Chapter 15 of 15
DORA Regulation (EU) 2022/2554 — Sectoral Amendments, Application, and Legislative References
DORA concludes by rewiring existing financial-services legislation around one consolidated ICT-risk regime. The final provisions and footnotes establish the amended instruments, application date, direct effect, legislative lineage, and authoritative cross-references.
1. Why Section II Matters: DORA Rewires Existing Sectoral Rules
The legislative function
Articles 59 to 63 amend five earlier EU Regulations. They connect sector-specific operational duties to DORA where ICT systems, ICT continuity, recovery, or network security are involved.
The sectoral rule does not disappear. A CCP, CSD, trade repository, or other entity still has its own operational objective. DORA becomes the referenced framework for the ICT component.
Three drafting actions
- Replaced: the Regulation supplies new wording.
- Deleted: the provision is removed; this slice does not state a substitute.
- Excluded: an RTS mandate is limited so ICT matters are dealt with elsewhere.
How to avoid overreading
Do not treat every operational-risk duty as an ICT duty. Several amendments expressly preserve rules for non-ICT operational risk while moving ICT-risk matters to DORA.
Status checkpoint
As of 24 July 2026, DORA is in force and has applied since 17 January 2025. This lesson nevertheless teaches the supplied Articles 59 to 64 in their own wording.
2. Article 59: Credit Rating Agencies
Two linked amendments
Article 59 replaces Annex I, Section A, point 4, then replaces Annex III, point 12. The first states the control requirement; the second describes the corresponding infringement.
Mandatory organisational controls
A credit rating agency shall have sound administrative and accounting procedures, internal control mechanisms, and effective procedures for risk assessment.
Exact ICT linkage
The agency shall have effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554.
What Annex III captures
The infringement description covers not having the listed procedures or arrangements. It also covers not implementing or maintaining required decision-making procedures or organisational structures.
Interpretation
Article 59 connects the agency's sectoral governance requirement and its infringement description to the same DORA-based management of ICT systems.
3. Article 60: Central Counterparties and Trade Repositories
CCP organisational structure
Article 26(3) requires a CCP to maintain and operate an organisational structure ensuring continuity and orderly functioning, using appropriate and proportionate systems, resources, and procedures.
Those systems, resources, and procedures include ICT systems managed in accordance with Regulation (EU) 2022/2554. Article 26(6) is deleted.
CCP continuity and recovery
Article 34(1) requires an adequate business continuity policy and disaster recovery plan. It shall include DORA-aligned ICT continuity policy and ICT response and recovery plans.
A deliberate division of rulemaking
Article 34(3) excludes ICT business continuity policy and disaster recovery plans from ESMA's RTS mandate. Article 56(3) similarly excludes ICT-risk-management requirements from registration-detail RTS.
Trade repositories
Article 79 requires trade repositories to identify and minimise operational risk using appropriate controls, including DORA-managed ICT systems, and to maintain DORA-aligned continuity and recovery planning.
4. Article 60 Continued: Enforcement Annexes and Tier 2 CCPs
Trade repository infringements
Article 60 updates Annex I so failure to identify or minimise operational risk through systems, controls, and procedures including DORA-managed ICT systems is described as an infringement.
Failure to establish, implement, or maintain the required DORA-aligned continuity policy and disaster recovery plan is also described as an infringement. Annex I, Section II, point (c) is deleted.
Tier 2 CCP organisational failure
Annex III, Section II, point (c) covers failure to maintain an organisational structure ensuring continuity and orderly functioning, or failure to use appropriate and proportionate resources, systems, or procedures.
A specific recovery threshold
For a Tier 2 CCP, the plan must at least allow recovery of all transactions at the time of disruption, continued operation with certainty, and settlement on the scheduled date.
Core lesson
DORA alignment supports, rather than displaces, the sectoral objective: a CCP must preserve clearing operations and complete settlement despite disruption.
5. Article 61: Central Securities Depositories
Operational risk across the CSD
Article 45(1) requires a CSD to identify internal and external operational-risk sources and minimise their impact, including across every securities settlement system it operates.
The CSD uses appropriate ICT tools, processes, and policies set up and managed under DORA, alongside relevant tools, controls, and procedures for other operational risks.
Continuity at two levels
Article 45(3) applies both to CSD services and to each settlement system. The arrangements include including ICT business continuity policy and ICT response and recovery plans established in accordance with Regulation (EU) 2022/2554.
Required recovery outcome
The plan shall recover all transactions and participants' positions at disruption, allowing continued operation with certainty and settlement on the scheduled date.
Non-ICT qualifier
The authority-notification duty in Article 45(6), and ESMA's Article 45(7) RTS mandate, concern operational incidents and risks other than in relation to ICT risk.
6. Articles 62 and 63: Data Reporting Services and Critical Benchmarks
Three data reporting services
Article 62 covers an APA, a CTP, and an ARM. The same DORA security linkage appears in Article 27g(4), Article 27h(5), and Article 27i(3), respectively.
Exact compliance requirement
Each relevant provider shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554.
Technical-standard cross-references
Article 62 changes which organisational paragraphs are cited for APA, CTP, and ARM technical standards. This slice changes references; it does not set out the content of those organisational requirements.
Critical benchmarks only
Article 63 adds Article 6(6) to the Benchmarks Regulation for critical benchmarks. The scope qualifier must be retained.
The administrator shall have governance, control, and risk-assessment arrangements, including effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554.
7. Worked Example: One Cyber Disruption, Different Sectoral Outcomes
Start with the entity
A cyber disruption may affect several infrastructures, but Articles 60 and 61 do not prescribe one identical sectoral outcome. Begin by identifying whether the entity is a CCP, trade repository, or CSD.
CCP outcome
A CCP needs continuity and orderly functioning, plus an adequate continuity policy and disaster recovery plan. A Tier 2 CCP plan must at least recover all transactions at disruption.
Trade repository outcome
A trade repository must identify and minimise operational-risk sources through suitable controls, and maintain continuity and recovery arrangements aimed at maintaining functions and timely recovery.
CSD outcome
A CSD plan must recover all transactions and participants' positions at disruption, enabling participants to operate with certainty and complete settlement on the scheduled date.
Method
Use this sequence: `entity -> amended article -> exact sectoral outcome -> DORA-linked ICT element`. It prevents a vague, one-size-fits-all description of resilience.
8. Sorting Activity: Match the Duty to the Entity
Match each statement to its legal setting
Before revealing the answers, match each statement to the most precise option: credit rating agency, CCP, trade repository, CSD, APA/CTP/ARM, or administrator of a critical benchmark.
- Must comply with requirements concerning the security of network and information systems set out in DORA.
- Must provide for recovery of all transactions and participants' positions at the time of disruption.
- Must have DORA-aligned effective control and safeguard arrangements for managing ICT systems.
- Must identify sources of operational risk and minimise them through systems, controls, and procedures including DORA-managed ICT systems.
- Must employ appropriate and proportionate systems, resources, and procedures including DORA-managed ICT systems.
Answer key
- APA/CTP/ARM under Article 62. The identical compliance formulation is inserted for each provider type.
- CSD under Article 61, Article 45(4). The wording refers to transactions and participants' positions, and to scheduled-date settlement.
- Credit rating agency under Article 59, and also an administrator of a critical benchmark under Article 63. The critical-benchmark qualifier is essential for the latter.
- Trade repository under Article 60, Article 79(1).
- CCP under Article 60, Article 26(3).
Reflection: Which answers are easy to confuse? The CSD and Tier 2 CCP both have recovery language, but the supplied provisions express it differently. Accurate legal explanation means preserving the entity-specific wording and conditions.
9. Quiz: Preserving the CSD Qualifier
Check your precision
Choose the statement that most accurately reflects Article 61's amended Article 45(6). Focus on the phrase that limits the notification requirement.
Under Article 45(6) as amended by Article 61, a CSD shall inform the competent authority and relevant authorities without delay of which incidents?
- All ICT-related incidents affecting any service provider.
- Any operational incidents, other than in relation to ICT risk, resulting from risks posed by specified participants, providers, CSDs, or market infrastructures.
- Only incidents causing the cancellation of securities settlement.
- Only incidents identified by ESMA as major incidents.
Show Answer
Answer: B) Any operational incidents, other than in relation to ICT risk, resulting from risks posed by specified participants, providers, CSDs, or market infrastructures.
Article 45(6) requires notification without delay of operational incidents resulting from the specified risks, but expressly qualifies them as incidents "other than in relation to ICT risk." The provision does not say all ICT incidents, only settlement cancellations, or incidents designated by ESMA.
10. Article 64 and the Legislative Reference Map
Three distinct ideas
Article 64 distinguishes entry into force, application, and direct applicability. These are related but not interchangeable legal concepts.
Application date
It shall apply from 17 January 2025. As of 24 July 2026, DORA already applies. Do not describe that date as future.
Legal effect
This Regulation shall be binding in its entirety and directly applicable in all Member States. Article 64 does not frame this as a national-transposition deadline.
Legislative procedure
Footnote (3) records the Parliament's position of 10 November 2022 and the Council decision of 28 November 2022. The phrase about not yet being published reflects the footnote's historical wording.
Reference map
The footnotes identify NIS2, the digital-operational-resilience amending Directive, GDPR, and the statutory-audits Directive. A cross-reference is not a complete statement of each referenced instrument's rules.
11. Flashcards: Exact Phrases and Scope Limits
Review the load-bearing language
Flip each card and test whether you can recall both the entity and the qualifier.
- Credit rating agency ICT wording
- It shall have **effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554**.
- CCP ICT systems wording
- A CCP shall employ appropriate and proportionate systems, resources and procedures, including **ICT systems managed in accordance with Regulation (EU) 2022/2554**.
- CSD recovery object
- The plan shall provide for recovery of **all transactions and participants' positions at the time of disruption**.
- Data reporting services duty
- An APA, CTP, or ARM **shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554**.
- Critical benchmark qualifier
- Article 63 adds the ICT-governance requirement **for critical benchmarks**.
- Application date
- **It shall apply from 17 January 2025.**
- Direct applicability
- **This Regulation shall be binding in its entirety and directly applicable in all Member States.**
- NIS2 reference
- Footnote (8): **Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union**.
12. Final Quiz: Application, Direct Effect, and References
Final check
Select the fully accurate answer. It combines Article 64 with the footnotes' legislative references.
Which statement is accurate as of 24 July 2026?
- DORA will apply on 17 January 2025 after Member States transpose it into national law.
- DORA applied from 17 January 2025 and is binding in its entirety and directly applicable in all Member States; footnote (3) records the Parliament position of 10 November 2022 and Council decision of 28 November 2022.
- DORA applies only after ESMA adopts all regulatory technical standards, and NIS2 replaced DORA.
- Article 64 says that only ICT-risk provisions are directly applicable, while other provisions require national implementation.
Show Answer
Answer: B) DORA applied from 17 January 2025 and is binding in its entirety and directly applicable in all Member States; footnote (3) records the Parliament position of 10 November 2022 and Council decision of 28 November 2022.
Article 64 says, "It shall apply from 17 January 2025" and "This Regulation shall be binding in its entirety and directly applicable in all Member States." Footnote (3) gives the stated Parliament and Council milestones. The supplied provisions do not make application conditional on all ESMA standards, do not say NIS2 replaces DORA, and do not limit direct applicability to ICT-risk provisions.
Key Terms
- APA
- Approved publication arrangement. Under Article 62, an APA shall comply with DORA requirements concerning security of network and information systems.
- ARM
- Approved reporting mechanism. Under Article 62, an ARM shall comply with DORA requirements concerning security of network and information systems.
- CCP
- Central counterparty. Article 60 amends its organisational, business-continuity, disaster-recovery, and related infringement provisions.
- CSD
- Central securities depository. Article 61 amends its operational-risk, continuity, recovery, notification, and technical-standard provisions.
- CTP
- Consolidated tape provider. Under Article 62, a CTP shall comply with DORA requirements concerning security of network and information systems.
- ICT
- Information and communication technology. In these amendments, ICT systems and ICT-related continuity or recovery arrangements are expressly linked to DORA.
- DORA
- Regulation (EU) 2022/2554, the EU Regulation on digital operational resilience for the financial sector.
- ESCB
- European System of Central Banks. Article 60 requires ESMA to consult its members before developing specified CCP technical standards.
- ESMA
- European Securities and Markets Authority. In the supplied amendments, some ESMA regulatory technical standards are expressly limited to matters other than ICT risk or exclude ICT continuity and disaster-recovery plans.
- GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.
- Tier 2 CCP
- A category of CCP addressed in Annex III of Regulation (EU) No 648/2012. The supplied amendment includes a recovery requirement for all transactions at the time of disruption.
- NIS2 Directive
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.
- trade repository
- An entity whose Article 79 operational-risk and continuity requirements are amended by Article 60.
- critical benchmark
- The scope qualifier in Article 63 for the added ICT-governance requirement applicable to an administrator.
- statutory audits Directive
- Directive 2006/43/EC of the European Parliament and of the Council of 17 May 2006 on statutory audits of annual accounts and consolidated accounts.
- digital operational resilience amending Directive
- Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022 amending Directives 2009/65/EC, 2009/138/EC, 2011/61/EU, 2013/36/EU, 2014/59/EU, 2014/65/EU, (EU) 2015/2366 and (EU) 2016/2341 as regards digital operational resilience for the financial sector.