Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

EU · DORA (Reg 2022/2554)

Digital operational resilience.

Applies to: EU financial entities & ICT providers. Built · in force

What the signed record shows

ICT-incident detection/logging and incident records supporting reporting.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Arts 17/19/24/28; RTS (EU) 2025/301

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector ("DORA"). Applies since 17 January 2025. Provisions this mapper evidences from the per-event signed record:

Art. 17
ICT-related incident management process (detect, manage, log).
Art. 19
Reporting of major ICT-related incidents to the competent authority (initial notification, intermediate report, final report).
Art. 24
General requirements for the performance of digital operational resilience testing (sound testing programme; record results).
Art. 28
General principles for sound management of ICT third-party risk (register of, and records relating to, ICT third-party providers). The major-incident reporting timelines (initial / intermediate / final) are set by Commission Delegated Regulation (EU) 2025/301 (RTS on incident reporting).

Taken from the Regulayer entry for this instrument, which is built against the primary text.

This is the duty on the business. For what a lawyer in Europe must disclose about using AI in a filing, see Europe: the EU AI Act, the CCBE guides, and what Germany tells its lawyers.