Source: OJ L 333, 27.12.2022, p. 1–79

Current language: FR

Article 23 Incidents opérationnels ou de sécurité liés au paiement concernant les établissements de crédit, les établissements de paiement, les prestataires de services d’information sur les comptes et les établissements de monnaie électronique


Summary What does Article 23 of the DORA regulation say?

This brief but important article extends the scope of the Chapter's requirements — which primarily concern ICT-related incidents — to also cover operational or security payment-related incidents.

It acts as a bridging provision, ensuring that the incident management and reporting rules established in this Chapter are not limited to purely technology-driven events, but also capture broader payment-related disruptions, whether or not they are ICT-related in origin.

Crucially, this extension does not apply to all financial entities, but only to a defined subset of payment-focused entities.

Important points:

  • The incident management and reporting requirements of this Chapter apply to both operational or security payment-related incidents and major operational or security payment-related incidents — not just ICT-related ones.
  • This extension applies only to credit institutions, payment institutions, account information service providers, and electronic money institutions.
  • Note that the scope here covers incidents whether or not they are ICT-related in origin, broadening the reach of the Chapter's obligations for these specific entity types.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Les exigences énoncées au présent chapitre s’appliquent également aux incidents opérationnels ou de sécurité liés au paiement et aux incidents opérationnels ou de sécurité majeurs liés au paiement lorsqu’ils concernent des établissements de crédit, des établissements de paiement, des prestataires de services d’information sur les comptes et des établissements de monnaie électronique.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod