Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Chapter VII – Competent authorities
Article 47
Cooperation with structures and authorities established by Directive (EU) 2022/2555
1. To foster cooperation and enable supervisory exchanges between the competent authorities designated under this Regulation and the Cooperation Group established by Article 14 of NIS2 Directive (Network and Information Security), the ESAs and the competent authorities may participate in the activities of the Cooperation Group for matters that concern their supervisory activities in relation to financial entities. The ESAs and the competent authorities may request to be invited to participate in the activities of the Cooperation Group for matters in relation to essential or important entities subject to NIS2 Directive (Network and Information Security) that have also been designated as critical ICT third-party service providers pursuant to Article 31 of this Regulation.
2. Where appropriate, competent authorities may consult and share information with the single points of contact and the CSIRTs designated or established in accordance with NIS2 Directive (Network and Information Security).
3. Where appropriate, competent authorities may request any relevant technical advice and assistance from the competent authorities designated or established in accordance with NIS2 Directive (Network and Information Security) and establish cooperation arrangements to allow effective and fast-response coordination mechanisms to be set up.
4. The arrangements referred to in paragraph 3 of this Article may, inter alia, specify the procedures for the coordination of supervisory and oversight activities in relation to essential or important entities subject to NIS2 Directive (Network and Information Security) that have been designated as critical ICT third-party service providers pursuant to Article 31 of this Regulation, including for the conduct, in accordance with national law, of investigations and on-site inspections, as well as for mechanisms for the exchange of information between the competent authorities under this Regulation and the competent authorities designated or established in accordance with that Directive which includes access to information requested by the latter authorities.