Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Chapter IX – Transitional and final provisions
Article 62
Amendments to Regulation (EU) No 600/2014
Markets in Financial Instruments Regulation (MiFIR) is amended as follows:
(1) Article 27g is amended as follows:
(a) paragraph 4 is replaced by the following:
‘4. An APA shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554 of the European Parliament and of the Council.
(b) in paragraph 8, point (c) is replaced by the following:
‘(c) the concrete organisational requirements laid down in paragraphs 3 and 5.’;
(2) Article 27h is amended as follows:
(a) paragraph 5 is replaced by the following:
‘5. A CTP shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554.’.
(b) in paragraph 8, point (e) is replaced by the following:
‘(e) the concrete organisational requirements laid down in paragraph 4.’;
(3) Article 27i is amended as follows:
(a) paragraph 3 is replaced by the following:
‘3. An ARM shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554.’;
(b) in paragraph 5, point (b) is replaced by the following:
‘(b) the concrete organisational requirements laid down in paragraphs 2 and 4.’.