Cite this version: /celex/32022R2554/ART_14/20260823-85307f9e/
That address is frozen: its bytes never change. This page shows the current text and moves when a newer capture is held. Corpus Merkle root 581628a5b36518981241d2b51f048aa46384f30a74bf648ef542c652028cdeff.

← SatoshiShrine·Source Pathfinder·Topics

DORA Article 14 — held text

Open the official source (EUR-Lex) →

DORA Article 14 — held text Article 14 Communication 1.

As part of the ICT risk management framework referred to in Article 6(1), financial entities shall have in place crisis communication plans enabling a responsible disclosure of, at least, major ICT-related incidents or vulnerabilities to clients and counterparts as well as to the public, as appropriate.

2.

As part of the ICT risk management framework, financial entities shall implement communication policies for internal staff and for external stakeholders.

Communication policies for staff shall take into account the need to differentiate between staff involved in ICT risk management, in particular the staff responsible for response and recovery, and staff that needs to be informed.

3.

At least one person in the financial entity shall be tasked with implementing the communication strategy for ICTrelated incidents and fulfil the public and media function for that purpose.

32022R2554

docs_evidence/eu-legislation/eurlex-full-text/20260823T093000Z/32022R2554.pdf · sha256 85307f9e2a0409826dd0f54489645935816d16e929f0db4db3ef15badd11d38c · saved and fingerprinted 20260823T093000Z · Article 14; PDF page 37; derived-text line 835

Legal text reproduced from the official source under Commission Decision 2011/833/EU. Only the official publication is authentic. This page shows our saved copy of the text. It is not advice and does not decide whether any provision applies to anyone.