NixFleet

DORA - Chapter III mapping

Regulation 2022/2554, applicable since 17 January 2025. Articles 8, 9, 12, 17.

DORA (Regulation 2022/2554, applicable since 17 January 2025) sets ICT risk-management requirements for credit institutions, investment firms, crypto-asset providers, and other financial entities. The four chapter-III articles below carry the operational ICT-security content; nixfleet-compliance covers each via the named controls.

ArticleRequirementControls
Art. 8ICT asset management & change/patch management_asset-inventory, _change-management, _vulnerability-mgmt
Art. 9ICT access control, authentication, network segmentation_access-control, _authentication, _network-segmentation
Art. 12Backup & recovery, business continuity_backup-retention, _disaster-recovery
Art. 17ICT incident management_incident-response

Canonical control source: docs/dora-mapping.md in the compliance repo.

← Back to compliance