Chapter 8 of 15
DORA Regulation (EU) 2022/2554 — Response, Recovery, Learning, and the Simplified Framework
What happens after disruption, and how should the regime scale for specified smaller entities? Articles 11–16 combine continuity and recovery engineering with post-incident learning, crisis communication, technical harmonisation, and a simplified but testable framework.
1. The response-to-learning cycle in DORA
A resilience cycle
Articles 11-16 form a connected cycle: prepare -> contain -> restore -> communicate -> review -> improve. DORA treats resilience as ongoing operational work, not a static emergency manual.
What each Article does
Article 11 covers response; Article 12 covers restoration; Article 13 covers learning; Article 14 covers communication; Article 15 supports harmonisation; Article 16 creates a simplified route for specified entities.
Read obligation words carefully
In these provisions, shall states a mandatory obligation. May preserves discretion. For example, a dedicated ICT business continuity policy is permitted, while the policy itself is required.
2. Article 11(1)-(3): policy, action, and recovery plans
The mandatory policy
Article 11(1) says: "financial entities shall put in place a comprehensive ICT business continuity policy". It belongs within the Article 6(1) ICT risk management framework and is based on Article 8 identification.
From policy to action
Article 11(2) requires dedicated, appropriate, and documented arrangements, plans, procedures, and mechanisms. They must preserve functions, limit damage, contain incidents, estimate losses, and support communications.
Plans receive extra scrutiny
Article 11(3) requires associated ICT response and recovery plans. For entities other than microenterprises, those plans shall be subject to independent internal audit reviews.
3. Article 11(4)-(11): test what you intend to rely on
Start with the BIA
The Article 11(5) BIA examines severe disruption using quantitative and qualitative criteria, relevant data, and scenario analysis. It must address functions, processes, dependencies, information assets, and interdependencies.
A firm testing minimum
Article 11(6) requires entities to "test the ICT business continuity plans and the ICT response and recovery plans in relation to ICT systems supporting all functions at least yearly".
Test change and failure
Testing is also required after substantive changes to ICT systems supporting critical or important functions. Non-microenterprises must include cyber-attacks and switchovers to redundant capacity, backups, and facilities.
Keep evidence
When plans are activated, Article 11(8) requires readily accessible records of activities before and during the disruption. This evidence supports later review, accountability, and learning.
4. Article 12(1)-(3): backups are not just copies
Define what is backed up
Article 12(1) requires documented backup policies and procedures. They specify both the scope of data backed up and the minimum backup frequency, based on criticality or confidentiality.
A backup must be usable
Backup systems must be activatable without harming network security or the availability, authenticity, integrity, or confidentiality of data. Procedures and methods shall be tested periodically.
Segregation is explicit
When restoring backup data on own systems, "financial entities shall use ICT systems that are physically and logically segregated from the source ICT system".
Special cases
Central counterparties must be able to recover all transactions at disruption. Data reporting service providers must additionally maintain adequate resources plus backup and restoration facilities to maintain services at all times.
5. Article 12(4)-(7): redundancy, secondary sites, and recovery objectives
Redundancy scales by entity type
Entities other than microenterprises shall maintain adequate redundant ICT capacities. Microenterprises shall assess the need for them based on their risk profile.
The CSD secondary-site rule
"Central securities depositories shall maintain at least one secondary processing site endowed with adequate resources, capabilities, functions and staffing arrangements".
Distance, access, and capability
The CSD site needs a distinct geographic risk profile, continuity capability or sufficient recovery service, and immediate staff accessibility if the primary processing site is unavailable.
Recovery is verified
Recovery objectives must reflect criticality and market efficiency. During recovery, necessary checks, including multiple checks and reconciliations where needed, shall protect the highest level of data integrity.
6. Knowledge check: recovery controls
Choose the statement that most accurately reflects Article 12.
When a financial entity restores backup data using its own systems, what does Article 12(3) require?
- It shall use ICT systems that are physically and logically segregated from the source ICT system.
- It may restore directly to the source system if a senior manager approves the decision.
- It shall restore only after all external stakeholders have confirmed their data.
- It shall use a secondary processing site only if it is a central securities depository.
Show Answer
Answer: A) It shall use ICT systems that are physically and logically segregated from the source ICT system.
Article 12(3) expressly requires physical and logical segregation from the source ICT system when restoring backup data using own systems. The separate secondary processing-site requirement applies specifically to central securities depositories under Article 12(5).
7. Article 13: learn from incidents, tests, and threats
Gather and analyse
Article 13(1) requires capabilities and staff to gather information on vulnerabilities, cyber threats, and ICT-related incidents, especially cyber-attacks, and analyse their likely resilience impact.
The review trigger
"Financial entities shall put in place post ICT-related incident reviews after a major ICT-related incident disrupts their core activities". This is not framed as a review after every minor event.
What the review tests
The review determines whether procedures were followed and actions effective, including alert response, incident assessment, forensic analysis where appropriate, escalation, and internal/external communication.
Learning becomes governance
Lessons from tests, incidents, plan activations, counterpart information, and supervisory reviews shall enter the risk assessment process continuously. Senior ICT staff shall report findings and recommendations at least yearly.
8. Article 13(6)-(7) and Article 14: people and communication
Training is compulsory
"Financial entities shall develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes." It applies to employees and senior management.
Training must fit the role
The level of complexity shall be commensurate with each function's remit. Where appropriate, ICT third-party service providers shall also be included in relevant training schemes.
Crisis communication plans
Article 14(1) requires plans enabling responsible disclosure of at least major ICT-related incidents or vulnerabilities to clients, counterparts, and the public, as appropriate.
Someone owns public communication
At least one person shall implement the ICT-incident communication strategy and fulfil the public and media function. Staff policies must distinguish responders from staff who merely need information.
9. Knowledge check: post-incident learning
Identify the trigger and purpose that Article 13(2) actually states.
Which situation triggers the mandatory post ICT-related incident review described in Article 13(2)?
- Any routine alert generated by a monitoring tool.
- A major ICT-related incident that disrupts the financial entity's core activities.
- Only a cyber-attack reported to the public.
- Any outage involving an ICT third-party service provider.
Show Answer
Answer: B) A major ICT-related incident that disrupts the financial entity's core activities.
Article 13(2) requires reviews after a major ICT-related incident disrupts core activities. The review analyses causes and identifies required improvements; DORA does not state here that every alert, every public cyber-attack, or every provider outage automatically triggers this review.
10. Article 15: harmonisation and the technical-standard deadline
Who develops the draft RTS?
Article 15 assigns the ESAs, through the Joint Committee and in consultation with ENISA, the development of common draft RTS on ICT risk-management tools, methods, processes, and policies.
Continuity and recovery are included
The Article 15 list covers the Article 11 continuity policy, testing of continuity plans, including provider-failure scenarios, and the Article 11 ICT response and recovery plans.
The source deadline
Article 15 says: "The ESAs shall submit those draft regulatory technical standards to the Commission by 17 January 2024." This is a past deadline as of 24 July 2026.
External currency note
Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplements DORA on these matters and the simplified framework; it was published on 25 June 2024 and is in force.
11. Article 16(1)-(2): the simplified framework is still substantive
Who uses this route?
Article 16 disapplies Articles 5-15 for a specified group, beginning with small and non-interconnected investment firms and payment institutions exempted under Directive (EU) 2015/2366.
Still a mandatory framework
Listed entities shall "put in place and maintain a sound and documented ICT risk management framework that details the mechanisms and measures aimed at a quick, efficient and comprehensive management of ICT risk".
Continuity remains required
They must "ensure the continuity of critical or important functions, through business continuity plans and response and recovery measures, which include, at least, back-up and restoration measures".
Review and improve
The framework shall be documented, reviewed periodically and after major ICT-related incidents, continuously improved from implementation and monitoring lessons, and reported to the competent authority upon request.
12. Flashcards: precise DORA recall
Flip each card and check whether you can state the Article, trigger, and qualifier precisely.
- Article 11(1): What is the central continuity obligation?
- Financial entities shall put in place a comprehensive ICT business continuity policy. It may be a dedicated policy, but must form an integral part of the overall business continuity policy.
- Article 11(6): What is the minimum testing frequency?
- Financial entities shall test the ICT business continuity plans and ICT response and recovery plans for ICT systems supporting all functions at least yearly, and after substantive changes to systems supporting critical or important functions.
- Article 12(3): What protects restoration from the compromised environment?
- When restoring backup data using own systems, financial entities shall use ICT systems that are physically and logically segregated from the source ICT system.
- Article 13(2): When is a post ICT-related incident review required?
- After a major ICT-related incident disrupts the financial entity's core activities.
- Article 14(3): Who handles public and media communication?
- At least one person in the financial entity shall implement the communication strategy for ICT-related incidents and fulfil the public and media function.
- Article 16: Does simplified mean no resilience duties?
- No. Listed entities still shall maintain a sound, documented ICT risk management framework, ensure continuity, test plans and controls regularly, and review and improve the framework.
Key Terms
- recovery time objective
- A time objective determined for each function under Article 12(6), taking account of whether the function is critical or important and the potential overall impact on market efficiency.
- recovery point objective
- A recovery objective determined for each function under Article 12(6), alongside recovery time objectives.
- redundant ICT capacities
- ICT capacities that entities other than microenterprises shall maintain under Article 12(4), with adequate resources, capabilities, and functions for business needs.
- secondary processing site
- For a central securities depository, the at least one site required by Article 12(5), geographically distinct from the primary site, capable of continuity or recovery-level service, and immediately accessible to staff.
- ICT business continuity policy
- The comprehensive policy required by Article 11(1), within the Article 6(1) ICT risk management framework and based on Article 8 identification requirements.
- business impact analysis (BIA)
- The Article 11(5) assessment of potential impacts of severe business disruptions using quantitative and qualitative criteria, relevant data, and scenario analysis, as appropriate.
- critical or important function
- A function whose continuity receives particular treatment in Articles 11, 12, and 16, including continuity planning, testing, recovery objectives, and redundancy considerations.
- ICT response and recovery plans
- Associated plans required by Article 11(3) to support response to and recovery from ICT-related incidents.
- post ICT-related incident review
- A review required under Article 13(2) after a major ICT-related incident disrupts core activities, examining causes, procedural compliance, effectiveness, and required improvements.
- simplified ICT risk management framework
- The Article 16 framework applicable to the specified entities for which Articles 5 to 15 do not apply; it remains documented, monitored, tested, reviewed, and continuously improved.