Updated 04/02/2025
In force since 16/01/2023

Initial Legal Act
Search for legal acts
Search within this legal act

Digital Operational Resilience Act (DORA)

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Text with EEA relevance)

Article 6 - ICT risk management framework RTSQ&AArticle 7 - ICT systems, protocols and tools Q&AArticle 8 - Identification Q&AArticle 9 - Protection and prevention RTSQ&AArticle 10 - Detection RTSQ&AArticle 11 - Response and recovery RTSQ&AGLArticle 12 - Backup policies and procedures, restoration and recovery procedures and methods Q&AArticle 13 - Learning and evolving Q&AArticle 14 - Communication RTSQ&AArticle 15 - Further harmonisation of ICT risk management tools, methods, processes and policies RTSQ&AArticle 16 - Simplified ICT risk management framework RTSQ&AGL
Article 17 - ICT-related incident management process Article 18 - Classification of ICT-related incidents and cyber threats RTSQ&AArticle 19 - Reporting of major ICT-related incidents and voluntary notification of significant cyber threats ITSRTSQ&AArticle 20 - Harmonisation of reporting content and templates ITSRTSArticle 21 - Centralisation of reporting of major ICT-related incidents Article 22 - Supervisory feedback Q&AArticle 23 - Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Article 31 - Designation of critical ICT third-party service providers RTSDAQ&AGLArticle 32 - Structure of the Oversight Framework Q&AGLArticle 33 - Tasks of the Lead Overseer Q&AArticle 34 - Operational coordination between Lead Overseers Q&AArticle 35 - Powers of the Lead Overseer RTSQ&AGLArticle 36 - Exercise of the powers of the Lead Overseer outside the Union Q&AGLArticle 37 - Request for information Q&AArticle 38 - General investigations Q&AGLArticle 39 - Inspections Q&AGLArticle 40 - Ongoing oversight RTSQ&AGLArticle 41 - Harmonisation of conditions enabling the conduct of the oversight activities RTSQ&AArticle 42 - Follow-up by competent authorities RTSQ&AGLArticle 43 - Oversight fees DAQ&AArticle 44 - International cooperation Q&A
Article 46 - Competent authorities Q&AArticle 47 - Cooperation with structures and authorities established by Directive (EU) 2022/2555Article 48 - Cooperation between authoritiesArticle 49 - Financial cross-sector exercises, communication and cooperation Q&AArticle 50 - Administrative penalties and remedial measuresArticle 51 - Exercise of the power to impose administrative penalties and remedial measuresArticle 52 - Criminal penaltiesArticle 53 - Notification dutiesArticle 54 - Publication of administrative penalties Q&AArticle 55 - Professional secrecyArticle 56 - Data Protection