Agent · dora-2022-2554-18
DORA artikel 18: Classification of ICT-related incidents and cyber threats
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, DORA artikel 18
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does DORA Article 18 require, and what outcome does the rule tree give?
DORA Article 18 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022R2554. The outcome is a machine classification, not a compliance decision.
DORA Article 18Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:
- Paragraph 2 applies. (a)
- Paragraph 3 applies. the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
(a)
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(b)
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
the duration of the ICT-related incident, including the service downtime;
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(c)
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
(d)
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality of data;
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
(e)
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
the criticality of the services affected, including the financial entity’s transactions and operations;
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
(f)
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
the economic impact, in particular direct and indirect costs and losses, of the ICT-related incident in both absolute and relative terms.
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
2. Financial entities shall classify cyber threats as significant based on the criticality of the services at risk, including the financial entity’s transactions and operations, number and/or relevance of clients or financial counterparts targeted and the geographical spread of the areas at risk.
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:
- 2(a)
- 3the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;
- 4(b)
- 5the duration of the ICT-related incident, including the service downtime;
- 6(c)
- 7the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;
- 8(d)
- 9the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality of data;
- 10(e)
- 11the criticality of the services affected, including the financial entity’s transactions and operations;
- 12(f)
- 13the economic impact, in particular direct and indirect costs and losses, of the ICT-related incident in both absolute and relative terms.
- 142. Financial entities shall classify cyber threats as significant based on the criticality of the services at risk, including the financial entity’s transactions and operations, number and/or relevance of clients or financial counterparts targeted and the geographical spread of the areas at risk.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022R2554 art. 18, Classification of ICT-related incidents and cyber threats. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-18 (hämtad 2026-08-18, bevis sha256:5fdece7c7011e57c, bygge legal-2026-08-25).