
Commission Delegated Regulation (EU) 2024/1774 and Related DORA Secondary Legislation: An Advanced Deep Dive
This course walks section by section through Commission Delegated Regulation (EU) 2024/1774 and four related DORA regulatory technical standards on incident classification, third-party contracting, incident reporting, and ICT subcontracting. Learners will be able to interpret the instruments’ governance, security, resilience, reporting, and outsourcing requirements and connect each operational obligation to its regulatory rationale.
The first lecture plays free — no account needed.
What you'll learn
- Students will be able to identify the purpose, legal basis, issuing authority, and structure of Regulation 2024/1774.
- Students will be able to relate proportional implementation to entity size, complexity, structure, and ICT risk profile.
- Students will be able to trace the regulatory rationale for asset, cryptographic, vulnerability, access, project, incident, and continuity controls.
- Students will be able to distinguish the ordinary and simplified frameworks included within the same delegated act.
- Students will be able to map the required content and review cycle of ICT security and risk-management policies.
- Students will be able to identify required asset information, including ownership, dependencies, criticality, recovery objectives, exposure, and support end dates.
- Students will be able to assess whether encryption, cryptographic-key, certificate, and renewal arrangements satisfy the Regulation’s risk-based requirements.
- Students will be able to evaluate operations controls for capacity, vulnerabilities, patches, endpoints, third parties, environment separation, logging, and time synchronisation.
- Students will be able to evaluate network architecture, connection documentation, administration networks, firewall governance, encryption, and session controls.
- Students will be able to identify protections required for information availability, authenticity, integrity, confidentiality, and leakage prevention during transit.
Prerequisites
- Regulation 2024/1774 structure
- Proportionality
- Lifecycle control rationale
- ICT asset criticality
- Operations security
- Risk-based control selection
Course Content
11 modules · 4h total
Regulation 2024/1774: Regulatory Rationale, Proportionality, and Control Foundations
Why does a single ICT risk standard need to work for financial entities with radically different structures and risk profiles? This opening chapter situates Regulation 2024/1774 within DORA, identifies its legal status and architecture, and follows the recitals from proportionality through security, incident, and continuity rationales.
Regulation 2024/1774: ICT Risk Governance, Assets, Cryptography, and Operations Security
The Regulation now moves from regulatory rationale to the machinery of day-to-day ICT control. This chapter examines how governance, risk treatment, asset records, cryptographic safeguards, vulnerability management, secure operations, and logging fit into a reviewable control system.
Regulation 2024/1774: Networks, Secure Development, Change, Identity, and Access
A resilient environment can still fail at its boundaries, during deployment, or through excessive access. This chapter follows the Regulation across network segregation, protected information transfer, secure acquisition and development, change governance, physical security, personnel controls, and identity management.
Regulation 2024/1774: Incident Response, Business Continuity, and Framework Review Reports
What happens when preventive controls do not stop disruption? This chapter examines the full response arc—from anomaly detection and evidence retention through severe-but-plausible continuity testing, recovery scenarios, and the searchable report documenting the framework review.
Regulation 2024/1774: Simplified ICT Framework and Final Provisions
Proportionality does not mean the absence of disciplined control. This chapter traces the simplified framework from governance and risk assessment through technical safeguards, continuity planning, review reporting, and the Regulation’s binding entry into force.
Regulation 2024/1772: Incident Classification Foundations and Initial Criteria
Incident reporting begins with a defensible classification, not a label applied after the fact. This chapter introduces Regulation 2024/1772 and examines how financial entities count affected parties and transactions, evaluate reputation, and measure incident duration and service downtime.
Regulation 2024/1772: Materiality Thresholds, Cyber Threats, and Cross-Border Relevance
When does an operational event cross the line into a major incident, and when does a threat become significant before materialising? This chapter works through the remaining classification criteria, the major-incident decision rule, recurring-incident aggregation, cross-border relevance, authority information sharing, and final provisions.
Regulation 2024/1773: Third-Party ICT Policy Governance and Contractual Lifecycle
A contract supporting a critical or important function must be governed as a lifecycle risk, not treated as a procurement artifact. This chapter situates Regulation 2024/1773 and examines proportional policy design, group consistency, management-body oversight, independent review, reporting lines, and lifecycle governance.
Regulation 2024/1773: Due Diligence, Contract Clauses, Monitoring, and Exit
The quality of a third-party arrangement is tested before signature, during performance, and at the point of exit. This chapter follows that sequence through ex-ante risk assessment, provider due diligence, conflicts management, mandatory contractual protections, continuous monitoring, remediation, termination, and tested exit plans.
Regulation 2025/301: Major Incident Reports, Deadlines, and Voluntary Cyber-Threat Notifications
Classification becomes regulatory communication under Regulation 2025/301. This chapter moves from the lean initial notification to detailed intermediate and final reports, testing each deadline and extension rule before examining voluntary significant cyber-threat notifications and the instrument’s legislative references.
Regulation 2025/532: Critical-Function ICT Subcontracting, Material Changes, and Termination
The collection culminates where outsourcing chains become most difficult to see and control: subcontracting beneath an ICT third-party provider. This final chapter consolidates the wider DORA control logic while examining subcontracting complexity, due diligence, contractual chain controls, material changes, termination rights, and continuing financial-entity accountability.
Read the Textbook
Read every chapter for free, right here in your browser.
Regulation 2024/1774: Regulatory Rationale, Proportionality, and Control Foundations
The instrument and its legal setting
Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 is a Commission Delegated Regulation with EEA relevance, published in the Official Journal on 25 June 2024. Its stated purpose is "supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework".
Study Flashcards
Key concepts from this course as flashcard pairs.
Regulation 2024/1774: Regulatory Rationale, Proportionality, and Control Foundations
Proportionality
Requirements regarding ICT security policies, procedures, protocols and tools, and the simplified framework, should be proportionate to the entity's size, structure, internal organisation, nature and complexity, and corresponding risks.
Documentation flexibility
Financial entities should be allowed to use documentation they already have to comply with documentation requirements flowing from the requirements.
Segregation of duties
Financial entities should ensure segregation of duties when assigning ICT roles and responsibilities, to limit conflicts of interest.
Two-pronged encryption process
Data classification plus a comprehensive ICT risk assessment informs encryption at rest, in transit, or, where necessary, in use.
Production separation
The recital identifies strict separation of production from development, testing, and other non-production environments; production testing is described only for exceptional, justified, approved circumstances.
Incident detection and personal data
Entities should use different information sources and, where information is personal data, it should be limited to what is necessary for incident detection.
+2 more flashcards
Regulation 2024/1774: ICT Risk Governance, Assets, Cryptography, and Operations Security
Article 1 proportionality principle
When developing and implementing the stated controls, the entity's size, overall risk profile, and the nature, scale, and increased or reduced complexity of its services, activities, and operations shall be taken into account.
Accepted residual-risk inventory
Article 3 requires the development of an inventory of accepted residual ICT risks, including a justification for their acceptance.
Residual-risk review frequency
Accepted residual ICT risks shall be reviewed at least once a year, including changed risks, available mitigations, and whether acceptance reasons remain valid and applicable.
Asset lifecycle
The asset-management policy shall prescribe monitoring and management of the lifecycle of ICT assets identified and classified in accordance with Article 8(1) of Regulation (EU) 2022/2554.
Encryption fallback for data in use
Where encryption of data in use is not possible, data shall be processed in a separated and protected environment, or equivalent measures shall be taken.
Cryptographic key lifecycle
It includes generating, renewing, storing, backing up, archiving, retrieving, transmitting, retiring, revoking, and destroying cryptographic keys.
Regulation 2024/1774: Networks, Secure Development, Change, Identity, and Access
Network segmentation
Article 13 requires "the segregation and segmentation of ICT systems and networks" taking account of supported-function criticality or importance, Article 8(1) classification, and the ICT assets' overall risk profile.
Firewall review for critical systems
For ICT systems supporting critical or important functions, adequacy of existing firewall rules and connection filters shall be verified at least every 6 months.
Network architecture review
Article 13 requires reviews of network architecture and network-security design once a year, and periodically for microenterprises, to identify potential vulnerabilities.
Testing proportionality
"The level of testing shall be commensurate to the criticality of the business procedures and ICT assets concerned."
Non-production data default
"non-production environments only store anonymised, pseudonymised, or randomised production data". Production data are permitted only under the Article 16(6) derogation and its conditions.
Change-function independence
Article 17 requires mechanisms ensuring independence between functions approving changes and functions requesting and implementing them.
+2 more flashcards
Regulation 2024/1774: Incident Response, Business Continuity, and Framework Review Reports
Article 22 evidence retention
Financial entities shall "retain all evidence relating to ICT-related incidents for a period that shall be no longer than necessary for the purposes for which the data are collected" and retain that evidence securely.
Article 23 automated alerts
Tools shall contain tools that provide automated alerts based on pre-defined rules to identify anomalies affecting completeness and integrity of data sources or log collection.
Article 23 escalation
Consider malicious activity or compromise indications, data loss, adverse transaction or operational impact, and ICT system or network unavailability. Also consider the criticality of affected services.
Article 24 recovery objectives
The policy must specify that critical or important functions can be recovered after disruption within a recovery time objective and a recovery point objective.
Article 25 scenario standard
Testing shall be performed using scenarios that simulate potential disruptions, including an adequate set of severe but plausible scenarios.
Article 26 alternatives
Where primary recovery measures may not be feasible in the short term because of costs, risks, logistics, or unforeseen circumstances, plans shall consider alternative options.
+1 more flashcards
Regulation 2024/1774: Simplified ICT Framework and Final Provisions
Article 28 governance objective
"an internal governance and control framework that ensures an effective and prudent management of ICT risk to achieve a high level of digital operational resilience."
Annual budget obligation
"allocates and reviews at least once a year the budget necessary to fulfil the financial entity’s digital operational resilience needs"
Access-control basis
"access rights to information assets, ICT assets, and their supported functions, and to critical locations of operation of the financial entity, are managed on a need-to-know, need-to-use and least privileges basis"
Operational vulnerability control
"perform automated vulnerability scanning and assessments of ICT assets commensurate to their classification"
Data-protection states
"the identification and implementation of measures to protect data in use, in transit, and at rest"
Controlled change requirement
"all changes to ICT systems are recorded, tested, assessed, approved, implemented, and verified in a controlled manner"
+2 more flashcards
Regulation 2024/1772: Incident Classification Foundations and Initial Criteria
Affected clients under Article 1(1)
All affected natural or legal-person clients who were unable to use the service during the incident or were adversely impacted, plus explicitly covered contractual beneficiaries.
Affected transactions under Article 1(4)
All affected transactions involving a monetary amount where at least one part of the transaction is carried out in the Union.
Unknown affected figures under Article 1(5)
The financial entity shall estimate numbers or amounts based on available data from comparable reference periods.
Reputational impact under Article 2(1)
It has occurred where at least one listed criterion is met: media reflection, repetitive complaints, actual or likely regulatory non-compliance, or actual or likely material loss of clients or counterparts.
Incident duration under Article 3(1)
From when the incident occurs until it is resolved, subject to the specified detection, log-record, and estimation rules.
Service downtime under Article 3(2)
From full or partial unavailability until restoration to the pre-incident level of service; where a delay remains, until the delayed service is fully provided.
Regulation 2024/1772: Materiality Thresholds, Cyber Threats, and Cross-Border Relevance
Article 8 major-incident rule
Critical services under Article 6 must be affected, and either Article 9(5)(b) is met or two or more other Article 9 thresholds are met.
Recurring incidents
They must occur at least twice within 6 months, have the same apparent root cause, and collectively meet Article 8(1). Assessment is monthly, subject to the stated exclusions.
Article 9 client percentage
The threshold is met where affected clients are higher than 10% of all clients using the affected service.
Duration and downtime
Duration longer than 24 hours, or downtime longer than 2 hours for ICT services supporting critical or important functions.
Economic impact
Included incident costs and losses are summed without accounting for financial recoveries. The threshold is exceeded or likely exceeded at EUR 100,000.
Significant cyber threat
All Article 10 conditions are required: potential impact, high probability of materialisation, and potential to meet the specified criticality or materiality consequence.
+1 more flashcards
Regulation 2024/1773: Third-Party ICT Policy Governance and Contractual Lifecycle
Annual review
Article 3(1): The management body shall review the policy at least once a year and update it where necessary.
Classification methodology
Article 3(2): The policy shall establish or refer to a methodology for determining which ICT services support critical or important functions, and specify when assessment and review occur.
Internal responsibilities
Article 3(3): The policy shall clearly assign responsibilities for approval, management, control, and documentation of relevant contractual arrangements.
Reporting lines
Article 3(5): The policy shall identify the responsible role or senior-management member and set out reporting lines, information, documents, and frequency.
Independent review
Article 3(7): ICT services supporting critical or important functions provided by ICT third party service providers shall be subject to independent review and included in the audit plan.
Regulation 2024/1773: Due Diligence, Contract Clauses, Monitoring, and Exit
Article 5 timing
Business needs must be defined, and the required risk assessment must be conducted, before a contractual arrangement is concluded.
Article 6 assurance
Financial entities shall ensure an appropriate level of assurance on the provider's performance. Where appropriate, more than one assurance element shall be used.
Article 7 intragroup rule
For ICT intra-group service providers, decisions on conditions, including financial conditions, are to be taken objectively.
Article 8 long-term reliance rule
The financial entity shall not over time rely solely on specified third-party certifications or provider-made-available audit reports.
Article 9 remediation
Measures addressing shortcomings must be monitored so that they are effectively complied with within a defined timeframe, taking account of materiality.
Article 10 exit-plan standard
The exit plan shall be realistic, feasible, based on plausible scenarios and reasonable assumptions, with a schedule compatible with contractual exit and termination terms.
+2 more flashcards
Regulation 2025/301: Major Incident Reports, Deadlines, and Voluntary Cyber-Threat Notifications
Article 1
Applies general information to initial notifications, intermediate reports, and final reports, including entity identity, LEI code, submitter, contacts, and conditional aggregation, group, and currency details.
Initial notification deadline
As early as possible and, in any event, within four hours from classification as major and no later than 24 hours from awareness of the ICT-related incident.
Intermediate report deadline
At the latest within 72 hours from submission of the initial notification, even if the status or handling of the incident has not changed.
Updated intermediate report
Submit without undue delay and, in any case, when regular activities have been recovered.
Final report deadline
No later than one month after the intermediate report or, where applicable, the latest updated intermediate report.
Delay notice
Inform the competent authority without undue delay, no later than the relevant reporting deadline, and explain the reasons for the delay.
+2 more flashcards
Regulation 2025/532: Critical-Function ICT Subcontracting, Material Changes, and Termination
When must the financial entity decide whether subcontracting is permitted?
Before entering into the contractual arrangement with the ICT third-party service provider, under Article 3(1).
Who must identify all relevant subcontractors and notify the financial entity?
The ICT third-party service provider, under Article 3(1)(b).
What rights must the subcontractor grant under Article 3(1)(d)?
The same contractual rights of access and inspection as those granted by the ICT third-party service provider to the financial entity and competent and resolution authorities.
Which Article 3 risks are periodically reassessed?
The risk assessment in Article 3(1)(f) to (j), against possible changes in the business environment.
Can a financial entity transfer its final DORA responsibility by relying on its provider's assessment?
No. Article 3(3) states that reliance on the provider's risk assessment shall not limit the financial entity's final responsibility.
More in Legal
See all →
Mastering the EU NIS2 Directive: From Legal Framework to Practical Compliance

Commission Implementing Regulation (EU) 2024/2690: Cybersecurity Measures and Significant-Incident Thresholds

EU:s AI-förordning artikel för artikel

Understanding the EU’s New Legislative Framework

Förstå EU:s allmänna produktsäkerhetsförordning (GPSR) i detalj
