Agent · dora-2022-2554-13
DORA artikel 13: Learning and evolving
Strukturelt tre: artikkelens egne punkter, ordrett.
CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- Hva siden er
- Agent, DORA artikel 13
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does DORA Article 13 require, and what outcome does the rule tree give?
DORA Article 13 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022R2554. The outcome is a machine classification, not a compliance decision.
DORA Article 13Lest mot utgiveren 2026-08-18Offisiell tekst
- Paragraph 1 applies. 1. Financial entities shall have in place capabilities and staff to gather information on vulnerabilities and cyber threats, ICT-related incidents, in particular cyber-attacks, and analyse the impact they are likely to have on their digital operational resilience.
- Paragraph 2 applies. 2. Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activities, analysing the causes of disruption and identifying required improvements to the ICT operations or within the ICT business continuity policy referred to in Article 11.
- Paragraph 3 applies. Financial entities, other than microenterprises, shall, upon request, communicate to the competent authorities, the changes that were implemented following post ICT-related incident reviews as referred to in the first subparagraph.
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Regeltre
Hvis: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. Financial entities shall have in place capabilities and staff to gather information on vulnerabilities and cyber threats, ICT-related incidents, in particular cyber-attacks, and analyse the impact they are likely to have on their digital operational resilience.
Punkt 1
Hvis: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activities, analysing the causes of disruption and identifying required improvements to the ICT operations or within the ICT business continuity policy referred to in Article 11.
Punkt 2
Hvis: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
Financial entities, other than microenterprises, shall, upon request, communicate to the competent authorities, the changes that were implemented following post ICT-related incident reviews as referred to in the first subparagraph.
Punkt 3
Hvis: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
The post ICT-related incident reviews referred to in the first subparagraph shall determine whether the established procedures were followed and the actions taken were effective, including in relation to the following:
Punkt 4
Hvis: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(a)
Punkt 5
Hvis: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
the promptness in responding to security alerts and determining the impact of ICT-related incidents and their severity;
Punkt 6
Hvis: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(b)
Punkt 7
Hvis: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
the quality and speed of performing a forensic analysis, where deemed appropriate;
Punkt 8
Hvis: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(c)
Punkt 9
Hvis: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
the effectiveness of incident escalation within the financial entity;
Punkt 10
Hvis: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(d)
Punkt 11
Hvis: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
the effectiveness of internal and external communication.
Punkt 12
Hvis: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
3. Lessons derived from the digital operational resilience testing carried out in accordance with Articles 26 and 27 and from real life ICT-related incidents, in particular cyber-attacks, along with challenges faced upon the activation of ICT business continuity plans and ICT response and recovery plans, together with relevant information exchanged with counterparts and assessed during supervisory reviews, shall be d…
Punkt 13
Hvis: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
4. Financial entities shall monitor the effectiveness of the implementation of their digital operational resilience strategy set out in Article 6(8). They shall map the evolution of ICT risk over time, analyse the frequency, types, magnitude and evolution of ICT-related incidents, in particular cyber-attacks and their patterns, with a view to understanding the level of ICT risk exposure, in particular in relation to…
Punkt 14
Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
Artikkelteksten som ble lest
- 11. Financial entities shall have in place capabilities and staff to gather information on vulnerabilities and cyber threats, ICT-related incidents, in particular cyber-attacks, and analyse the impact they are likely to have on their digital operational resilience.
- 22. Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activities, analysing the causes of disruption and identifying required improvements to the ICT operations or within the ICT business continuity policy referred to in Article 11.
- 3Financial entities, other than microenterprises, shall, upon request, communicate to the competent authorities, the changes that were implemented following post ICT-related incident reviews as referred to in the first subparagraph.
- 4The post ICT-related incident reviews referred to in the first subparagraph shall determine whether the established procedures were followed and the actions taken were effective, including in relation to the following:
- 5(a)
- 6the promptness in responding to security alerts and determining the impact of ICT-related incidents and their severity;
- 7(b)
- 8the quality and speed of performing a forensic analysis, where deemed appropriate;
- 9(c)
- 10the effectiveness of incident escalation within the financial entity;
- 11(d)
- 12the effectiveness of internal and external communication.
- 133. Lessons derived from the digital operational resilience testing carried out in accordance with Articles 26 and 27 and from real life ICT-related incidents, in particular cyber-attacks, along with challenges faced upon the activation of ICT business continuity plans and ICT response and recovery plans, together with relevant information exchanged with counterparts and assessed during supervisory reviews, shall be duly incorporated on a continuous basis into the ICT risk assessment process. Those findings shall form the basis for appropriate reviews of relevant components of the ICT risk management framework referred to in Article 6(1).
- 144. Financial entities shall monitor the effectiveness of the implementation of their digital operational resilience strategy set out in Article 6(8). They shall map the evolution of ICT risk over time, analyse the frequency, types, magnitude and evolution of ICT-related incidents, in particular cyber-attacks and their patterns, with a view to understanding the level of ICT risk exposure, in particular in relation to critical or important functions, and enhance the cyber maturity and preparedness of the financial entity.
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32022R2554 art. 13, Learning and evolving. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-13 (hämtad 2026-08-18, bevis sha256:01723f2241f4cf9c, bygge legal-2026-08-25).