> For the complete documentation index, see [llms.txt](https://www.headlesslaw.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.headlesslaw.com/dora/readme.md).

# DORA

*In force · Regulation (EU) 2022/2554, OJ L 333, 27.12.2022 ·* [*Official source*](https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng)

**Regulation (EU) 2022/2554** of the European Parliament and of the Council of **14 December 2022** on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011.

* **OJ reference:** OJ L 333, 27.12.2022, p. 1
* **EUR-Lex:** [CELEX:32022R2554](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554)
* **Application date:** **17 January 2025**
* **Status:** In Force

**Source:** [Regulation (EU) 2022/2554 — EUR-Lex](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554)

### Contents

* [Recitals](/dora/recitals.md)

#### [Chapter I — General provisions](/dora/chapters/i.md)

* [Article 1 — Subject matter](/dora/articles/1.md)
* [Article 2 — Scope](/dora/articles/2.md)
* [Article 3 — Definitions](/dora/articles/3.md)
* [Article 4 — Proportionality principle](/dora/articles/4.md)

#### [Chapter II — ICT risk management](/dora/chapters/ii.md)

**Section I**

* [Article 5 — Governance and organisation](/dora/articles/5.md)

**Section II**

* [Article 6 — ICT risk management framework](/dora/articles/6.md)
* [Article 7 — ICT systems, protocols and tools](/dora/articles/7.md)
* [Article 8 — Identification](/dora/articles/8.md)
* [Article 9 — Protection and prevention](/dora/articles/9.md)
* [Article 10 — Detection](/dora/articles/10.md)
* [Article 11 — Response and recovery](/dora/articles/11.md)
* [Article 12 — Backup policies and procedures, restoration and recovery procedures and methods](/dora/articles/12.md)
* [Article 13 — Learning and evolving](/dora/articles/13.md)
* [Article 14 — Communication](/dora/articles/14.md)
* [Article 15 — Further harmonisation of ICT risk management tools, methods, processes and policies](/dora/articles/15.md)
* [Article 16 — Simplified ICT risk management framework](/dora/articles/16.md)

#### [Chapter III — ICT-related incident management, classification and reporting](/dora/chapters/iii.md)

* [Article 17 — ICT-related incident management process](/dora/articles/17.md)
* [Article 18 — Classification of ICT-related incidents and cyber threats](/dora/articles/18.md)
* [Article 19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threats](/dora/articles/19.md)
* [Article 20 — Harmonisation of reporting content and templates](/dora/articles/20.md)
* [Article 21 — Centralisation of reporting of major ICT-related incidents](/dora/articles/21.md)
* [Article 22 — Supervisory feedback](/dora/articles/22.md)
* [Article 23 — Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions](/dora/articles/23.md)

#### [Chapter IV — Digital operational resilience testing](/dora/chapters/iv.md)

* [Article 24 — General requirements for the performance of digital operational resilience testing](/dora/articles/24.md)
* [Article 25 — Testing of ICT tools and systems](/dora/articles/25.md)
* [Article 26 — Advanced testing of ICT tools, systems and processes based on TLPT](/dora/articles/26.md)
* [Article 27 — Requirements for testers for the carrying out of TLPT](/dora/articles/27.md)

#### [Chapter V — Managing of ICT third-party risk](/dora/chapters/v.md)

**Section I — Key principles for a sound management of ICT third-party risk**

* [Article 28 — General principles](/dora/articles/28.md)
* [Article 29 — Preliminary assessment of ICT concentration risk at entity level](/dora/articles/29.md)
* [Article 30 — Key contractual provisions](/dora/articles/30.md)

**Section II — Oversight Framework of critical ICT third-party service providers**

* [Article 31 — Designation of critical ICT third-party service providers](/dora/articles/31.md)
* [Article 32 — Structure of the Oversight Framework](/dora/articles/32.md)
* [Article 33 — Tasks of the Lead Overseer](/dora/articles/33.md)
* [Article 34 — Operational coordination between Lead Overseers](/dora/articles/34.md)
* [Article 35 — Powers of the Lead Overseer](/dora/articles/35.md)
* [Article 36 — Exercise of the powers of the Lead Overseer outside the Union](/dora/articles/36.md)
* [Article 37 — Request for information](/dora/articles/37.md)
* [Article 38 — General investigations](/dora/articles/38.md)
* [Article 39 — Inspections](/dora/articles/39.md)
* [Article 40 — Ongoing oversight](/dora/articles/40.md)
* [Article 41 — Harmonisation of conditions enabling the conduct of the oversight activities](/dora/articles/41.md)
* [Article 42 — Follow-up by competent authorities](/dora/articles/42.md)
* [Article 43 — Oversight fees](/dora/articles/43.md)
* [Article 44 — International cooperation](/dora/articles/44.md)

#### [Chapter VI — Information-sharing arrangements](/dora/chapters/vi.md)

* [Article 45 — Information-sharing arrangements on cyber threat information and intelligence](/dora/articles/45.md)

#### [Chapter VII — Competent authorities](/dora/chapters/vii.md)

* [Article 46 — Competent authorities](/dora/articles/46.md)
* [Article 47 — Cooperation with structures and authorities established by Directive (EU) 2022/2555](/dora/articles/47.md)
* [Article 48 — Cooperation between authorities](/dora/articles/48.md)
* [Article 49 — Financial cross-sector exercises, communication and cooperation](/dora/articles/49.md)
* [Article 50 — Administrative penalties and remedial measures](/dora/articles/50.md)
* [Article 51 — Exercise of the power to impose administrative penalties and remedial measures](/dora/articles/51.md)
* [Article 52 — Criminal penalties](/dora/articles/52.md)
* [Article 53 — Notification duties](/dora/articles/53.md)
* [Article 54 — Publication of administrative penalties](/dora/articles/54.md)
* [Article 55 — Professional secrecy](/dora/articles/55.md)
* [Article 56 — Data Protection](/dora/articles/56.md)

#### [Chapter VIII — Delegated acts](/dora/chapters/viii.md)

* [Article 57 — Exercise of the delegation](/dora/articles/57.md)

#### [Chapter IX — Transitional and final provisions](/dora/chapters/ix.md)

**Section I**

* [Article 58 — Review clause](/dora/articles/58.md)

**Section II — Amendments**

* [Article 59 — Amendments to Regulation (EC) No 1060/2009](/dora/articles/59.md)
* [Article 60 — Amendments to Regulation (EU) No 648/2012](/dora/articles/60.md)
* [Article 61 — Amendments to Regulation (EU) No 909/2014](/dora/articles/61.md)
* [Article 62 — Amendments to Regulation (EU) No 600/2014](/dora/articles/62.md)
* [Article 63 — Amendment to Regulation (EU) 2016/1011](/dora/articles/63.md)
* [Article 64 — Entry into force and application](/dora/articles/64.md)

### Level 2 and Level 3

* [Level 2](/dora/level-2.md)
* [Level 3](/dora/level-3.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.headlesslaw.com/dora/readme.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
