Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Back to the act

EU regulatory register · DORA

Article 9Protection and prevention

CELEX 32022R2554 · Read on 2026-08-18

Official text

Read from the EU Publications Office for this CELEX number. The wording stands as published; nothing here is rewritten or summarised.

1. For the purposes of adequately protecting ICT systems and with a view to organising response measures, financial entities shall continuously monitor and control the security and functioning of ICT systems and tools and shall minimise the impact of ICT risk on ICT systems through the deployment of appropriate ICT security tools, policies and procedures.

2. Financial entities shall design, procure and implement ICT security policies, procedures, protocols and tools that aim to ensure the resilience, continuity and availability of ICT systems, in particular for those supporting critical or important functions, and to maintain high standards of availability, authenticity, integrity and confidentiality of data, whether at rest, in use or in transit.

3. In order to achieve the objectives referred to in paragraph 2, financial entities shall use ICT solutions and processes that are appropriate in accordance with Article 4. Those ICT solutions and processes shall:

(a)

ensure the security of the means of transfer of data;

(b)

minimise the risk of corruption or loss of data, unauthorised access and technical flaws that may hinder business activity;

(c)

prevent the lack of availability, the impairment of the authenticity and integrity, the breaches of confidentiality and the loss of data;

(d)

ensure that data is protected from risks arising from data management, including poor administration, processing-related risks and human error.

4. As part of the ICT risk management framework referred to in Article 6(1), financial entities shall:

(a)

develop and document an information security policy defining rules to protect the availability, authenticity, integrity and confidentiality of data, information assets and ICT assets, including those of their customers, where applicable;

The article continues in the official text.

Open the article on EUR-Lex

Related articles

Articles in other acts connected to this one, with the reason written against the text. The map is a route between acts, not an assessment.

  • Analogous to · mutualGDPR · 32

    Safeguards for processing meet safeguards for the ICT systems of a financial entity: the same kind of requirement, a different object of protection.

    CELEX 32016R0679 · 2026-08-18

The text is quoted from the official source and is not legal advice. A national court reads the language version that binds in its jurisdiction.

Verifiable trust signals

  • Six fixed blocks, one source per line
  • No sentence written by a language model
  • Engine version and read date on every answer
  • No customer data, no documents, no advice
  • Model card and audit published under the EU AI Act

Model cardAudit