> For the complete documentation index, see [llms.txt](https://www.mica.wtf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.mica.wtf/dora/digital-operational-resilience-act.md).

# DIGITAL OPERATIONAL RESILIENCE ACT

- [Recitals](https://www.mica.wtf/dora/digital-operational-resilience-act/recitals.md): Recitals of Regulation (EU) 2022/2554 (DORA).
- [Chapter I — General provisions (Art. 1–4)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-i-general-provisions.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Art. 1 — Subject matter](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-i-general-provisions/article-1-subject-matter.md): Article 1 — Subject matter of Regulation (EU) 2022/2554 (DORA).
- [Art. 2 — Scope](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-i-general-provisions/article-2-scope.md): Article 2 — Scope of Regulation (EU) 2022/2554 (DORA).
- [Art. 3 — Definitions](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-i-general-provisions/article-3-definitions.md): Article 3 — Definitions of Regulation (EU) 2022/2554 (DORA).
- [Art. 4 — Proportionality](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-i-general-provisions/article-4-proportionality-principle.md): Article 4 — Proportionality principle of Regulation (EU) 2022/2554 (DORA).
- [Chapter II — ICT risk management (Art. 5–16)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Art. 5 — Governance](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-5-governance-and-organisation.md): Article 5 — Governance and organisation of Regulation (EU) 2022/2554 (DORA).
- [Art. 6 — ICT risk framework](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-6-ict-risk-management-framework.md): Article 6 — ICT risk management framework of Regulation (EU) 2022/2554 (DORA).
- [Art. 7 — ICT systems, protocols, tools](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-7-ict-systems-protocols-and-tools.md): Article 7 — ICT systems, protocols and tools of Regulation (EU) 2022/2554 (DORA).
- [Art. 8 — Identification](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-8-identification.md): Article 8 — Identification of Regulation (EU) 2022/2554 (DORA).
- [Art. 9 — Protection and prevention](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-9-protection-and-prevention.md): Article 9 — Protection and prevention of Regulation (EU) 2022/2554 (DORA).
- [Art. 10 — Detection](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-10-detection.md): Article 10 — Detection of Regulation (EU) 2022/2554 (DORA).
- [Art. 11 — Response and recovery](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery.md): Article 11 — Response and recovery of Regulation (EU) 2022/2554 (DORA).
- [Art. 12 — Backup & restoration](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-12-backup-policies-and-procedures.md): Article 12 — Backup policies and procedures, restoration and recovery procedures and methods of Regulation (EU) 2022/2554 (DORA).
- [Art. 13 — Learning and evolving](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-13-learning-and-evolving.md): Article 13 — Learning and evolving of Regulation (EU) 2022/2554 (DORA).
- [Art. 14 — Communication](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-14-communication.md): Article 14 — Communication of Regulation (EU) 2022/2554 (DORA).
- [Art. 15 — Further harmonisation](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-15-further-harmonisation.md): Article 15 — Further harmonisation of ICT risk management tools, methods, processes and policies of Regulation (EU) 2022/2554 (DORA).
- [Art. 16 — Simplified ICT risk framework](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-16-simplified-ict-risk-management-framework.md): Article 16 — Simplified ICT risk management framework of Regulation (EU) 2022/2554 (DORA).
- [Chapter III — Incident reporting (Art. 17–23)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Art. 17 — Incident management process](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-17-ict-related-incident-management-process.md): Article 17 — ICT-related incident management process of Regulation (EU) 2022/2554 (DORA).
- [Art. 18 — Classification of incidents](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-18-classification-of-ict-related-incidents.md): Article 18 — Classification of ICT-related incidents and cyber threats of Regulation (EU) 2022/2554 (DORA).
- [Art. 19 — Reporting major incidents](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-19-reporting-of-major-incidents.md): Article 19 — Reporting of major ICT-related incidents and voluntary notification of significant cyber threats of Regulation (EU) 2022/2554 (DORA).
- [Art. 20 — Harmonisation of reporting](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-20-harmonisation-of-reporting-content-and-templates.md): Article 20 — Harmonisation of reporting content and templates of Regulation (EU) 2022/2554 (DORA).
- [Art. 21 — Centralisation of reporting](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-21-centralisation-of-reporting.md): Article 21 — Centralisation of reporting of major ICT-related incidents of Regulation (EU) 2022/2554 (DORA).
- [Art. 22 — Supervisory feedback](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-22-supervisory-feedback.md): Article 22 — Supervisory feedback of Regulation (EU) 2022/2554 (DORA).
- [Art. 23 — Payment-related incidents](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-23-payment-related-incidents.md): Article 23 — Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions of Regulat
- [Chapter IV — DOR testing (Art. 24–27)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iv-digital-operational-resilience-testing.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Art. 24 — General testing requirements](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iv-digital-operational-resilience-testing/article-24-general-requirements-for-testing.md): Article 24 — General requirements for the performance of digital operational resilience testing of Regulation (EU) 2022/2554 (DORA).
- [Art. 25 — Testing ICT tools & systems](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iv-digital-operational-resilience-testing/article-25-testing-of-ict-tools-and-systems.md): Article 25 — Testing of ICT tools and systems of Regulation (EU) 2022/2554 (DORA).
- [Art. 26 — Advanced testing (TLPT)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iv-digital-operational-resilience-testing/article-26-advanced-testing-tlpt.md): Article 26 — Advanced testing of ICT tools, systems and processes based on TLPT of Regulation (EU) 2022/2554 (DORA).
- [Art. 27 — Requirements for testers](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iv-digital-operational-resilience-testing/article-27-requirements-for-testers.md): Article 27 — Requirements for testers for the carrying out of TLPT of Regulation (EU) 2022/2554 (DORA).
- [Chapter V — ICT third-party risk (Art. 28–44)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Art. 28 — General principles](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-28-general-principles.md): Article 28 — General principles of Regulation (EU) 2022/2554 (DORA).
- [Art. 29 — Concentration risk assessment](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-29-preliminary-assessment-of-concentration-risk.md): Article 29 — Preliminary assessment of ICT concentration risk at entity level of Regulation (EU) 2022/2554 (DORA).
- [Art. 30 — Key contractual provisions](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-30-key-contractual-provisions.md): Article 30 — Key contractual provisions of Regulation (EU) 2022/2554 (DORA).
- [Art. 31 — Designation as critical](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-31-designation-of-critical-providers.md): Article 31 — Designation of critical ICT third-party service providers of Regulation (EU) 2022/2554 (DORA).
- [Art. 32 — Oversight Framework structure](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-32-structure-of-oversight-framework.md): Article 32 — Structure of the Oversight Framework of Regulation (EU) 2022/2554 (DORA).
- [Art. 33 — Lead Overseer tasks](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-33-tasks-of-the-lead-overseer.md): Article 33 — Tasks of the Lead Overseer of Regulation (EU) 2022/2554 (DORA).
- [Art. 34 — Lead Overseer coordination](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-34-operational-coordination.md): Article 34 — Operational coordination between Lead Overseers of Regulation (EU) 2022/2554 (DORA).
- [Art. 35 — Lead Overseer powers](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-35-powers-of-the-lead-overseer.md): Article 35 — Powers of the Lead Overseer of Regulation (EU) 2022/2554 (DORA).
- [Art. 36 — Powers outside the Union](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-36-powers-outside-the-union.md): Article 36 — Exercise of the powers of the Lead Overseer outside the Union of Regulation (EU) 2022/2554 (DORA).
- [Art. 37 — Request for information](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-37-request-for-information.md): Article 37 — Request for information of Regulation (EU) 2022/2554 (DORA).
- [Art. 38 — General investigations](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-38-general-investigations.md): Article 38 — General investigations of Regulation (EU) 2022/2554 (DORA).
- [Art. 39 — Inspections](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-39-inspections.md): Article 39 — Inspections of Regulation (EU) 2022/2554 (DORA).
- [Art. 40 — Ongoing oversight](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-40-ongoing-oversight.md): Article 40 — Ongoing oversight of Regulation (EU) 2022/2554 (DORA).
- [Article 41 — Harmonisation of conditions enabling the conduct of the oversight activities](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-41-harmonisation-of-conditions-enabling-the-conduct-of-the-oversight-activities.md): Article 41 — Harmonisation of conditions enabling the conduct of the oversight activities of Regulation (EU) 2022/2554 (DORA).
- [Article 42 — Follow-up by competent authorities](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-42-follow-up-by-competent-authorities.md): Article 42 — Follow-up by competent authorities of Regulation (EU) 2022/2554 (DORA).
- [Article 43 — Oversight fees](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-43-oversight-fees.md): Article 43 — Oversight fees of Regulation (EU) 2022/2554 (DORA).
- [Article 44 — International cooperation](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-v-managing-ict-third-party-risk/article-44-international-cooperation.md): Article 44 — International cooperation of Regulation (EU) 2022/2554 (DORA).
- [Chapter VI — Information sharing (Art. 45)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vi-information-sharing-arrangements.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Article 45 — Information-sharing arrangements on cyber threat information and intelligence](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vi-information-sharing-arrangements/article-45-information-sharing-arrangements-on-cyber-threat-information-and-intelligence.md): Article 45 — Information-sharing arrangements on cyber threat information and intelligence of Regulation (EU) 2022/2554 (DORA).
- [Chapter VII — Competent authorities (Art. 46–56)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Article 46 — Competent authorities](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-46-competent-authorities.md): Article 46 — Competent authorities of Regulation (EU) 2022/2554 (DORA).
- [Article 47 — Cooperation with structures and authorities established by Directive (EU) 2022/2555](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-47-cooperation-with-structures-and-authorities-established-by-directive-eu-2022-2555.md): Article 47 — Cooperation with structures and authorities established by Directive (EU) 2022/2555 of Regulation (EU) 2022/2554 (DORA).
- [Article 48 — Cooperation between authorities](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-48-cooperation-between-authorities.md): Article 48 — Cooperation between authorities of Regulation (EU) 2022/2554 (DORA).
- [Article 49 — Financial cross-sector exercises, communication and cooperation](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-49-financial-cross-sector-exercises-communication-and-cooperation.md): Article 49 — Financial cross-sector exercises, communication and cooperation of Regulation (EU) 2022/2554 (DORA).
- [Article 50 — Administrative penalties and remedial measures](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-50-administrative-penalties-and-remedial-measures.md): Article 50 — Administrative penalties and remedial measures of Regulation (EU) 2022/2554 (DORA).
- [Article 51 — Exercise of the power to impose administrative penalties and remedial measures](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-51-exercise-of-the-power-to-impose-administrative-penalties-and-remedial-measures.md): Article 51 — Exercise of the power to impose administrative penalties and remedial measures of Regulation (EU) 2022/2554 (DORA).
- [Article 52 — Criminal penalties](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-52-criminal-penalties.md): Article 52 — Criminal penalties of Regulation (EU) 2022/2554 (DORA).
- [Article 53 — Notification duties](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-53-notification-duties.md): Article 53 — Notification duties of Regulation (EU) 2022/2554 (DORA).
- [Article 54 — Publication of administrative penalties](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-54-publication-of-administrative-penalties.md): Article 54 — Publication of administrative penalties of Regulation (EU) 2022/2554 (DORA).
- [Article 55 — Professional secrecy](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-55-professional-secrecy.md): Article 55 — Professional secrecy of Regulation (EU) 2022/2554 (DORA).
- [Article 56 — Data Protection](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-vii-competent-authorities/article-56-data-protection.md): Article 56 — Data Protection of Regulation (EU) 2022/2554 (DORA).
- [Chapter VIII — Delegated acts (Art. 57)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-viii-delegated-acts.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Article 57 — Exercise of the delegation](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-viii-delegated-acts/article-57-exercise-of-the-delegation.md): Article 57 — Exercise of the delegation of Regulation (EU) 2022/2554 (DORA).
- [Chapter IX — Transitional & final (Art. 58–64)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions.md): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
- [Article 58 — Review clause](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-58-review-clause.md): Article 58 — Review clause of Regulation (EU) 2022/2554 (DORA).
- [Article 59 — Amendments to Regulation (EC) No 1060/2009](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-59-amendments-to-regulation-ec-no-1060-2009.md): Article 59 — Amendments to Regulation (EC) No 1060/2009 of Regulation (EU) 2022/2554 (DORA).
- [Article 60 — Amendments to Regulation (EU) No 648/2012](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-60-amendments-to-regulation-eu-no-648-2012.md): Article 60 — Amendments to Regulation (EU) No 648/2012 of Regulation (EU) 2022/2554 (DORA).
- [Article 61 — Amendments to Regulation (EU) No 909/2014](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-61-amendments-to-regulation-eu-no-909-2014.md): Article 61 — Amendments to Regulation (EU) No 909/2014 of Regulation (EU) 2022/2554 (DORA).
- [Article 62 — Amendments to Regulation (EU) No 600/2014](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-62-amendments-to-regulation-eu-no-600-2014.md): Article 62 — Amendments to Regulation (EU) No 600/2014 of Regulation (EU) 2022/2554 (DORA).
- [Article 63 — Amendment to Regulation (EU) 2016/1011](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-63-amendment-to-regulation-eu-2016-1011.md): Article 63 — Amendment to Regulation (EU) 2016/1011 of Regulation (EU) 2022/2554 (DORA).
- [Article 64 — Entry into force and application](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ix-transitional-and-final-provisions/article-64-entry-into-force-and-application.md): Article 64 — Entry into force and application of Regulation (EU) 2022/2554 (DORA).
- [Level 2](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards.md)
- [RTS](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts.md)
- [2024/1502 - Critical ICT Providers](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2024-1502-critical-ict-third-party-providers.md): Commission regulatory technical standard specifying criteria for designating ICT third-party service providers as critical under DORA.
- [2024/1505 - ICT Oversight Fees](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2024-1505-ict-third-party-oversight-fees.md): Commission delegated regulation determining oversight fees for critical ICT third-party service providers under DORA.
- [2024/1772 - ICT Incident Classification](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2024-1772-ict-incident-classification.md): Commission regulatory technical standard on ICT-related incident classification, materiality thresholds and major-incident report details under DORA.
- [2024/1773 - ICT Third-Party Risk Policy](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2024-1773-ict-third-party-risk-policy.md): Commission regulatory technical standard specifying the detailed content of the ICT third-party risk policy under DORA.
- [2024/1774 - ICT Risk Framework](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2024-1774-ict-risk-management-framework.md): Commission regulatory technical standard specifying ICT risk-management tools, methods, processes and policies, including the simplified framework under DORA.
- [2025/295 - Oversight Activities](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2025-295-oversight-activities.md): Commission regulatory technical standard on harmonised conditions enabling oversight activities under DORA.
- [2025/301 - Major ICT Incident Reporting](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2025-301-major-ict-incident-reporting.md): Commission regulatory technical standard specifying content and time limits for DORA major ICT-related incident reports and significant-cyber-threat notifications.
- [2025/420 - Joint Examination Team](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2025-420-joint-examination-team.md): Commission regulatory technical standard on joint examination team composition, designation, tasks and working arrangements under DORA.
- [2025/532 - ICT Subcontracting](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2025-532-ict-subcontracting.md): Commission regulatory technical standard on the elements financial entities must determine and assess when subcontracting ICT services supporting critical or important functions under DORA.
- [2025/1190 - TLPT](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/rts/2025-1190-tlpt.md): Commission regulatory technical standard specifying DORA threat-led penetration testing criteria, tester requirements, methodology, results, closure and mutual-recognition cooperation.
- [ITS](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/its.md)
- [2024/2956 - Register of Information Templates](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/its/2024-2956-register-of-information-templates.md): Commission implementing technical standard laying down standard templates for the register of information under DORA.
- [2025/302 - Major Incident Templates](https://www.mica.wtf/dora/digital-operational-resilience-act/technical-standards/its/2025-302-major-incident-reporting-templates.md): Commission implementing technical standard laying down forms, templates and procedures for DORA major ICT-related incident reports and significant-cyber-threat notifications.
- [Guidelines](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines.md)
- [EBA/GL/2017/05 — Guidelines on ICT Risk Assessment under the SREP](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines/eba-gl-2017-05-ict-risk-srep.md): EBA guideline on DORA: Guidelines on ICT Risk Assessment under the SREP.
- [EBA/GL/2019/02 — Guidelines on outsourcing arrangements](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines/eba-gl-2019-02-outsourcing-arrangements.md): EBA guideline on DORA: Guidelines on outsourcing arrangements.
- [EBA/GL/2025/02 — Guidelines amending Guidelines EBA/GL/2019/04 o...](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines/eba-gl-2025-02-amend-ict-security-risk.md): EBA guideline on DORA: Guidelines amending Guidelines EBA/GL/2019/04 on ICT and security risk management.
- [JC/GL/2024/34 — Joint Guidelines on the estimation of aggregate...](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines/jc-gl-2024-34-costs-losses.md): Joint (ESAs) guideline on DORA: Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents.
- [JC/GL/2024/36 — Joint Guidelines on the oversight cooperation a...](https://www.mica.wtf/dora/digital-operational-resilience-act/guidelines/jc-gl-2024-36-oversight-cooperation.md): Joint (ESAs) guideline on DORA: Joint Guidelines on the oversight cooperation and information exchange between the ESAs and the competent authorities.
- [Q\&As](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a.md)
- [Critical Services Affected](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7047-critical-services-affected.md): EBA Q\&A 2024\_7047 on Regulation (EU) 2022/2554 (DORA): Critical Services Affected.
- [Duplicate ICT Incident Reporting](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7050-duplicate-ict-incident-reporting.md): EBA Q\&A 2024\_7050 on Regulation (EU) 2022/2554 (DORA): Duplicate ICT Incident Reporting.
- [Exemption for Non-EU ICT Intra-group Service Providers](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7096-exemption-for-non-eu-ict-intra-group-service-providers.md): EBA Q\&A 2024\_7096 on Regulation (EU) 2022/2554 (DORA): Exemption for Non-EU ICT Intra-group Service Providers.
- [Scope of Register of Information for Contractual Arrangem...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7098-scope-of-register-of-information-for-contractual-arrangement.md): EBA Q\&A 2024\_7098 on Regulation (EU) 2022/2554 (DORA): Scope of Register of Information for Contractual Arrangements on the use of ICT Services Provided by ICT Third-party Service Providers.
- [Elaboration on the meaning of a separated and dedicated n...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7178-elaboration-on-the-meaning-of-a-separated-and-dedicated-netw.md): EBA Q\&A 2024\_7178 on Regulation (EU) 2022/2554 (DORA): Elaboration on the meaning of a separated and dedicated network for ICT asset administration.
- [Template specific instructions – field B\_01.02.0050 (Hier...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7277-template-specific-instructions-field-b-01-02-0050-hierarchy.md): EBA Q\&A 2024\_7277 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_01.02.0050 (Hierarchy of the financial entity within the group).
- [Template specific instructions - field B\_01.02.0060 (LEI ...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7278-template-specific-instructions-field-b-01-02-0060-lei-of-the.md): EBA Q\&A 2024\_7278 on Regulation (EU) 2022/2554 (DORA): Template specific instructions - field B\_01.02.0060 (LEI of the direct parent undertaking of the financial entity).
- [Template specific instructions – field B\_02.02.0130 (Coun...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7279-template-specific-instructions-field-b-02-02-0130-country-of.md): EBA Q\&A 2024\_7279 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_02.02.0130 (Country of the governing law of the contractual arrangement).
- [Template specific instructions – field B\_02.02.0160 (Loca...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7281-template-specific-instructions-field-b-02-02-0160-location-o.md): EBA Q\&A 2024\_7281 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_02.02.0160 (Location of management of the data).
- [Template specific instructions – field B\_04.01.0040 (Iden...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7282-template-specific-instructions-field-b-04-01-0040-identifica.md): EBA Q\&A 2024\_7282 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_04.01.0040 (Identification code of the branch).
- [Template specific instructions – field B\_05.01.0020 (Type...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7283-template-specific-instructions-field-b-05-01-0020-type-of-co.md): EBA Q\&A 2024\_7283 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_05.01.0020 (Type of code to identify the ICT third-party service provider).
- [Template specific instructions – field B\_05.02.0060 (Iden...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7284-template-specific-instructions-field-b-05-02-0060-identifica.md): EBA Q\&A 2024\_7284 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – field B\_05.02.0060 (Identification code of the recipient of sub-contracted ICT services).
- [Template specific instructions – primary keys](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7285-template-specific-instructions-primary-keys.md): EBA Q\&A 2024\_7285 on Regulation (EU) 2022/2554 (DORA): Template specific instructions – primary keys.
- [Definition and scope of ICT services](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2024-7290-definition-and-scope-of-ict-services.md): EBA Q\&A 2024\_7290 on Regulation (EU) 2022/2554 (DORA): Definition and scope of ICT services.
- [The scope of the regulation described in Article 6 mismat...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7297-the-scope-of-the-regulation-described-in-article-6-mismatche.md): EBA Q\&A 2025\_7297 on Regulation (EU) 2022/2554 (DORA): The scope of the regulation described in Article 6 mismatches what is presented as an option in the Annex I, Part 2 of the same regulation.
- [ANNUAL REPORT ON NEW ARRANGEMENTS ON THE USE OF ICT SERVICES](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7309-annual-report-on-new-arrangements-on-the-use-of-ict-services.md): EBA Q\&A 2025\_7309 on Regulation (EU) 2022/2554 (DORA): ANNUAL REPORT ON NEW ARRANGEMENTS ON THE USE OF ICT SERVICES.
- [Part 2 – Template specific instructions to template B\_06.01](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7313-part-2-template-specific-instructions-to-template-b-06-01.md): EBA Q\&A 2025\_7313 on Regulation (EU) 2022/2554 (DORA): Part 2 – Template specific instructions to template B\_06.01.
- [How to fill the refPeriod field of the parameters.csv fil...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7387-how-to-fill-the-refperiod-field-of-the-parameters-csv-file-f.md): EBA Q\&A 2025\_7387 on Regulation (EU) 2022/2554 (DORA): How to fill the refPeriod field of the parameters.csv file for the DORA register of information.
- [Obligation to maintain a register of information for FEs ...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7388-obligation-to-maintain-a-register-of-information-for-fes-exe.md): EBA Q\&A 2025\_7388 on Regulation (EU) 2022/2554 (DORA): Obligation to maintain a register of information for FEs exempt under article 16.
- [Staff costs](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7439-staff-costs.md): EBA Q\&A 2025\_7439 on Regulation (EU) 2022/2554 (DORA): Staff costs.
- [Public Authorities Exemption](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7466-public-authorities-exemption.md): EBA Q\&A 2025\_7466 on Regulation (EU) 2022/2554 (DORA): Public Authorities Exemption.
- [Types of 'telephone services' included under the definiti...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7539-types-of-telephone-services-included-under-the-definition-of.md): EBA Q\&A 2025\_7539 on Regulation (EU) 2022/2554 (DORA): Types of 'telephone services' included under the definition of 'ICT services'.
- [Classification of phishing-attacks as a reportable major ...](https://www.mica.wtf/dora/digital-operational-resilience-act/q-and-a/eba-qa-2025-7613-classification-of-phishing-attacks-as-a-reportable-major-ict.md): EBA Q\&A 2025\_7613 on Regulation (EU) 2022/2554 (DORA): Classification of phishing-attacks as a reportable major ICT-related incident.
- [Soft law](https://www.mica.wtf/dora/digital-operational-resilience-act/soft-law.md)
- [Opinions](https://www.mica.wtf/dora/digital-operational-resilience-act/soft-law/opinions.md)
- [JC/2024/75 — Opinion of the ESAs on the rejection of the ITS...](https://www.mica.wtf/dora/digital-operational-resilience-act/soft-law/opinions/jc-2024-75-opinion-its-roi.md): Joint (ESAs) opinion on DORA: Opinion of the ESAs on the rejection of the ITS on the Register of Information under DORA.
- [JC/2025/06 — ESAs Joint Committee Opinion on the rejection o...](https://www.mica.wtf/dora/digital-operational-resilience-act/soft-law/opinions/jc-2025-06-opinion-rts-subcontracting.md): Joint (ESAs) opinion on DORA: ESAs Joint Committee Opinion on the rejection of the RTS on subcontracting under DORA.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.mica.wtf/dora/digital-operational-resilience-act.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
