EU RegulationsHome | DORA RTS on ICT Risk Management

Browse Articles Full Text and PDF
Browse Articles Full Text and PDF

Table of Contents

TITLE I GENERAL PRINCIPLE
⊞ ▼
  • Article 1 Overall risk profile and complexity
CHAPTER I ICT Security policies, procedures, protocols, and tools
⊞ ▼
Section 1
⊞ ▼
  • Article 2 General elements of ICT security policies, procedures, protocols, and tools
Section 2
⊞ ▼
  • Article 3 ICT risk management
Section 3 — ICT asset management
⊞ ▼
  • Article 4 ICT asset management policy
  • Article 5 ICT asset management procedure
Section 4 — Encryption and cryptography
⊞ ▼
  • Article 6 Encryption and cryptographic controls
  • Article 7 Cryptographic key management
Section 5 — ICT operations security
⊞ ▼
  • Article 8 Policies and procedures for ICT operations
  • Article 9 Capacity and performance management
  • Article 10 Vulnerability and patch management
  • Article 11 Data and system security
  • Article 12 Logging
Section 6 — Network security
⊞ ▼
  • Article 13 Network security management
  • Article 14 Securing information in transit
Section 7 — ICT project and change management
⊞ ▼
  • Article 15 ICT project management
  • Article 16 ICT systems acquisition, development, and maintenance
  • Article 17 ICT change management
Section 8
⊞ ▼
  • Article 18 Physical and environmental security
  • Article 28 Governance and organisation
  • Article 29 Information security policy and measures
  • Article 30 Classification of information assets and ICT assets
  • Article 31 ICT risk management
  • Article 32 Physical and environmental security
CHAPTER II Human resources policy and access control
⊞ ▼
  • Article 19 Human resources policy
  • Article 20 Identity management
  • Article 21 Access control
  • Article 33 Access Control
  • Article 34 ICT operations security
  • Article 35 Data, system and network security
  • Article 36 ICT security testing
  • Article 37 ICT systems acquisition, development, and maintenance
  • Article 38 ICT project and change management
CHAPTER III ICT-related incident detection and response
⊞ ▼
  • Article 22 ICT-related incident management policy
  • Article 23 Anomalous activities detection and criteria for ICT-related incidents detection and response
  • Article 39 Components of the ICT business continuity plan
  • Article 40 Testing of business continuity plans
CHAPTER IV ICT business continuity management
⊞ ▼
  • Article 24 Components of the ICT business continuity policy
  • Article 25 Testing of the ICT business continuity plans
  • Article 26 ICT response and recovery plans
  • Article 41 Format and content of the report on the review of the simplified ICT risk management framework
CHAPTER V Report on the ICT risk management framework review
⊞ ▼
  • Article 27 Format and content of the report on the review of the ICT risk management framework
TITLE IV FINAL PROVISIONS
⊞ ▼
  • Article 42 Entry into force
© 2026 digitalacts.eu. All rights reserved. This a free website that allows everyone to easily navigate through the various articles of EU regulations in the digital space. This website or its authors cannot be held liable for any misinterpretation of the regulations. Always refer to the official text published in the Official Journal of the European Union for legal purposes. For inquiries, questions or feedback, contact us at info@digitalacts.eu. This website is sponsored by RiskNow, a company that provides Governance, Risk and Compliance solutions for businesses.

Recently Viewed

No recent articles yet

Latest News

2026-06-29

Council adopts AI Act simplification regulation

The Council of the EU gave final approval to an AI Act simplification regulation that delays some high-risk AI application dates and introduces targeted changes to AI governance and compliance rules.

Read more

2026-06-24

EDPB launches form to support consistent GDPR interpretation across Europe

The European Data Protection Board launched a form for stakeholders to report possible inconsistencies in GDPR interpretation across Europe.

Read more

2026-06-03

EU supervisors publish first DORA report on major ICT incidents in finance

The European Supervisory Authorities published their first annual DORA overview of major ICT-related incidents, highlighting cross-border impact and third-party dependencies.

Read more

2026-01-20

EU cybersecurity package proposes targeted NIS2 simplification while strengthening ENISA

The European Commission proposed a cybersecurity package with targeted NIS2 amendments and changes to strengthen ENISA’s role in EU cyber resilience.

Read more

All News

Search results

We may use cookies to improve your experience and analyse site usage. You can accept all cookies or choose to allow only essential cookies.