens that provision on its own page, with the official text, what it cites, what cites it and where it reaches another act.
Chapter IGeneral provisions
Chapter IIICT risk management
- Article 5Governance and organisation
- Article 6ICT risk management framework
- Article 7ICT systems, protocols and tools
- Article 8Identification
- Article 9Protection and prevention
- Article 10Detection
- Article 11Response and recovery
- Article 12Backup policies and procedures, restoration and recovery procedures and methods
- Article 13Learning and evolving
- Article 14Communication
- Article 15Further harmonisation of ICT risk management tools, methods, processes and policies
- Article 16Simplified ICT risk management framework
Chapter IIIICT-related incident management, classification and reporting
- Article 17ICT-related incident management process
- Article 18Classification of ICT-related incidents and cyber threats
- Article 19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
- Article 20Harmonisation of reporting content and templates
- Article 21Centralisation of reporting of major ICT-related incidents
- Article 22Supervisory feedback
- Article 23Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Chapter IVDigital operational resilience testing
Chapter VManaging of ICT third-party risk
- Article 28General principles
- Article 29Preliminary assessment of ICT concentration risk at entity level
- Article 30Key contractual provisions
- Article 31Designation of critical ICT third-party service providers
- Article 32Structure of the Oversight Framework
- Article 33Tasks of the Lead Overseer
- Article 34Operational coordination between Lead Overseers
- Article 35Powers of the Lead Overseer
- Article 36Exercise of the powers of the Lead Overseer outside the Union
- Article 37Request for information
- Article 38General investigations
- Article 39Inspections
- Article 40Ongoing oversight
- Article 41Harmonisation of conditions enabling the conduct of the oversight activities
- Article 42Follow-up by competent authorities
- Article 43Oversight fees
- Article 44International cooperation
Chapter VIInformation-sharing arrangements
Chapter VIICompetent authorities
- Article 46Competent authorities
- Article 47Cooperation with structures and authorities established by Directive (EU) 2022/2555
- Article 48Cooperation between authorities
- Article 49Financial cross-sector exercises, communication and cooperation
- Article 50Administrative penalties and remedial measures
- Article 51Exercise of the power to impose administrative penalties and remedial measures
- Article 52Criminal penalties
- Article 53Notification duties
- Article 54Publication of administrative penalties
- Article 55Professional secrecy
- Article 56Data Protection
Chapter VIIIDelegated acts
Chapter IXTransitional and final provisions
- Article 58Review clause
- Article 59Amendments to Regulation (EC) No 1060/2009
- Article 60Amendments to Regulation (EU) No 648/2012
- Article 61Amendments to Regulation (EU) No 909/2014
- Article 62Amendments to Regulation (EU) No 600/2014
- Article 63Amendment to Regulation (EU) 2016/1011
- Article 64Entry into force and application
Defined terms (65)
- digital operational resilience
- network and information system
- legacy ICT system
- security of network and information systems
- ICT risk
- information asset
- ICT asset
- ICT-related incident
- operational or security payment-related incident
- major ICT-related incident
- major operational or security payment-related incident
- cyber threat
- significant cyber threat
- cyber-attack
- threat intelligence
- vulnerability
- threat-led penetration testing (TLPT)
- ICT third-party risk
- ICT third-party service provider
- ICT intra-group service provider
- ICT services
- critical or important function
- critical ICT third-party service provider
- ICT third-party service provider established in a third country
- subsidiary
- group
- parent undertaking
- ICT subcontractor established in a third country
- ICT concentration risk
- management body
- credit institution
- institution exempted pursuant to Directive 2013/36/EU
- investment firm
- small and non-interconnected investment firm
- payment institution
- payment institution exempted pursuant to Directive (EU) 2015/2366
- account information service provider
- electronic money institution
- electronic money institution exempted pursuant to Directive 2009/110/EC
- central counterparty
- trade repository
- central securities depository
- trading venue
- manager of alternative investment funds
- management company
- data reporting service provider
- insurance undertaking
- reinsurance undertaking
- insurance intermediary
- ancillary insurance intermediary
- reinsurance intermediary
- institution for occupational retirement provision
- small institution for occupational retirement provision
- credit rating agency
- crypto-asset service provider
- issuer of asset-referenced tokens
- administrator of critical benchmarks
- crowdfunding service provider
- securitisation repository
- microenterprise
- Lead Overseer
- Joint Committee
- small enterprise
- medium-sized enterprise
- public authority
Recitals (106)
Source texts: the Official Journal, through the Publications Office. Study aid, not legal advice.
DORA and NIS2 cite each other more than any other pair on this map. Those sentences are at /tools/cross-compliance-graph/crossover.