Law / European Union

DORA, Articles 5-16 (ICT Risk Management Framework)

Regulation (EU) 2022/2554, Arts. 5-16

In force since .

A sector security regimes rule binding private bodies.

Private right of action
No
Obligation class
Governance, Security

As of .

What it requires

  • It reaches you if you are a financial entity under Article 2(1), points (a) to (t), of Regulation (EU) 2022/2554, such as a credit institution, payment institution, electronic money institution, investment firm, crypto-asset service provider, central counterparty or trading venue, unless Article 2(3) takes you out of the Regulation or your Member State has excluded you under Article 2(4). If you are an entity named in Article 16(1), Articles 5 to 15 do not apply to you and the simplified framework of Article 16 applies instead. Apply these rules in proportion to your size, overall risk profile, and the nature, scale and complexity of your services, activities and operations (Article 4(1)). An ICT third-party service provider is not a financial entity under Article 2(2) and these Articles do not bind it directly.
  • Have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk. Have your management body define, approve, oversee and answer for all arrangements under the ICT risk management framework, bear the ultimate responsibility for managing ICT risk, set and approve the digital operational resilience strategy and risk tolerance level, and approve and review your ICT business continuity policy, response and recovery plans, ICT internal audit plans and policy on the use of ICT third-party services (Article 5(1) and (2)).
  • Keep the members of your management body up to date with sufficient knowledge and skills to understand and assess ICT risk, including through specific training on a regular basis. Unless you are a microenterprise, establish a role, or designate a member of senior management, to monitor the arrangements with ICT third-party service providers (Article 5(3) and (4)).
  • Maintain a sound, comprehensive and well-documented ICT risk management framework as part of your overall risk management system, with the strategies, policies, procedures, ICT protocols and tools needed to protect all information assets and ICT assets. Document and review it at least once a year (periodically if you are a microenterprise), after major ICT-related incidents, and after supervisory instructions or conclusions from testing or audit. Give your competent authority complete and updated information on ICT risk and a report on the review of the framework on request (Article 6(1) to (3) and (5)).
  • Unless you are a microenterprise, assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence, keep ICT risk management, control and internal audit functions segregated, have the framework audited internally on a regular basis by auditors with sufficient knowledge, skills and expertise in ICT risk, and establish a formal follow-up process for critical ICT audit findings (Article 6(4), (6) and (7)).
  • Include in the framework a digital operational resilience strategy that explains how the framework supports your business strategy, sets the risk tolerance level for ICT risk and the impact tolerance for ICT disruptions, sets information security objectives with key performance indicators and key risk metrics, describes the ICT reference architecture, outlines the mechanisms to detect and prevent the impact of ICT-related incidents, provides for digital operational resilience testing, and outlines a communication strategy for incident disclosure (Article 6(8)).
  • Use and maintain updated ICT systems, protocols and tools that are appropriate to the magnitude of your operations, reliable, equipped with sufficient capacity to process data accurately and deal with peak volumes, and technologically resilient under stressed conditions (Article 7).
  • Identify, classify and document all ICT supported business functions, the information assets and ICT assets that support them and their dependencies, and review that classification at least yearly. Identify all sources of ICT risk on a continuous basis and review the risk scenarios that affect you at least yearly. Map the assets you consider critical, and identify the processes that depend on ICT third-party service providers. Unless you are a microenterprise, perform a risk assessment on each major change in your network and information system infrastructure and at least yearly on all legacy ICT systems (Article 8).
  • Continuously monitor and control the security and functioning of your ICT systems and deploy ICT security policies, procedures, protocols and tools that keep data available, authentic, intact and confidential at rest, in use and in transit. Document an information security policy, policies that limit physical and logical access to what is needed, strong authentication mechanisms and protection of cryptographic keys, ICT change management, and policies for patches and updates, and design network connections so that they can be instantaneously severed or segmented (Article 9).
  • Have mechanisms with multiple layers of control, alert thresholds and criteria that promptly detect anomalous activities, ICT network performance issues and ICT-related incidents and trigger incident response, test them regularly under Article 25, and devote sufficient resources to monitor user activity, ICT anomalies and ICT-related incidents. If you are a data reporting service provider, also have systems that check trade reports for completeness, identify omissions and obvious errors, and request re-transmission (Article 10).
  • Put in place a comprehensive ICT business continuity policy and ICT response and recovery plans, and conduct a business impact analysis of your exposures to severe business disruptions. Test the continuity and the response and recovery plans at least yearly and on substantive changes to systems supporting critical or important functions, and test your crisis communication plans. Keep readily accessible records of activities before and during disruption events. Unless you are a microenterprise, include cyber-attack and switchover scenarios in the tests, have a crisis management function, and report to your competent authority on request an estimate of the aggregated annual costs and losses caused by major ICT-related incidents (Article 11).
  • Develop and document backup policies and procedures and restoration and recovery procedures and methods, set up backup systems and test them periodically, and restore backup data on ICT systems that are physically and logically segregated from the source system. Unless you are a microenterprise, maintain redundant ICT capacities adequate to your business needs. If you are a central securities depository, maintain a secondary processing site that meets Article 12(5) (Article 12).
  • Have capabilities and staff to gather information on vulnerabilities, cyber threats and ICT-related incidents, run post-incident reviews after a major ICT-related incident disrupts your core activities, build the lessons from testing and real incidents into the ICT risk assessment, have senior ICT staff report at least yearly to the management body, and make ICT security awareness programs and digital operational resilience training compulsory modules for all employees and senior management (Article 13).
  • Have crisis communication plans that enable a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients and counterparts and to the public, communication policies for staff and external stakeholders, and at least one person tasked with implementing the communication strategy and fulfilling the public and media function (Article 14).
  • If you are an entity named in Article 16(1), maintain a sound and documented ICT risk management framework, continuously monitor the security and functioning of all ICT systems, use sound, resilient and updated ICT systems, protocols and tools, promptly identify and detect sources of ICT risk and anomalies, identify key dependencies on ICT third-party service providers, ensure the continuity of critical or important functions through business continuity plans and response and recovery measures that include back-up and restoration, and test those plans and the controls regularly. Document and review the framework periodically and after major ICT-related incidents, and give the competent authority a report on the review on request (Article 16(1) and (2)).

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46, which ensures compliance with the Regulation in accordance with the powers granted by the respective legal acts.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Regulation (EU) 2022/2554 (DORA) applies to the financial entities listed in Article 2(1), points (a) to (t), among them credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers, central counterparties, trading venues and insurance and reinsurance undertakings.

Article 2(3) takes six classes of entity out of the Regulation, among them insurance and reinsurance undertakings referred to in Article 4 of Directive 2009/138/EC, institutions for occupational retirement provision with no more than 15 members in total, and post office giro institutions. Article 2(4) lets a Member State exclude from the Regulation the entities referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU that are located within its territory.

Article 4 requires a financial entity to implement the rules of Chapter II in proportion to its size and overall risk profile and to the nature, scale and complexity of its services, activities and operations. Article 5(1) requires a financial entity to have an internal governance and control framework that ensures an effective and prudent management of ICT risk.

Article 5(2) makes the management body of the financial entity define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework. Article 5(4) requires the members of the management body to keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including by following specific training on a regular basis.

Article 6(1) requires a financial entity to have a sound, comprehensive and well-documented ICT risk management framework as part of its overall risk management system. Article 6(5) requires the framework to be documented and reviewed at least once a year, or periodically in the case of microenterprises, and upon the occurrence of major ICT-related incidents.

Article 6(4) requires a financial entity other than a microenterprise to assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence. Article 6(8) requires the framework to include a digital operational resilience strategy that sets the risk tolerance level for ICT risk and information security objectives and covers the implementation of digital operational resilience testing.

Article 7 requires a financial entity to use and maintain updated ICT systems, protocols and tools that are appropriate to the magnitude of its operations, reliable, equipped with sufficient capacity and technologically resilient. Article 8 requires a financial entity to identify, classify and document all ICT supported business functions and the information assets and ICT assets supporting them, and to review the adequacy of that classification at least yearly.

Article 9(4) requires a financial entity to document an information security policy, access-limiting policies, strong authentication mechanisms, ICT change management and policies for patches and updates. Article 10(1) requires mechanisms to promptly detect anomalous activities, including ICT network performance issues and ICT-related incidents, and to identify potential material single points of failure.

Article 11 requires a comprehensive ICT business continuity policy and, under Article 11(3), ICT response and recovery plans, which Article 11(6) requires to be tested at least yearly. Article 12(1) requires a financial entity to develop and document backup policies and procedures and restoration and recovery procedures and methods. Article 13(2) requires post ICT-related incident reviews after a major ICT-related incident disrupts the financial entity's core activities.

Article 14(1) requires crisis communication plans that enable a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients and counterparts and to the public. Article 15 delegates to the Commission the adoption of regulatory technical standards that specify these elements further.

Article 16(1) disapplies Articles 5 to 15 to small and non-interconnected investment firms, payment institutions exempted pursuant to Directive (EU) 2015/2366, institutions exempted pursuant to Directive 2013/36/EU in respect of which Member States have decided not to apply the option referred to in Article 2(4), electronic money institutions exempted pursuant to Directive 2009/110/EC and small institutions for occupational retirement provision, and requires those entities to meet the simplified framework of Article 16 instead.

Article 50(3) requires Member States to lay down rules establishing appropriate administrative penalties and remedial measures for breaches of the Regulation, which must be effective, proportionate and dissuasive. Article 64 applies the Regulation from .

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app