Agent · dora-2022-2554-11
DORA artikel 11: Response and recovery
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, DORA artikel 11
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does DORA Article 11 require, and what outcome does the rule tree give?
DORA Article 11 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022R2554. The outcome is a machine classification, not a compliance decision.
DORA Article 11Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. As part of the ICT risk management framework referred to in Article 6(1) and based on the identification requirements set out in Article 8, financial entities shall put in place a comprehensive ICT business continuity policy, which may be adopted as a dedicated specific policy, forming an integral part of the overall business continuity policy of the financial entity.
- Paragraph 2 applies. 2. Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms aiming to:
- Paragraph 3 applies. (a)
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. As part of the ICT risk management framework referred to in Article 6(1) and based on the identification requirements set out in Article 8, financial entities shall put in place a comprehensive ICT business continuity policy, which may be adopted as a dedicated specific policy, forming an integral part of the overall business continuity policy of the financial entity.
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms aiming to:
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
ensure the continuity of the financial entity’s critical or important functions;
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
quickly, appropriately and effectively respond to, and resolve, all ICT-related incidents in a way that limits damage and prioritises the resumption of activities and recovery actions;
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(c)
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
activate, without delay, dedicated plans that enable containment measures, processes and technologies suited to each type of ICT-related incident and prevent further damage, as well as tailored response and recovery procedures established in accordance with Article 12;
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(d)
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
estimate preliminary impacts, damages and losses;
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(e)
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
set out communication and crisis management actions that ensure that updated information is transmitted to all relevant internal staff and external stakeholders in accordance with Article 14, and report to the competent authorities in accordance with Article 19.
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
3. As part of the ICT risk management framework referred to in Article 6(1), financial entities shall implement associated ICT response and recovery plans which, in the case of financial entities other than microenterprises, shall be subject to independent internal audit reviews.
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
4. Financial entities shall put in place, maintain and periodically test appropriate ICT business continuity plans, notably with regard to critical or important functions outsourced or contracted through arrangements with ICT third-party service providers.
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. As part of the ICT risk management framework referred to in Article 6(1) and based on the identification requirements set out in Article 8, financial entities shall put in place a comprehensive ICT business continuity policy, which may be adopted as a dedicated specific policy, forming an integral part of the overall business continuity policy of the financial entity.
- 22. Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms aiming to:
- 3(a)
- 4ensure the continuity of the financial entity’s critical or important functions;
- 5(b)
- 6quickly, appropriately and effectively respond to, and resolve, all ICT-related incidents in a way that limits damage and prioritises the resumption of activities and recovery actions;
- 7(c)
- 8activate, without delay, dedicated plans that enable containment measures, processes and technologies suited to each type of ICT-related incident and prevent further damage, as well as tailored response and recovery procedures established in accordance with Article 12;
- 9(d)
- 10estimate preliminary impacts, damages and losses;
- 11(e)
- 12set out communication and crisis management actions that ensure that updated information is transmitted to all relevant internal staff and external stakeholders in accordance with Article 14, and report to the competent authorities in accordance with Article 19.
- 133. As part of the ICT risk management framework referred to in Article 6(1), financial entities shall implement associated ICT response and recovery plans which, in the case of financial entities other than microenterprises, shall be subject to independent internal audit reviews.
- 144. Financial entities shall put in place, maintain and periodically test appropriate ICT business continuity plans, notably with regard to critical or important functions outsourced or contracted through arrangements with ICT third-party service providers.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022R2554 art. 11, Response and recovery. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-11 (hämtad 2026-08-18, bevis sha256:a8ccf9615ba85b42, bygge legal-2026-08-25).