Rättskällor med officiella primärkällor

Utskrivet ·

Hopp til innhold
Hopp til svaret

Agent · dora-2022-2554-18

DORA artikel 18: Classification of ICT-related incidents and cyber threats

Strukturelt tre: artikkelens egne punkter, ordrett.

CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOffisiell kilde

Hva siden er
Agent, DORA artikel 18
Lest mot offisiell kilde
2026-08-18Fersk
Ansvarlig utgiver
ExploreWorld Legal, redaksjonenAnsvarsposisjon

Jurisdiksjon

Samme agent, lest med ett lands øyne.

Inndata

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Regeltre

  1. Hvis: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:

    Punkt 1

  2. Hvis: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    (a)

    Punkt 2

  3. Hvis: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;

    Punkt 3

  4. Hvis: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    (b)

    Punkt 4

  5. Hvis: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    the duration of the ICT-related incident, including the service downtime;

    Punkt 5

  6. Hvis: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    (c)

    Punkt 6

  7. Hvis: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;

    Punkt 7

  8. Hvis: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    (d)

    Punkt 8

  9. Hvis: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality of data;

    Punkt 9

  10. Hvis: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    (e)

    Punkt 10

  11. Hvis: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    the criticality of the services affected, including the financial entity’s transactions and operations;

    Punkt 11

  12. Hvis: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    (f)

    Punkt 12

  13. Hvis: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    the economic impact, in particular direct and indirect costs and losses, of the ICT-related incident in both absolute and relative terms.

    Punkt 13

  14. Hvis: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    2. Financial entities shall classify cyber threats as significant based on the criticality of the services at risk, including the financial entity’s transactions and operations, number and/or relevance of clients or financial counterparts targeted and the geographical spread of the areas at risk.

    Punkt 14

Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

Artikkelteksten som ble lest

  1. 11. Financial entities shall classify ICT-related incidents and shall determine their impact based on the following criteria:
  2. 2(a)
  3. 3the number and/or relevance of clients or financial counterparts affected and, where applicable, the amount or number of transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact;
  4. 4(b)
  5. 5the duration of the ICT-related incident, including the service downtime;
  6. 6(c)
  7. 7the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;
  8. 8(d)
  9. 9the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality of data;
  10. 10(e)
  11. 11the criticality of the services affected, including the financial entity’s transactions and operations;
  12. 12(f)
  13. 13the economic impact, in particular direct and indirect costs and losses, of the ICT-related incident in both absolute and relative terms.
  14. 142. Financial entities shall classify cyber threats as significant based on the criticality of the services at risk, including the financial entity’s transactions and operations, number and/or relevance of clients or financial counterparts targeted and the geographical spread of the areas at risk.

Opphav

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article18
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Grensesnitt

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-18/run
methodGET
outputmatched, outcome, trace, missing, hash
Kvote60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hasher

textsha256:d2008e399573c907150fea74589122404dd5a38b1e3804ffafae14a15fb47607
scriptsha256:8cea087485e277ca061bf40db41b6e2a50b0638ea5e335c8d1be333b1fad9cb8
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:8f1345ff74271fe2d5a55ddf68d2789784dbf932ba8480cfda23bace38c38a97
versionagent-engine-1+legal-2026-08-25 / 8f1345ff74271fe2

Artefakter

Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Sitering: 32022R2554 art. 18, Classification of ICT-related incidents and cyber threats. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-18 (hämtad 2026-08-18, bevis sha256:5fdece7c7011e57c, bygge legal-2026-08-25).