CyberTRIZPEDIA

Digital Operational Resilience Act

Framework for digital operational resilience for EU financial entities.

Jurisdiction
EU / EEA
Issuer
European Parliament and Council
Effective
2025-01-17

Sectors

Banking & FinanceCrypto & Digital AssetsDigital InfrastructureICT Service ManagementInsuranceIT & Cybersecurity

Articles (137)

Article 20 — Harmonisation of reporting content and templatesEU_DORAArticle 21 — Centralisation of reporting of major ICT-related incidentsEU_DORAArticle 22 — Supervisory feedbackEU_DORAArticle 23 — Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutionsEU_DORAArticle 24 — General requirements for the performance of digital operational resilience testingEU_DORAArticle 25 — Testing of ICT tools and systemsEU_DORAArticle 26 — Advanced testing of ICT tools, systems and processes based on TLPTEU_DORAArticle 27 — Requirements for testers for the carrying out of TLPTEU_DORAArticle 28 — General principlesEU_DORAArticle 29 — Preliminary assessment of ICT concentration risk at entity levelEU_DORAArticle 30 — Key contractual provisionsEU_DORAArticle 31 — Designation of critical ICT third-party service providersEU_DORAArticle 32 — Structure of the Oversight FrameworkEU_DORAArticle 33 — Tasks of the Lead OverseerEU_DORAArticle 34 — Operational coordination between Lead OverseersEU_DORAArticle 35 — Powers of the Lead OverseerEU_DORAArticle 36 — Exercise of the powers of the Lead Overseer outside the UnionEU_DORAArticle 37 — Request for informationEU_DORAArticle 38 — General investigationsEU_DORAArticle 39 — InspectionsEU_DORAArticle 40 — Ongoing oversightEU_DORAArticle 41 — Harmonisation of conditions enabling the conduct of the oversight activitiesEU_DORAArticle 42 — Follow-up by competent authoritiesEU_DORAArticle 43 — Oversight feesEU_DORAArticle 44 — International cooperationEU_DORAArticle 45 — Information-sharing arrangements on cyber threat information and intelligenceEU_DORAArticle 46 — Competent authoritiesEU_DORAArticle 47 — Cooperation with structures and authorities established by Directive (EU) 2022/2555EU_DORAArticle 48 — Cooperation between authoritiesEU_DORAArticle 49 — Financial cross-sector exercises, communication and cooperationEU_DORAArticle 50 — Administrative penalties and remedial measuresEU_DORAArticle 51 — Exercise of the power to impose administrative penalties and remedial measuresEU_DORAArticle 52 — Criminal penaltiesEU_DORAArticle 53 — Notification dutiesEU_DORAArticle 54 — Publication of administrative penaltiesEU_DORAArticle 55 — Professional secrecyEU_DORAArticle 56 — Data ProtectionEU_DORAArticle 57 — Exercise of the delegationEU_DORAArticle 58 — Review clauseEU_DORAArticle 59 — Amendments to Regulation (EC) No 1060/2009EU_DORAArticle 60 — Amendments to Regulation (EU) No 648/2012EU_DORAArticle 61 — Amendments to Regulation (EU) No 909/2014EU_DORAArticle 62 — Amendments to Regulation (EU) No 600/2014EU_DORAArticle 63 — Amendment to Regulation (EU) 2016/1011EU_DORAArticle 64 — Entry into force and applicationEU_DORAArticle 1 — Subject matterEU_DORAArticle 2 — ScopeEU_DORAArticle 3 — DefinitionsEU_DORAArticle 4 — Proportionality principleEU_DORAArticle 5 — Governance and organisationEU_DORAArticle 6 — ICT risk management frameworkEU_DORAArticle 7 — ICT systems, protocols and toolsEU_DORAArticle 8 — IdentificationEU_DORAArticle 9 — Protection and preventionEU_DORAArticle 10 — DetectionEU_DORAArticle 11 — Response and recoveryEU_DORAArticle 12 — Backup policies and procedures, restoration and recovery procedures and methodsEU_DORAArticle 13 — Learning and evolvingEU_DORAArticle 14 — CommunicationEU_DORAArticle 15 — Further harmonisation of ICT risk management tools, methods, processes and policiesEU_DORAArticle 16 — Simplified ICT risk management frameworkEU_DORAArticle 17 — ICT-related incident management processEU_DORAArticle 18 — Classification of ICT-related incidents and cyber threatsEU_DORAArticle 19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threatsEU_DORAArticle 1 — DefinitionsEU_DORA_ITS_2956Article 2 — Ranking of ICT third-party providers in the supply chainEU_DORA_ITS_2956Article 3 — General requirements for the templates of the register of informationEU_DORA_ITS_2956Article 4 — Data format requirementEU_DORA_ITS_2956Article 5 — Content of the register of informationEU_DORA_ITS_2956Article 6 — Scope of the register of information at sub-consolidated and consolidated levelEU_DORA_ITS_2956Article 7 — Entry into forceEU_DORA_ITS_2956Article 1 — Clients, financial counterparts and transactionsEU_DORA_RTS_1772Article 2 — Reputational impactEU_DORA_RTS_1772Article 3 — Duration and service downtimeEU_DORA_RTS_1772Article 4 — Geographical spreadEU_DORA_RTS_1772Article 5 — Data lossesEU_DORA_RTS_1772Article 6 — Criticality of services affectedEU_DORA_RTS_1772Article 7 — Economic impactEU_DORA_RTS_1772Article 8 — Major incidentsEU_DORA_RTS_1772Article 9 — Materiality thresholds for determining major incidentsEU_DORA_RTS_1772Article 10 — High materiality thresholds for determining significant cyber threatsEU_DORA_RTS_1772Article 11 — Relevance of major incidents to competent authorities in other Member StatesEU_DORA_RTS_1772Article 12 — Details of major incidents to be shared with other competent authoritiesEU_DORA_RTS_1772Article 13 — Entry into forceEU_DORA_RTS_1772Article 1 — Overall risk profile and complexityEU_DORA_RTS_1773Article 2 — Group applicationEU_DORA_RTS_1773Article 3 — Governance arrangementsEU_DORA_RTS_1773Article 4 — Main phases of the life cycle for the adoption and use of contractual arrangementsEU_DORA_RTS_1773Article 5 — Ex-ante risk assessmentEU_DORA_RTS_1773Article 6 — Due diligenceEU_DORA_RTS_1773Article 7 — Conflicts of interestEU_DORA_RTS_1773Article 8 — Contractual clausesEU_DORA_RTS_1773Article 9 — Monitoring of the contractual arrangementsEU_DORA_RTS_1773Article 10 — Exit from and termination of the contractual arrangementsEU_DORA_RTS_1773Article 11 — Entry into forceEU_DORA_RTS_1773Article 1 — Overall risk profile and complexityEU_DORA_RTS_1774Article 2 — General elements of ICT security policies, procedures, protocols, and toolsEU_DORA_RTS_1774Article 3 — ICT risk managementEU_DORA_RTS_1774Article 4 — ICT asset management policyEU_DORA_RTS_1774Article 5 — ICT asset management procedureEU_DORA_RTS_1774Article 6 — Encryption and cryptographic controlsEU_DORA_RTS_1774Article 7 — Cryptographic key managementEU_DORA_RTS_1774Article 8 — Policies and procedures for ICT operationsEU_DORA_RTS_1774Article 9 — Capacity and performance managementEU_DORA_RTS_1774Article 10 — Vulnerability and patch managementEU_DORA_RTS_1774Article 11 — Data and system securityEU_DORA_RTS_1774Article 12 — LoggingEU_DORA_RTS_1774Article 13 — Network security managementEU_DORA_RTS_1774Article 14 — Securing information in transitEU_DORA_RTS_1774Article 15 — ICT project managementEU_DORA_RTS_1774Article 16 — ICT systems acquisition, development, and maintenanceEU_DORA_RTS_1774Article 17 — ICT change managementEU_DORA_RTS_1774Article 18 — Physical and environmental securityEU_DORA_RTS_1774Article 19 — Human resources policyEU_DORA_RTS_1774Article 20 — Identity managementEU_DORA_RTS_1774Article 21 — Access controlEU_DORA_RTS_1774Article 22 — ICT-related incident management policyEU_DORA_RTS_1774Article 23 — Anomalous activities detection and criteria for ICT-related incidents detection and responseEU_DORA_RTS_1774Article 24 — Components of the ICT business continuity policyEU_DORA_RTS_1774Article 25 — Testing of the ICT business continuity plansEU_DORA_RTS_1774Article 26 — ICT response and recovery plansEU_DORA_RTS_1774Article 27 — Format and content of the report on the review of the ICT risk management frameworkEU_DORA_RTS_1774Article 28 — Governance and organisationEU_DORA_RTS_1774Article 29 — Information security policy and measuresEU_DORA_RTS_1774Article 30 — Classification of information assets and ICT assetsEU_DORA_RTS_1774Article 31 — ICT risk managementEU_DORA_RTS_1774Article 32 — Physical and environmental securityEU_DORA_RTS_1774Article 33 — Access ControlEU_DORA_RTS_1774Article 34 — ICT operations securityEU_DORA_RTS_1774Article 35 — Data, system and network securityEU_DORA_RTS_1774Article 36 — ICT security testingEU_DORA_RTS_1774Article 37 — ICT systems acquisition, development, and maintenanceEU_DORA_RTS_1774Article 38 — ICT project and change managementEU_DORA_RTS_1774Article 39 — Components of the ICT business continuity planEU_DORA_RTS_1774Article 40 — Testing of business continuity plansEU_DORA_RTS_1774Article 41 — Format and content of the report on the review of the simplified ICT risk management frameworkEU_DORA_RTS_1774Article 42 — Entry into forceEU_DORA_RTS_1774

Controls that address this (40)

DORA-A17-001-B - DORA Incident Classification and Managementoperational · critical priority · Implement DORA-aligned incident classification using Article 18 criteria. Establish 24/7 incident capability. Log all incidents. Conduct posDORA-A5-001-B - Board ICT Risk Accountabilitygovernance · critical priority · Management body must formally approve ICT risk management framework, define ICT risk tolerance, and receive quarterly ICT risk reporting. CoDORA-GOV-001 - Maintain Board-Approved ICT Risk Management Frameworkoperational · critical priority · The management body must formally approve, own and oversee a documented ICT risk management framework. It must cover identification, protect