Text applicable on 7 Oct 2026Consolidated version of 16 Jan 2023In forceUnofficial text · authentic on EUR-Lex (opens in a new tab)
DORA Chapter iii — as applicable on 7 Oct 2026 (version of 16 Jan 2023)
Teal underlined text links to another provision.
CHAPTER III
ICT-related incident management, classification and reporting
- Article 17ICT-related incident management process
- Article 18Classification of ICT-related incidents and cyber threats
- Article 19Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
- Article 20Harmonisation of reporting content and templates
- Article 21Centralisation of reporting of major ICT-related incidents
- Article 22Supervisory feedback
- Article 23Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions