Regulation
DORA
From legal text to evidence
The Digital Operational Resilience Act sets one ICT risk framework for the EU financial sector. It replaces a patchwork of supervisory expectations with binding rules on ICT risk management, incident classification and reporting, resilience testing, and the contracts behind third-party technology.
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011
- CELEX
- 32022R2554
- Official Journal
- OJ L 333, 27.12.2022, p. 1 to 79
- Articles
- 64
- Jurisdiction
- 🇪🇺 Europe
- Status
- In force
From the Official Journal to a tracked obligation
Three stages, and the legal text is not rewritten at any of them.
- 01
The article
The Official Journal text, transcribed word for word and checked against a hash of the source it came from. Nothing is paraphrased, and nothing is written from memory.
- 02
The clause
Each article becomes one clause in the catalogue, carrying its official heading, its citation and any deadline the text sets. This is the layer the platform reads, and it is shared across every tenant.
- 03
Your obligation
You adopt the clauses that apply to you, and each becomes a tracked obligation of your own: an owner, an applicability decision, a review date, and the evidence that it is being met.
Where an article sets a reporting clock, the deadline the Incident Centre counts down is computed from that clause and starts when the text says it starts, rather than from a duration typed into the product.
Key dates
Entry into force and the day the obligations start to bite are different dates, so each one is listed separately against the article that sets it.
14 Dec 2022
Adopted by the Parliament and the Council
27 Dec 2022
Published in the Official Journal
16 Jan 2023
Entered into force
Art. 64
17 Jan 2025
Applies from
Art. 64
The articles that create work
The obligation-bearing articles Pritect tracks, under the headings the Official Journal prints.
The regulation runs to 64 articles. Pritect decomposes 17 of them clause by clause into obligations you can adopt, own and evidence: the ICT risk management framework, the incident management, classification and reporting chain, and the key contractual provisions that govern ICT third-party arrangements. The rest are deliberately not decomposed, because they are not duties a financial entity discharges on its own account. Articles 1 to 4 set the subject matter, scope, definitions and the proportionality principle, Articles 14 to 16 cover communication, further harmonisation and the simplified framework for smaller entities, Articles 24 to 29 govern resilience testing and the wider third-party risk principles, and Articles 31 to 64 cover the oversight framework for critical ICT third-party service providers, information sharing, competent authorities, delegated acts and the final provisions. The set grows as the catalogue is extended.
ICT risk management
Chapter II, Art. 5 to 13
- Art. 5Governance and organisation
- Art. 6ICT risk management framework
- Art. 7ICT systems, protocols and tools
- Art. 8Identification
- Art. 9Protection and prevention
- Art. 10Detection
- Art. 11Response and recovery
- Art. 12Backup policies and procedures, restoration and recovery procedures and methods
- Art. 13Learning and evolving
Incident management, classification and reporting
Chapter III, Art. 17 to 23
- Art. 17ICT-related incident management process
- Art. 18Classification of ICT-related incidents and cyber threats
- Art. 19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
- Art. 20Harmonisation of reporting content and templates
- Art. 21Centralisation of reporting of major ICT-related incidents
- Art. 22Supervisory feedback
- Art. 23Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
ICT third-party risk
Chapter V, Art. 30
- Art. 30Key contractual provisions
Article headings are reproduced verbatim from the Official Journal and stay in English in every language, because a citation has to remain quotable. They are transcribed from the published text; the subject-matter review that makes them authoritative inside the product is still pending.
Where the work lives in Pritect
Each obligation lands in a suite that already does that job, on one shared record rather than a spreadsheet per article.
Common questions
The questions teams ask first, answered plainly.
- Who does DORA apply to?
- Article 2 lists the financial entities in scope, from credit institutions, payment and electronic money institutions and investment firms through to insurers, pension providers, crypto-asset service providers and central counterparties. It also reaches ICT third-party service providers designated as critical. Pritect records which limb of Article 2 places you in scope.
- What has to be reported, and when?
- Article 19 requires major ICT-related incidents to be reported to the competent authority, as an initial notification followed by intermediate and final reports, and allows voluntary notification of significant cyber threats. The classification test in Article 18 decides what counts as major, which is why Pritect classifies before it starts a clock.
- What is the register of information?
- Article 28 requires financial entities to maintain a register of all contractual arrangements on the use of ICT services provided by third-party service providers, kept at entity, sub-consolidated and consolidated level. Pritect keeps it as a live register tied to the contracts and suppliers it describes, rather than as an annual export.
- Do we have to run threat-led penetration testing?
- Articles 24 to 27 set the testing regime. Every entity in scope runs a digital operational resilience testing programme, and the subset identified by their competent authority additionally carries out threat-led penetration testing. Pritect records which regime applies and holds the results against the systems that were tested.
- How does DORA relate to NIS2?
- DORA is the more specific law for the financial sector: where it applies, its ICT risk management and incident reporting rules take the place of the equivalent NIS2 obligations, while NIS2 continues to govern the sectors DORA does not reach. Pritect maps a control once and reports it against both where an entity is caught by each.
This page summarises publicly available legal text so you can orient yourself. It is not legal advice.
See it against your own records
Bring one processing activity, one supplier and one open request. We will show you where each of them lands.