Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I — General provisions
Chapter II — ICT risk management
Art. 5 — Governance and organisationArt. 6 — ICT risk management frameworkArt. 7 — ICT systems, protocols and toolsArt. 8 — IdentificationArt. 9 — Protection and preventionArt. 10 — DetectionArt. 11 — Response and recoveryArt. 12 — Backup policies and procedures, restoration and recovery procedures and methodsArt. 13 — Learning and evolvingArt. 14 — CommunicationArt. 15 — Further harmonisation of ICT risk management tools, methods, processes and policiesArt. 16 — Simplified ICT risk management framework
Chapter III — ICT-related incident management, classification and reporting
Art. 17 — ICT-related incident management processArt. 18 — Classification of ICT-related incidents and cyber threatsArt. 19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsArt. 20 — Harmonisation of reporting content and templatesArt. 21 — Centralisation of reporting of major ICT-related incidentsArt. 22 — Supervisory feedbackArt. 23 — Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Chapter IV — Digital operational resilience testing
Chapter V — Managing of ICT third-party risk
Art. 28 — General principlesArt. 29 — Preliminary assessment of ICT concentration risk at entity levelArt. 30 — Key contractual provisionsArt. 31 — Designation of critical ICT third-party service providersArt. 32 — Structure of the Oversight FrameworkArt. 33 — Tasks of the Lead OverseerArt. 34 — Operational coordination between Lead OverseersArt. 35 — Powers of the Lead OverseerArt. 36 — Exercise of the powers of the Lead Overseer outside the UnionArt. 37 — Request for informationArt. 38 — General investigationsArt. 39 — InspectionsArt. 40 — Ongoing oversightArt. 41 — Harmonisation of conditions enabling the conduct of the oversight activitiesArt. 42 — Follow-up by competent authoritiesArt. 43 — Oversight feesArt. 44 — International cooperation
Chapter VI — Information-sharing arrangements
Chapter VII — Competent authorities
Art. 46 — Competent authoritiesArt. 47 — Cooperation with structures and authorities established by Directive (EU) 2022/2555Art. 48 — Cooperation between authoritiesArt. 49 — Financial cross-sector exercises, communication and cooperationArt. 50 — Administrative penalties and remedial measuresArt. 51 — Exercise of the power to impose administrative penalties and remedial measuresArt. 52 — Criminal penaltiesArt. 53 — Notification dutiesArt. 54 — Publication of administrative penaltiesArt. 55 — Professional secrecyArt. 56 — Data Protection
Chapter VIII — Delegated acts
Chapter IX — Transitional and final provisions
Art. 58 — Review clauseArt. 59 — Amendments to Regulation (EC) No 1060/2009Art. 60 — Amendments to Regulation (EU) No 648/2012Art. 61 — Amendments to Regulation (EU) No 909/2014Art. 62 — Amendments to Regulation (EU) No 600/2014Art. 63 — Amendment to Regulation (EU) 2016/1011Art. 64 — Entry into force and application