acquis · Law · DORA

DORA · CELEX 32022R2554

Article 17

Verbatim text of the current consolidated version · status: in force. Check it on EUR-Lex ↗

DORA, Article 17(1) — ICT-related incident management process
Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents.
DORA, Article 17(2) — ICT-related incident management process
Financial entities shall record all ICT-related incidents and significant cyber threats. Financial entities shall establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling and follow-up of ICT-related incidents, to ensure that root causes are identified, documented and addressed in order to prevent the occurrence of such incidents.
DORA, Article 17(3) — ICT-related incident management process
The ICT-related incident management process referred to in paragraph 1 shall: (a) put in place early warning indicators; (b) establish procedures to identify, track, log, categorise and classify ICT-related incidents according to their priority and severity and according to the criticality of the services impacted, in accordance with the criteria set out in Article 18(1); (c) assign roles and responsibilities that need to be activated for different ICT-related incident types and scenarios; (d) set out plans for communication to staff, external stakeholders and media in accordance with Article 14 and for notification to clients, for internal escalation procedures, including ICT-related customer complaints, as well as for the provision of information to financial entities that act as counterparts, as appropriate; (e) ensure that at least major ICT-related incidents are reported to relevant senior management and inform the management body of at least major ICT-related incidents, explaining the impact, response and additional controls to be established as a result of such ICT-related incidents; (f) establish ICT-related incident response procedures to mitigate impacts and ensure that services become operational and secure in a timely manner.
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →

Other articles of the DORA

← Article 16 · Article 18

Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage

DORA, Article 17 — full text, verified