Chapter 14 of 15
DORA Regulation (EU) 2022/2554 — Information Sharing, Supervision, Penalties, and Review
The wider supervisory ecosystem depends on trusted information exchange and coordinated enforcement. Articles 45–58 connect threat-sharing communities, competent authorities, sanctions, publication, secrecy, data protection, delegated powers, and scheduled reviews.
1. The supervisory ecosystem in DORA
A connected system
DORA treats resilience as more than an internal compliance task. Articles 45 to 58 connect information sharing, supervision, enforcement, confidentiality, delegated powers, and review.
Read the sequence
Article 45: sharing. Articles 46-49: supervisors and cooperation. Articles 50-56: enforcement, secrecy, and data. Articles 57-58: delegated acts and review.
Obligation language matters
Keep DORA's modal verbs exact: may permits or leaves discretion; shall imposes a requirement. Do not turn a permission into a duty.
2. Article 45: permitted intelligence sharing, but only under conditions
The permission
Article 45 says: "Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures".
Purpose limitation
The exchange must aim to enhance digital operational resilience: for example, awareness, limiting spread, defence, detection, mitigation, response, or recovery.
Trusted and protected
Sharing "takes places within trusted communities of financial entities" and must use arrangements protecting sensitive information, confidentiality, personal data, and competition-policy requirements.
3. Article 45 in practice: designing a trusted sharing arrangement
A practical exchange
A group may share a malicious domain, file hash, and attack technique where the exchange supports detection, blocking, mitigation, response, or recovery.
Arrangement design
Article 45(2) requires participation conditions and, where appropriate, details of public-authority and ICT-provider involvement plus operational elements such as dedicated IT platforms.
Membership notice
"Financial entities shall notify competent authorities of their participation in the information-sharing arrangements" upon validated membership, or of cessation once it takes effect.
4. Knowledge check: Article 45
Choose the most accurate statement about an Article 45 information-sharing arrangement.
Which statement best reflects Article 45?
- Any financial entity must publicly disclose every cyber threat it identifies.
- Financial entities may share specified cyber-threat information, provided the sharing meets Article 45's purpose, trusted-community, and protective-arrangement conditions.
- Financial entities may share intelligence only after a competent authority gives prior approval.
- Information-sharing arrangements may ignore competition-policy guidelines if all members consent.
Show Answer
Answer: B) Financial entities may share specified cyber-threat information, provided the sharing meets Article 45's purpose, trusted-community, and protective-arrangement conditions.
Article 45 uses "may" for sharing, so it creates a permission rather than a universal duty. The permission is conditional on the resilience purpose, trusted-community setting, and protective arrangements respecting confidentiality, personal-data protection, and competition-policy guidelines. Article 45 requires notification of membership, not prior approval.
5. Article 46: which authority ensures compliance?
No single universal supervisor
Article 46 relies on sectoral legal acts. Compliance with DORA shall be ensured by the competent authority allocated to the financial entity's particular regulatory category.
Examples of allocation
Banks follow the CRD allocation, with the ECB for significant banks under the cited SSM provision. Payment and e-money entities follow the PSD2 authority; investment firms follow Directive (EU) 2019/2034.
Complete sectoral map
Article 46 also covers crypto-asset providers, CSDs, CCPs, trading venues, repositories, fund managers, insurers, intermediaries, pensions, rating agencies, benchmarks, crowdfunding, and securitisation repositories.
6. Articles 47 and 48: supervisory cooperation and NIS2 links
NIS2 connection
Under Article 47, the ESAs and DORA competent authorities may participate in relevant NIS2 Cooperation Group activities and may request invitations in specified critical-provider cases.
Consultation is qualified
Where appropriate, "competent authorities may consult and share information with the single points of contact and the CSIRTs designated or established in accordance with Directive (EU) 2022/2555".
Mandatory mutual cooperation
"Competent authorities shall cooperate closely among themselves and, where applicable, with the Lead Overseer." Timely exchange is required for relevant critical ICT-provider information.
7. Article 49: cross-sector exercises and coordinated response
Why exercise across sectors?
A cyber event at one shared ICT provider can affect banks, insurers, investment firms, and payment entities at once. Article 49 supports cross-sector situational awareness.
What may be developed?
"They may develop crisis management and contingency exercises involving cyber-attack scenarios" to build communication channels and a progressively coordinated Union-level response.
Coordination duty
Article 49(2) says competent authorities, ESAs, and the ECB shall cooperate closely, exchange information, coordinate supervision, remedy breaches, and foster consistent interpretation.
8. Articles 50 and 51: powers, penalties, remedies, and proportionality
Minimum authority powers
Authorities need access to relevant documents and data, inspection and investigation powers, the ability to obtain explanations, interview consenting persons, and require corrective or remedial measures.
Penalty standard
Member States must establish and implement administrative penalties and remedies. "Those penalties and measures shall be effective, proportionate and dissuasive."
Individualised enforcement
Authorities assess intent or negligence and factors including "the materiality, gravity and the duration of the breach". Relevant decisions must be reasoned and appealable.
9. Knowledge check: choosing an enforcement statement
Test whether you can separate a minimum enforcement power from a factor used to calibrate a penalty.
Under Articles 50 and 51, which is a factor competent authorities shall take into account, where appropriate, when determining the type and level of a penalty or remedial measure?
- Whether the entity belongs to a trusted information-sharing community.
- The materiality, gravity and the duration of the breach.
- Whether the entity has published its annual accounts in two languages.
- Whether every affected third party has agreed to the penalty.
Show Answer
Answer: B) The materiality, gravity and the duration of the breach.
Article 51(2) expressly includes "the materiality, gravity and the duration of the breach," along with responsibility, financial strength, gains or avoided losses, third-party losses, cooperation, and previous breaches. Trusted communities are relevant to Article 45 information sharing, not Article 51's penalty-calibration list.
10. Articles 52 to 56: criminal-law choices, publication, secrecy, and data
Administrative and criminal routes
Article 52 lets Member States choose not to set administrative penalties for breaches subject to national criminal penalties, but requires liaison arrangements where criminal penalties are chosen.
Publication with safeguards
Final penalty decisions are generally published, but case-specific safeguards may require deferral, anonymisation, or no publication. "This period shall not exceed five years after its publication."
Secrecy and retention
Professional secrecy covers confidential DORA information. Personal data may be processed only where necessary and retained "in any case for a maximum period of 15 years", subject to pending-court-proceedings retention.
11. Articles 57 and 58: delegated acts and scheduled review
Delegated-act control
The Commission's delegated power "shall be conferred on the Commission for a period of five years from 17 January 2024", subject to reporting, extension, objection, and revocation rules.
Three-month objection rule
A delegated act enters into force only if neither Parliament nor Council objects "within a period of three months of notification of that act to the European Parliament and the Council".
Three Article 58 review clocks
The payment report deadline was 17 July 2023; the auditor review deadline was 17 January 2026; and the broad review deadline is 17 January 2028.
12. Flashcards: precise DORA recall
Flip each card and check whether you can state the Article, the modal verb, and the condition or deadline precisely.
- Article 45: What is the central permission?
- "Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures".
- Article 45: Where must sharing take place?
- It "takes places within trusted communities of financial entities" and must meet the other Article 45 conditions.
- Article 45: What must an entity notify?
- "Financial entities shall notify competent authorities of their participation in the information-sharing arrangements" upon membership validation, and of cessation, as applicable, once effective.
- Article 48: What is mandatory?
- "Competent authorities shall cooperate closely among themselves and, where applicable, with the Lead Overseer."
- Article 50: What standard applies to penalties and measures?
- "Those penalties and measures shall be effective, proportionate and dissuasive."
- Article 54: How long may a publication remain online?
- "This period shall not exceed five years after its publication."
- Article 56: What is the ordinary maximum data-retention period?
- "In any case for a maximum period of 15 years, except in the event of pending court proceedings requiring further retention of such data".
- Article 58: When is the general review due?
- "By 17 January 2028, the Commission shall, after consulting the ESAs and the ESRB, as appropriate, carry out a review".
Key Terms
- ESA
- A European Supervisory Authority. In this module, this refers to the EBA, ESMA, and EIOPA where DORA uses that collective term.
- JON
- The Joint Oversight Network referenced in Article 58(1)(e), whose functioning and effectiveness must be included in the 2028 review.
- CSIRT
- A Computer Security Incident Response Team designated or established under Directive (EU) 2022/2555, referenced in Article 47.
- Lead Overseer
- The authority or role within DORA's critical ICT third-party provider Oversight Framework that cooperates and exchanges information with competent authorities under Article 48.
- delegated act
- A Commission act adopted under delegated power, subject in Article 57 to consultation, notification, Parliament and Council objection, extension, and revocation rules.
- remedial measure
- A corrective enforcement measure, such as requiring cessation of conduct or continued compliance with legal requirements.
- competent authority
- The sectorally designated authority that ensures compliance with DORA for the relevant category of financial entity under Article 46.
- professional secrecy
- The Article 55 obligation protecting confidential information received, exchanged, or transmitted under DORA.
- administrative penalty
- A penalty imposed through the administrative enforcement framework that Member States must establish under Article 50, subject to Article 52's criminal-law option.
- critical ICT third-party service provider
- An ICT third-party service provider designated as critical under DORA Article 31 and subject to the Oversight Framework.