← current version of this provision

DORA Article 17 — held text

This page is a held version, frozen at the capture below. It is a source for review. It is not advice, and it does not determine whether this provision applies to you.

Article 17 ICT-related incident management process 1. Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents. 2. Financial entities shall record all ICT-related incidents and significant cyber threats. Financial entities shall establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling and follow-up of ICTrelated incidents, to ensure that root causes are identified, documented and addressed in order to prevent the occurrence of such incidents. L 333/40 EN Official Journal of the European Union 27.12.2022 3. The ICT-related incident management process referred to in paragraph 1 shall: (a) put in place early warning indicators; (b) establish procedures to identify, track, log, categorise and classify ICT-related incidents according to their priority and severity and according to the criticality of the services impacted, in accordance with the criteria set out in Article 18(1); (c) assign roles and responsibilities that need to be activated for different ICT-related incident types and scenarios; (d) set out plans for communication to staff, external stakeholders and media in accordance with Article 14 and for notification to clients, for internal escalation procedures, including ICT-related customer complaints, as well as for the provision of information to financial entities that act as counterparts, as appropriate; (e) ensure that at least major ICT-related incidents are reported to relevant senior management and inform the management body of at least major ICT-related incidents, explaining the impact, response and additional controls to be established as a result of such ICT-related incidents; (f) establish ICT-related incident response procedures to mitigate impacts and ensure that services become operational and secure in a timely manner.
CELEX: 32022R2554 · provision: 17
Locator: Article 17; PDF page 39; derived-text line 898
Held artifact: docs_evidence/eu-legislation/eurlex-full-text/20260823T093000Z/32022R2554.pdf
Artifact SHA-256: 85307f9e2a0409826dd0f54489645935816d16e929f0db4db3ef15badd11d38c
Captured: 20260823T093000Z
Extracted with: pdftotext version 4.00
Official source: EUR-Lex
This version: /celex/32022R2554/ART_17/20260823-85307f9e/
Corpus Merkle root: 581628a5b36518981241d2b51f048aa46384f30a74bf648ef542c652028cdeff
Membership proof: 10 hashes — see corpus-proof.json
Modal verbs, counted verbatim (not a legal characterisation): 'shall not': 0 · 'shall': 4 · 'must': 0 · 'may not': 0 · 'may': 0 · 'should': 0

To verify independently: fetch the official source above, extract it with the named tool, and confirm the artifact SHA-256 matches. Then check this provision's leaf against the published Merkle root using the proof in corpus-proof.json.