Skip to main content
    Pritect

    Regulation

    DORA
    From legal text to evidence

    The Digital Operational Resilience Act sets one ICT risk framework for the EU financial sector. It replaces a patchwork of supervisory expectations with binding rules on ICT risk management, incident classification and reporting, resilience testing, and the contracts behind third-party technology.

    Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011

    CELEX
    32022R2554
    Official Journal
    OJ L 333, 27.12.2022, p. 1 to 79
    Articles
    64
    Jurisdiction
    🇪🇺 Europe
    Status
    In force
    Read the text on EUR-Lex

    From the Official Journal to a tracked obligation

    Three stages, and the legal text is not rewritten at any of them.

    1. 01

      The article

      The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.

    2. 02

      The clause

      Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.

    3. 03

      Your obligation

      You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.

    Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.

    Key dates

    Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.

    1. 14 Dec 2022

      Adopted by the Parliament and the Council

    2. 27 Dec 2022

      Published in the Official Journal

    3. 16 Jan 2023

      Entered into force

      Art. 64

    4. 17 Jan 2025

      Applies from

      Art. 64

    The articles that create work

    The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.

    64
    Articles
    17
    Tracked

    The regulation runs to 64 articles. Pritect decomposes 17 of them clause by clause into obligations you can adopt, own and evidence: the ICT risk management framework, the incident management, classification and reporting chain, and the key contractual provisions that govern ICT third-party arrangements. The rest are deliberately not decomposed, because they are not duties a financial entity discharges on its own account. Articles 1 to 4 set the subject matter, scope, definitions and the proportionality principle, Articles 14 to 16 cover communication, further harmonisation and the simplified framework for smaller entities, Articles 24 to 29 govern resilience testing and the wider third-party risk principles, and Articles 31 to 64 cover the oversight framework for critical ICT third-party service providers, information sharing, competent authorities, delegated acts and the final provisions. The set grows as the catalogue is extended.

    ICT risk management

    Chapter II, Art. 5 to 13

    • Art. 5Governance and organisation
    • Art. 6ICT risk management framework
    • Art. 7ICT systems, protocols and tools
    • Art. 8Identification
    • Art. 9Protection and prevention
    • Art. 10Detection
    • Art. 11Response and recovery
    • Art. 12Backup policies and procedures, restoration and recovery procedures and methods
    • Art. 13Learning and evolving

    Incident management, classification and reporting

    Chapter III, Art. 17 to 23

    • Art. 17ICT-related incident management process
    • Art. 18Classification of ICT-related incidents and cyber threats
    • Art. 19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
    • Art. 20Harmonisation of reporting content and templates
    • Art. 21Centralisation of reporting of major ICT-related incidents
    • Art. 22Supervisory feedback
    • Art. 23Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions

    ICT third-party risk

    Chapter V, Art. 30

    • Art. 30Key contractual provisions

    Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.

    Common questions

    The questions teams ask first, answered plainly.

    Who does DORA apply to?
    Article 2 lists the financial entities in scope, from credit institutions, payment and electronic money institutions and investment firms through to insurers, pension providers, crypto-asset service providers and central counterparties. It also reaches ICT third-party service providers designated as critical. Pritect records which limb of Article 2 places you in scope.
    What has to be reported, and when?
    Article 19 requires major ICT-related incidents to be reported to the competent authority, as an initial notification followed by intermediate and final reports, and allows voluntary notification of significant cyber threats. The classification test in Article 18 decides what counts as major, which is why Pritect classifies before it starts a clock.
    What is the register of information?
    Article 28 requires financial entities to maintain a register of all contractual arrangements on the use of ICT services provided by third-party service providers, kept at entity, sub-consolidated and consolidated level. Pritect keeps it as a live register tied to the contracts and suppliers it describes, rather than as an annual export.
    Do we have to run threat-led penetration testing?
    Articles 24 to 27 set the testing regime. Every entity in scope runs a digital operational resilience testing programme, and the subset identified by their competent authority additionally carries out threat-led penetration testing. Pritect records which regime applies and holds the results against the systems that were tested.
    How does DORA relate to NIS2?
    DORA is the more specific law for the financial sector: where it applies, its ICT risk management and incident reporting rules take the place of the equivalent NIS2 obligations, while NIS2 continues to govern the sectors DORA does not reach. Pritect maps a control once and reports it against both where an entity is caught by each.

    This page summarises publicly available legal text so you can orient yourself. It is not legal advice.

    See it against your own records

    Bring one processing activity, one supplier and one open request. We will show you where each of them lands.