{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/dora",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/dora)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-09-29",
    "fingerprint": "ewai:eu:23b344",
    "proof": "sha256:6f42815284d46a3fba1188af3ae37ddf32fed5ce0fdb2759c42a4c91390f6be1",
    "jurisdiction": "eu",
    "lang": "en"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "id": "topic:eu:dora",
  "object_type": "topic",
  "schema_version": "1",
  "jurisdiction": "eu",
  "title": "DORA, digital operativ motståndskraft",
  "title_en": "DORA, digital operational resilience",
  "short_answer": "Finansiella företag måste hantera IT-risker, rapportera allvarliga IT-incidenter, testa sin motståndskraft och styra sina IT-leverantörer med avtal.",
  "short_answer_en": "Financial entities must manage ICT risk, report major ICT incidents, test resilience and govern ICT providers by contract.",
  "applies": "Gäller sedan 17 januari 2025.",
  "law": {
    "title": "Förordning (EU) 2022/2554",
    "celex": "32022R2554",
    "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2554",
    "act_url": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554"
  },
  "chain": {
    "elements": [
      {
        "id": "topic:eu:dora#element-1",
        "label": "Finansiellt företag (banker, försäkring, betalning, kryptotjänster m.fl.)"
      },
      {
        "id": "topic:eu:dora#element-2",
        "label": "IT-tjänst från tredje part"
      },
      {
        "id": "topic:eu:dora#element-3",
        "label": "Allvarlig IT-relaterad incident"
      }
    ],
    "obligations": [
      {
        "id": "topic:eu:dora#obligation-1",
        "duty": "Ha ett ramverk för IT-riskhantering som ledningen ansvarar för",
        "article": "art. 5–6",
        "source": "art. 5–6 Förordning (EU) 2022/2554"
      },
      {
        "id": "topic:eu:dora#obligation-2",
        "duty": "Rapportera allvarliga IT-incidenter till tillsynsmyndigheten",
        "article": "art. 19",
        "source": "art. 19 Förordning (EU) 2022/2554"
      },
      {
        "id": "topic:eu:dora#obligation-3",
        "duty": "Testa den digitala motståndskraften, avancerade företag med hotbaserade tester vart tredje år",
        "article": "art. 24–26",
        "source": "art. 24–26 Förordning (EU) 2022/2554"
      },
      {
        "id": "topic:eu:dora#obligation-4",
        "duty": "Föra register över alla avtal med IT-leverantörer och ta in obligatoriska avtalsvillkor",
        "article": "art. 28–30",
        "source": "art. 28–30 Förordning (EU) 2022/2554"
      }
    ],
    "sanction": {
      "id": "topic:eu:dora#sanction-1",
      "text": "Medlemsstaterna fastställer sanktioner. Kritiska IT-leverantörer kan få vite på upp till 1 % av den genomsnittliga dagliga globala omsättningen.",
      "article": "art. 50, 35"
    },
    "compliance": [
      "Ramverk för IT-risk antaget av styrelsen",
      "Rutin för incidentrapportering",
      "Testprogram",
      "Register över IT-avtal",
      "Avtal uppfyller art. 30"
    ]
  },
  "next_questions": [
    {
      "id": "topic:eu:dora#q:vilka-omfattas-av-dora",
      "question": "Vilka omfattas av DORA?",
      "answer": "Nästan alla finansiella företag i EU: banker, försäkringsbolag, betalinstitut, värdepappersföretag, fondbolag och kryptotjänster, samt kritiska IT-leverantörer.",
      "question_en": "Who is covered by DORA?",
      "answer_en": "Almost all EU financial entities: banks, insurers, payment institutions, investment firms, fund managers and crypto providers, plus critical ICT providers.",
      "url": "https://legal.exploreworldai.com/eu/amne/dora/vilka-omfattas-av-dora",
      "leads_to": null
    },
    {
      "id": "topic:eu:dora#q:vad-kraver-artikel-30",
      "question": "Vad kräver artikel 30 i avtal med IT-leverantörer?",
      "answer": "Avtalet ska bland annat beskriva tjänsterna, var data behandlas, servicenivåer, incidenthjälp, revisionsrätt, uppsägningsrätt och en exitstrategi.",
      "question_en": "What does Article 30 require in ICT contracts?",
      "answer_en": "The contract must cover service descriptions, data location, service levels, incident assistance, audit rights, termination rights and an exit strategy.",
      "url": "https://legal.exploreworldai.com/eu/amne/dora/vad-kraver-artikel-30",
      "leads_to": null
    },
    {
      "id": "topic:eu:dora#q:hur-snabbt-rapporteras-en-incident",
      "question": "Hur snabbt ska en IT-incident rapporteras?",
      "answer": "Första anmälan inom 4 timmar efter klassificering och senast 24 timmar efter upptäckt, mellanrapport inom 72 timmar och slutrapport inom en månad.",
      "question_en": "How fast must an ICT incident be reported?",
      "answer_en": "Initial notification within 4 hours of classification and at most 24 hours of detection, intermediate report within 72 hours, final report within one month.",
      "url": "https://legal.exploreworldai.com/eu/amne/dora/hur-snabbt-rapporteras-en-incident",
      "leads_to": "topic:eu:nis2"
    }
  ],
  "edges": [
    {
      "type": "related",
      "to": "topic:eu:nis2",
      "url": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/nis2"
    },
    {
      "type": "related",
      "to": "topic:eu:mica",
      "url": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/mica"
    },
    {
      "type": "related",
      "to": "topic:eu:aml",
      "url": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/aml"
    },
    {
      "type": "next_question",
      "to": "topic:eu:nis2",
      "via": "How fast must an ICT incident be reported?",
      "url": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/nis2"
    }
  ],
  "sha256": "cb98ffe0ccb864c62370441c65a4aa8ac6b25ebb8ce47d6023faac8a7f6fba1c",
  "page": "https://legal.exploreworldai.com/eu/amne/dora",
  "permanent_url": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/dora",
  "ask": "https://legal.exploreworldai.com/api/public/v1/agent/ask?q=Who%20is%20covered%20by%20DORA%3F",
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "recheck_after_seconds": 86400,
    "how": "Send If-None-Match with the ETag; unchanged returns 304."
  },
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "source": "NovaCopilot",
  "hash": "sha256:6f42815284d46a3fba1188af3ae37ddf32fed5ce0fdb2759c42a4c91390f6be1",
  "version": "legal-2026-09-29",
  "expires": "2026-10-01T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-09-29+legal-2026-09-29+2026-09-29T21:40:00",
    "content_hash": "sha256:6f42815284d46a3fba1188af3ae37ddf32fed5ce0fdb2759c42a4c91390f6be1",
    "revalidate_after": "2026-09-30T03:44:25.835Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/topic-graph/eu/dora",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}