Agent · dora-2022-2554-25
DORA artikel 25: Testing of ICT tools and systems
Strukturelt tre: artikkelens egne punkter, ordrett.
CELEX 32022R2554 · 2026-08-18 · Vekt 86 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- Hva siden er
- Agent, DORA artikel 25
- Lest mot offisiell kilde
- 2026-08-18Fersk
- Ansvarlig utgiver
- ExploreWorld Legal, redaksjonenAnsvarsposisjon
Kort svar
What does DORA Article 25 require, and what outcome does the rule tree give?
DORA Article 25 is tested here by a deterministic rule tree of 3 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022R2554. The outcome is a machine classification, not a compliance decision.
DORA Article 25Lest mot utgiveren 2026-08-18Offisiell tekst
- Paragraph 1 applies. 1. The digital operational resilience testing programme referred to in Article 24 shall provide, in accordance with the criteria set out in Article 4(2), for the execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scen…
- Paragraph 2 applies. 2. Central securities depositories and central counterparties shall perform vulnerability assessments before any deployment or redeployment of new or existing applications and infrastructure components, and ICT services supporting critical or important functions of the financial entity.
- Paragraph 3 applies. 3. Microenterprises shall perform the tests referred to in paragraph 1 by combining a risk-based approach with a strategic planning of ICT testing, by duly considering the need to maintain a balanced approach between the scale of resources and the time to be allocated to the ICT testing provided for in this Article, on the one hand, and the urgency, type of risk, criticality of information assets and of services prov…
En kildehenvisning, ikke juridisk rådgivning.
Jurisdiksjon
Samme agent, lest med ett lands øyne.
Inndata
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3)
Regeltre
Hvis: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. The digital operational resilience testing programme referred to in Article 24 shall provide, in accordance with the criteria set out in Article 4(2), for the execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scen…
Punkt 1
Hvis: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. Central securities depositories and central counterparties shall perform vulnerability assessments before any deployment or redeployment of new or existing applications and infrastructure components, and ICT services supporting critical or important functions of the financial entity.
Punkt 2
Hvis: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
3. Microenterprises shall perform the tests referred to in paragraph 1 by combining a risk-based approach with a strategic planning of ICT testing, by duly considering the need to maintain a balanced approach between the scale of resources and the time to be allocated to the ICT testing provided for in this Article, on the one hand, and the urgency, type of risk, criticality of information assets and of services prov…
Punkt 3
Hvis ingen regel treffer: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
Artikkelteksten som ble lest
- 11. The digital operational resilience testing programme referred to in Article 24 shall provide, in accordance with the criteria set out in Article 4(2), for the execution of appropriate tests, such as vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing.
- 22. Central securities depositories and central counterparties shall perform vulnerability assessments before any deployment or redeployment of new or existing applications and infrastructure components, and ICT services supporting critical or important functions of the financial entity.
- 33. Microenterprises shall perform the tests referred to in paragraph 1 by combining a risk-based approach with a strategic planning of ICT testing, by duly considering the need to maintain a balanced approach between the scale of resources and the time to be allocated to the ICT testing provided for in this Article, on the one hand, and the urgency, type of risk, criticality of information assets and of services provided, as well as any other relevant factor, including the financial entity’s ability to take calculated risks, on the other hand.
Opphav
Grensesnitt
Hasher
Artefakter
Ingen rådgivning. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Sitering: 32022R2554 art. 25, Testing of ICT tools and systems. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-25 (hämtad 2026-08-18, bevis sha256:6131a1482a132119, bygge legal-2026-08-25).