Loading Vaultize
Skip to main content

Compliance/Global/DORA

Sixty-four articles: eighteen leave evidence in the file.

The Regulation makes financial entities responsible for managing ICT risk, handling incidents and governing their ICT third-party contracts. Vaultize adds records that stay with the file.

  • Regulation (EU) 2022/2554
  • Adopted 14 December 2022
  • Applicable from 17 January 2025
  • Capability mapping, not legal advice

8(1)ICT risk management

As part of the ICT risk management framework referred to in Article 6(1), financial entities shall identify, classify and adequately document all ICT supported business functions, roles and responsibilities, the information assets and ICT assets supporting those functions, and their roles and dependencies in relation to ICT risk.

Discover & Classify

  1. I

    General provisions

    0 of 4

    • 1
    • 2
    • 3
    • 4
  2. II

    ICT risk management

    5 of 12

    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
    • 11
    • 12
    • 13
    • 14
    • 15
    • 16
  3. III

    Incident management

    2 of 7

    • 17
    • 18
    • 19
    • 20
    • 21
    • 22
    • 23
  4. IV

    Resilience testing

    0 of 4

    • 24
    • 25
    • 26
    • 27
  5. V

    ICT third-party risk

    1 of 17

    • 28
    • 29
    • 30
    • 31
    • 32
    • 33
    • 34
    • 35
    • 36
    • 37
    • 38
    • 39
    • 40
    • 41
    • 42
    • 43
    • 44
  6. VI

    Information sharing

    0 of 1

    • 45
  7. VII

    Competent authorities

    0 of 11

    • 46
    • 47
    • 48
    • 49
    • 50
    • 51
    • 52
    • 53
    • 54
    • 55
    • 56
  8. VIII

    Delegated acts

    0 of 1

    • 57
  9. IX

    Transitional and final provisions

    0 of 7

    • 58
    • 59
    • 60
    • 61
    • 62
    • 63
    • 64
18of 64 articles, in 3 of 9 chapters

The answer in 30 seconds

Vaultize adds file-level records to eighteen provisions across eight articles in three of the Regulation’s nine chapters: ICT risk management, ICT-related incident management and reporting, and managing ICT third-party risk. Governance, testing methodology, incident classification, reporting to competent authorities, information-sharing arrangements and the Oversight Framework for critical providers sit outside a governed file, with the financial entity and its regulators.

The Regulation in one view

Nine chapters. Sixty-four articles. Where file evidence lands.

The Regulation runs in nine chapters. Chapter summaries are in our words. Select a chapter to see which of its articles a governed file can evidence.

IIIIIIIVVVIVIIVIIIIX

I

General provisions

Articles 1 to 4. What the Regulation covers, which entities and activities fall within its scope, and the definitions it uses throughout.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Scope and definitions are matters for counsel. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Article by article

    What each provision asks. What the file can answer.

    Wording is quoted from Regulation (EU) 2022/2554 as published in the Official Journal. Longer provisions are excerpted. Each row is a capability mapping, not legal advice. Read the Regulation and take advice on applicability, roles and technical implementation.

    Using this page

    Where these rows fit in a DORA programme.

    The Regulation has applied since 17 January 2025. The rows above are evidence for the obligations that touch documents.

    1. 1

      Confirm scope

      Articles 2 and 3. Whether the entity is a financial entity within scope, and the definitions that apply to it.

    2. 2

      Build the ICT risk management framework

      Article 6. Governance, strategy and the framework the rest of Chapter II sits inside.

    3. 3

      Protect and recover the data

      Articles 9 to 12. Protection and prevention, detection, response and recovery, and backup and restoration. These rows belong here.

      Bring the eighteen rows above as evidence of the protection, detection, response and recovery measures Articles 9 to 12 require.

    4. 4

      Manage and report incidents

      Articles 17 to 19. Define the incident management process, classify incidents and cyber threats, and report major incidents to the competent authority.

    5. 5

      Set the third-party contract terms

      Article 30. The provisions a contract with an ICT third-party service provider must contain, including on data protection and on access, recovery and return of data.

    Responsibility boundary

    Controls support compliance. They are not legal advice.

    Vaultize contributes technical measures and evidence for documents and files within the ICT risk management framework. It does not build the framework itself, test ICT systems, classify or report incidents to competent authorities, or assess whether a contract with an ICT third-party service provider meets Article 30 in full. Read the Regulation and take qualified advice before relying on this page.

    “Financial entities shall design, procure and implement ICT security policies, procedures, protocols and tools that aim to ensure the resilience, continuity and availability of ICT systems, in particular for those supporting critical or important functions, and to maintain high standards of availability, authenticity, integrity and confidentiality of data, whether at rest, in use or in transit.”

    Article 9(2), Regulation (EU) 2022/2554 (DORA)

    A practical next step

    Bring one document covered by your ICT risk framework.

    We will show which articles the governed document can evidence today. We will name the owner responsible for the rest.

    Request a compliance mapping session