Agent · dora-2022-2554-15
DORA artikel 15: Further harmonisation of ICT risk management tools, methods, processes and policies
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, DORA artikel 15
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does DORA Article 15 require, and what outcome does the rule tree give?
DORA Article 15 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022R2554. The outcome is a machine classification, not a compliance decision.
DORA Article 15Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. The ESAs shall, through the Joint Committee, in consultation with the European Union Agency on Cybersecurity (ENISA), develop common draft regulatory technical standards in order to:
- Paragraph 2 applies. (a)
- Paragraph 3 applies. specify further elements to be included in the ICT security policies, procedures, protocols and tools referred to in Article 9(2), with a view to ensuring the security of networks, enable adequate safeguards against intrusions and data misuse, preserve the availability, authenticity, integrity and confidentiality of data, including cryptographic techniques, and guarantee an accurate and prompt data transmission witho…
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
The ESAs shall, through the Joint Committee, in consultation with the European Union Agency on Cybersecurity (ENISA), develop common draft regulatory technical standards in order to:
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
(a)
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
specify further elements to be included in the ICT security policies, procedures, protocols and tools referred to in Article 9(2), with a view to ensuring the security of networks, enable adequate safeguards against intrusions and data misuse, preserve the availability, authenticity, integrity and confidentiality of data, including cryptographic techniques, and guarantee an accurate and prompt data transmission witho…
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(b)
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
develop further components of the controls of access management rights referred to in Article 9(4), point (c), and associated human resource policy specifying access rights, procedures for granting and revoking rights, monitoring anomalous behaviour in relation to ICT risk through appropriate indicators, including for network use patterns, hours, IT activity and unknown devices;
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(c)
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
develop further the mechanisms specified in Article 10(1) enabling a prompt detection of anomalous activities and the criteria set out in Article 10(2) triggering ICT-related incident detection and response processes;
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
(d)
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
specify further the components of the ICT business continuity policy referred to in Article 11(1);
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
(e)
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
specify further the testing of ICT business continuity plans referred to in Article 11(6) to ensure that such testing duly takes into account scenarios in which the quality of the provision of a critical or important function deteriorates to an unacceptable level or fails, and duly considers the potential impact of the insolvency, or other failures, of any relevant ICT third-party service provider and, where relevant…
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
(f)
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
specify further the components of the ICT response and recovery plans referred to in Article 11(3);
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
(g)
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 1The ESAs shall, through the Joint Committee, in consultation with the European Union Agency on Cybersecurity (ENISA), develop common draft regulatory technical standards in order to:
- 2(a)
- 3specify further elements to be included in the ICT security policies, procedures, protocols and tools referred to in Article 9(2), with a view to ensuring the security of networks, enable adequate safeguards against intrusions and data misuse, preserve the availability, authenticity, integrity and confidentiality of data, including cryptographic techniques, and guarantee an accurate and prompt data transmission without major disruptions and undue delays;
- 4(b)
- 5develop further components of the controls of access management rights referred to in Article 9(4), point (c), and associated human resource policy specifying access rights, procedures for granting and revoking rights, monitoring anomalous behaviour in relation to ICT risk through appropriate indicators, including for network use patterns, hours, IT activity and unknown devices;
- 6(c)
- 7develop further the mechanisms specified in Article 10(1) enabling a prompt detection of anomalous activities and the criteria set out in Article 10(2) triggering ICT-related incident detection and response processes;
- 8(d)
- 9specify further the components of the ICT business continuity policy referred to in Article 11(1);
- 10(e)
- 11specify further the testing of ICT business continuity plans referred to in Article 11(6) to ensure that such testing duly takes into account scenarios in which the quality of the provision of a critical or important function deteriorates to an unacceptable level or fails, and duly considers the potential impact of the insolvency, or other failures, of any relevant ICT third-party service provider and, where relevant, the political risks in the respective providers’ jurisdictions;
- 12(f)
- 13specify further the components of the ICT response and recovery plans referred to in Article 11(3);
- 14(g)
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022R2554 art. 15, Further harmonisation of ICT risk management tools, methods, processes and policies. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-15 (hämtad 2026-08-18, bevis sha256:81b9657a41928cef, bygge legal-2026-08-25).