2022-12-14

Added

Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Text with EEA relevance)

European Union logo

European Union

European Union

We hold this law as a reference for linked documents. Read the official text at the source.

Open official text
Share

Get EU alerts — same-day email on every new publication.

Lineage: In force

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it
Show all related documents (110)
Amends
Regulation (EU) 2016/1011 of the European Parliament and of the Council of 8 June 2016 on indices used as benchmarks in financial instruments and financial contracts or to measure the performance of investment funds and amending Directives 2008/48/EC and 2014/17/EU and Regulation (EU) No 596/2014 (Text with EEA relevance)2016Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 Text with EEA relevance2014Regulation (EU) No 600/2014 of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Regulation (EU) No 648/2012 Text with EEA relevance2014Regulation (EU) No 648/2012 of the European Parliament and of the Council of 4 July 2012 on OTC derivatives, central counterparties and trade repositories Text with EEA relevance2012Regulation (EC) No 1060/2009 of the European Parliament and of the Council of 16 September 2009 on credit rating agencies (Text with EEA relevance)2009
Basis for
Circular Letter No. CC/2026/00000020: EBA Guidelines on ICT Risk Management and Security in Payment Services2026MFSA Guidance on Codes of Conduct for Threat-Led Penetration Testing under DORA2026Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA2026Submission of the register of information required by DORA2026Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector – Register of Information Reporting Timelines for the Year 2026 and Onwards2025Regulations amending supervisory reporting for institutions for occupational pension retirement provision2025
+50 moreRegulations amending supervisory reporting for insurance business (FFFS 2024:30)2025MFSA Guidance on Threat-Led Penetration Testing (TLPT) under DORA and TIBER-EU2025Instruction No. 2025-I-09 on the Notification to the ACPR of the Outsourcing of the Obligation to Report Major ICT-Related Incidents2025Instruction No. 2025-I-10 on Major ICT Incident Reporting and Voluntary Notification of Significant Cyber Threats to the ACPR2025Instruction No. 2025-I-11 on Information to Notify to the ACPR Regarding Participation in Cyber Threat Intelligence Sharing Arrangements2025Instruction No. 2025-I-12 on the Submission to the ACPR of Registers of Information on Agreements Concerning the Use of ICT Services2025Commission Delegated Regulation (EU) 2025/1190 supplementing Regulation (EU) 2022/2554 on Threat-Led Penetration Testing (TLPT) criteria and standards2025Circular CSSF 25/893 on reporting of major ICT-related incidents and significant cyber threats under DORA2025CSSF Circular 25/892: Application of Joint ESA Guidelines on ICT-Related Incident Costs under DORA2025Circular CSSF 25/882 on requirements for the use of ICT third-party services under DORA2025Extension of Deadline for DORA Register of Information Submission under Regulation (EU) 2022/25542025Commission Delegated Regulation (EU) 2025/532 on ICT subcontracting for financial entities2025Instruction (Historical) No. 4/20252025Joint Guidelines on the Assessment of Aggregated Annual Costs and Losses Resulting from Significant ICT Incidents under Regulation (EU) 2022/2554 (JC 2024 34)2025Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regulatory technical standards on major ICT-related incident notifications and significant cyber threat reports2025Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing standards2025Notice describing the ICT risk management framework under EU Regulation 2022/2554 (DORA)2024Commission Delegated Regulation (EU) 2025/420 on joint examination teams for critical ICT third-party service providers2024Commission Implementing Regulation (EU) 2024/2956 laying down implementing technical standards for standard templates for the register of information2024Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector – Register of Information Reporting Timelines from Competent Authorities to the European Supervisory Authorities and 2024 Dry Run ad hoc Exercise Outcomes Webinar2024ESAs Decision on Reporting of Information for CTPP Designation2024Guidelines on DORA oversight cooperation2024Final Report on draft Implementing Technical Standards specifying ESAP collection body tasks and functionalities2024Commission Delegated Regulation (EU) 2025/301 on regulatory technical standards for major ICT-related incident notifications2024Commission Implementing Regulation (EU) 2025/302 on standard forms and procedures for reporting major ICT incidents and cyber threats2024ESAs Opinion on the rejection of the ITS on RoI under DORA2024Commission Delegated Regulations under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector Published in the EU Official Journal (Update 1)2024Draft Regulatory Technical Standards on Subcontracting ICT Services under DORA2024Draft Regulatory Technical Standards specifying elements related to threat led penetration tests under Article 26(11) of Regulation (EU) 2022/25542024Final Report on Draft Regulatory Technical Standards on Harmonisation of Conditions for Oversight Activities2024Final Report on Draft RTS and ITS for Major Incident Reporting and Cyber Threat Notification under DORA2024Final Report on Draft RTS and ITS on Incident Reporting under DORA2024Final Report on Draft RTS on Harmonisation of Conditions for Oversight of Critical ICT Third-Party Service Providers2024Final Report on draft RTS on the harmonisation of conditions enabling the conduct of the oversight activities2024Final Report on draft RTS specifying elements related to threat led penetration tests2024Final Report on Joint Guidelines on oversight cooperation and information exchange between ESAs and competent authorities under DORA2024Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents2024Commission Delegated Regulation (EU) 2024/1774 on ICT risk management standards2024Update on the Guidance on Technology Arrangements, ICT and Security Risk Management, and Outsourcing Arrangements2024Commission Delegated Regulation (EU) 2024/1772 on ICT incident classification and reporting standards2024Commission Delegated Regulation (EU) 2024/1773 on ICT third-party risk policy standards2024Commission Delegated Regulation (EU) 2024/1502 on criteria for designating ICT third-party service providers as critical2024Commission Delegated Regulation (EU) 2024/1505 on oversight fees for critical ICT third-party service providers2024Final Report on Draft Implementing Technical Standards on Register of Information for ICT Third-Party Services2024Final Report on Draft RTS on Classification of Major Incidents and Significant Cyber Threats under DORA2024Final report on draft RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework2024Final report on draft RTS to specify the policy on ICT services supporting critical or important functions2024European Commission Public Consultation on Two Delegated Acts under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector2023ESAs Decision on reporting of information for CTPP designation (corrigendum consolidated)Law on Digital Operational Resilience for the Financial Sector
Referred to by
Frontier Artificial Intelligence Models and the Evolving Cyber-Threat Landscape2026Law on Markets in Financial Instruments2026Supervisory Expectations on Geopolitical Risk Management2026Final Report on RTS for CCP Admission Criteria and NFC Clearing Member Assessment2026Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models2026Comparing the TIBER-EU Framework with other established Non-EU TLPT Frameworks2026
+43 moreImpact of Frontier AI Systems on Cyber Risk2026ICT Self-Assessment Tool 20262026General Observations on Digital Operational Resilience in Authorisation Applications Received in 20252026Overview of Notification and Reporting Requirements for Small and Medium-Sized Investment Firms2026Final report on the integrated collection of funds’ data2026Insurance Supervision Act 2016 (VAG 2016)2026Consolidation Act on Company Pension Funds2026Recommendation No. 3/2026 (March 25) of the Magyar Nemzeti Bank on internal policies, procedures and controls ensuring the implementation of EU and national restrictive measures related to fund transfers and certain crypto-asset transfers2026Opinion of the European Central Bank on the proposed Digital Omnibus regulation2026Guide to Submitting DORA Registers of Information on the Central Bank of Ireland Portal2026Latvijas Banka Rules No. 409 on Requirements for Digital Operational Resilience for Financial Market Participants Not Subject to Regulation (EU) 2022/25542026Recommendation No 13/2025 of the Magyar Nemzeti Bank on the digital transformation of credit institutions2025Guidelines on outsourcing to cloud service providers (2025)2025Regulations amending Finansinspektionen’s regulations and general guidelines governing payment institutions and registered payment service providers2025Regulations amending Finansinspektionen’s regulations regarding activities of payment service providers2025Regulations amending Finansinspektionen’s regulations regarding alternative investment fund managers2025Regulations amending Finansinspektionen’s regulations regarding occupational pension undertakings (FFFS 2024:32)2025Regulations amending Finansinspektionen’s regulations regarding Swedish UCITS2025Regulations amending Finansinspektionen’s rules on electronic money institutions regarding DORA compliance2025Regulations amending governance, risk management and control at credit institutions (FFFS 2024:28)2025Final Report on Draft Regulatory Technical Standards on Operational Risk Losses Mandates2025Final Report on Guidelines on Periodic Information Submission2025Commission Delegated Regulation (EU) 2025/1143 on regulatory technical standards for approved publication arrangements, approved reporting mechanisms, and consolidated tape providers2025Circular to Credit Institutions on Amendments to Banking Rules BR/14 and BR/242025Final Report on SI notification, volume cap and circuit breakers2025Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment2025Circular CSSF 25/883 amending Circular CSSF 22/806 on outsourcing arrangements2025Official Notice of the Czech National Bank of 7 April 2025 on the Repeal of Certain Official Notices Related to Financial Market Activity Rules2025Application Form for Authorisation as a Crypto-Asset Service Provider under MiCAR2025Guidelines on maintenance of systems and security access protocols under MiCA2025Final Report on Draft Technical Standards for CSDR Review and Evaluation2025Notification Form for the Provision of Crypto-Asset Services2024Joint EBA and ESMA Guidelines on the assessment of the suitability of the members of the management body of issuers of asset-referenced tokens and of crypto-asset service providers2024ESMA Opinion on MiCA Regulatory Technical Standards for Crypto-Asset Service Provider Authorisations and Notifications2024Circular Letter No. CC/2024/00000027: Supervisory Expectations on the Suitability of Board and Supervisory Board Members and ICT, Security, and Risk Management Unit Heads2024EBA Guidelines on Recovery Plans under Articles 46 and 55 of Regulation (EU) 2023/11142024Establishing and Classifying the Organisation Size of Financial Institutions2024Establishing and Classifying the Organisation Size2024Establishing and Classifying the Organisation Size of Credit Institutions2024Recommendation No 5/2023 on the prevention, detection and management of abuses observed through payment services2023ESMA Final Report on Market Outages2023Final report on amending Guidelines on ICT risk and security managementInsurance Act – Unofficial Consolidated Text (Official Gazette Nos. 30/15, 112/18, 63/20, 133/20, 151/22, 152/24, 151/25)

Source: European Union — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EU

We email you every new EU publication the day it's published.