Source: OJ L 333, 27.12.2022, p. 1–79

Current language: DE

Artikel 23 Zahlungsbezogene Betriebs- oder Sicherheitsvorfälle, die Kreditinstitute, Zahlungsinstitute, Kontoinformationsdienstleister und E-Geld-Institute betreffen


Summary What does Article 23 of the DORA regulation say?

This brief but important article extends the scope of the Chapter's requirements — which primarily concern ICT-related incidents — to also cover operational or security payment-related incidents.

It acts as a bridging provision, ensuring that the incident management and reporting rules established in this Chapter are not limited to purely technology-driven events, but also capture broader payment-related disruptions, whether or not they are ICT-related in origin.

Crucially, this extension does not apply to all financial entities, but only to a defined subset of payment-focused entities.

Important points:

  • The incident management and reporting requirements of this Chapter apply to both operational or security payment-related incidents and major operational or security payment-related incidents — not just ICT-related ones.
  • This extension applies only to credit institutions, payment institutions, account information service providers, and electronic money institutions.
  • Note that the scope here covers incidents whether or not they are ICT-related in origin, broadening the reach of the Chapter's obligations for these specific entity types.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Die Anforderungen in diesem Kapitel gelten auch für zahlungsbezogene Betriebs- oder Sicherheitsvorfälle, auch schwerwiegender Art, wenn sie Kreditinstitute, Zahlungsinstitute, Kontoinformationsdienstleister und E-Geld-Institute betreffen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod