DORA (Regulation (EU) 2022/2554)
The register cites 12 of its 26 clauses, on 24 policy types. Rendered when the buyer ticks "DORA".
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the DORA regime page.
Clauses cited
12 of 26DORA Art. 5 Governance and organisationThe management body of the financial entity shall define, approve, oversee and be responsible for the implementation of the ICT risk management framework, bear ultimate responsibility for managing ICT risk, set roles and responsibilities, approve the digital operational resilience strategy, and allocate appropriate budget and training.
Common gap: No management-body ownership of ICT risk
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 6 ICT risk management frameworkFinancial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, enabling them to address ICT risk quickly, efficiently and comprehensively, reviewed at least annually and audited periodically by ICT-audit staff.
Common gap: No documented ICT risk framework
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 9 Protection and preventionFinancial entities shall continuously monitor and control the security and functioning of ICT systems and tools, and minimise ICT risk through appropriate ICT security policies, procedures, protocols and tools ensuring resilience, continuity and availability, and preserving confidentiality, integrity and authenticity of data (incl access management, encryption, secure configuration, network security).
Common gap: Weak or absent protective controls
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 10 DetectionFinancial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.
Common gap: No anomaly detection or alerting
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 11 Response and recoveryFinancial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.
Common gap: No ICT continuity/response/recovery plans
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recoveryFinancial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.
Common gap: No tested backups
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 14 CommunicationFinancial entities shall have crisis communication plans enabling responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts and the public as appropriate, and designate communication policies for internal staff and external stakeholders.
Common gap: No crisis communication plan
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 17 ICT-related incident management processFinancial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.
Common gap: No structured incident management process
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 24 General requirements for the performance of digital operational resilience testingFinancial entities shall establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk management framework, following a risk-based approach.
Common gap: No resilience testing programme
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 25 Testing of ICT tools and systemsThe testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.
Common gap: Critical systems not tested annually
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 28 ICT third-party risk: general principlesFinancial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
Common gap: No Register of Information
Source: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisionsContractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.
Common gap: Contracts missing audit/access, termination or exit provisions
Source: DORA (Regulation (EU) 2022/2554)
See which clauses your list answers
Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.
Build a register