Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · DORA

Article 18Classification of ICT-related incidents and cyber threats

CELEX 32022R2554 · Read on 2026-08-18

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:

(a)

the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;

(b)

the duration of the ICT-related incident, including the service downtime;

(c)

the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;

(d)

the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality of data;

(e)

the criticality of the services affected, including the financial entity’s transactions and operations;

(f)

the economic impact, in particular direct and indirect costs and losses, of the ICT-related incident in both absolute and relative terms.

2. Financial entities shall classify cyber threats as significant based on the criticality of the services at risk, including the financial entity’s transactions and operations, number and/or relevance of clients or financial counterparts targeted and the geographical spread of the areas at risk.

The article continues in the official text.

Open the article on EUR-Lex

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit