Summary · cheatsheet · DORA / financial entity

OBLIGATIONS OF A FINANCIAL ENTITY

Financial entity under Article 2 · Regulation (EU) 2022/2554 applies from 17 Jan 2025 · supervised by the Czech National Bank · ready to print as PDF

← Back to the DORA guide
Summary · cheatsheet · DORA / financial entity
Financial entity under Article 2 · Regulation (EU) 2022/2554 applies from 17 Jan 2025 · supervised by the Czech National Bank · ready to print as PDF
Orientation document This document is a simplified, informative overview of selected obligations under Regulation (EU) 2022/2554 (DORA) and the accompanying Delegated Regulations (EU) 2024/1772 and (EU) 2025/301. It is not a binding legal opinion or a complete interpretation of the regulation. CypherOn is a cybersecurity consultancy, not a law firm. What governs is the official wording on EUR-Lex (links in the sources); on questions of interpretation and reporting, the authority for the Czech Republic is the Czech National Bank.
Direct obligations under the regulation Financial entity under Article 2 · Regulation (EU) 2022/2554 applies from 17 Jan 2025 · supervised by the Czech National Bank · ready to print as PDF

An overview of the obligations that DORA places directly on a financial entity — for management, IT and compliance. Every point carries the article you can use to look the binding wording up.

Who it applies to

The closed list sits in Article 2(1): points (a) to (t) are financial entities, point (u) covers ICT providers. Next to banks and insurers it takes in payment institutions and electronic money institutions including exempted ones, investment firms, trading venues, central securities depositories, central counterparties, fund managers, insurance intermediaries and crypto-asset service providers. The exclusions are in Article 2(3) — six points, among them insurance intermediaries that are microenterprises or small or medium-sized enterprises. Some entities only meet the simplified framework under Article 16 (last tile).

The five areas of the regulation and who gets relief

1. ICT risk management (Chapter II, Articles 5–16)

A documented ICT risk management framework as part of the overall risk management system, reviewed at least once a year and after major incidents (Article 6(1) and (5)). Entities other than microenterprises assign ICT risk management to an independent control function (paragraph 4) and subject the framework to internal audit with a formal follow-up on critical findings (paragraphs 6 and 7). It includes a digital operational resilience strategy (paragraph 8). Ultimate responsibility rests with the management body — it approves the framework, gives it a budget and keeps its own training up to date (Article 5(2) and (4)).

2. Incident reporting (Chapter III, Articles 17–23)

An incident is major where critical services are affected and, at the same time, either there was successful malicious unauthorised access that may result in data losses, or two or more other materiality thresholds are met (Article 8(1) of Regulation 2024/1772). Time limits under Article 5 of Regulation 2025/301: initial notification within 4 h of classification, and no later than 24 h from becoming aware; intermediate report within 72 h; final report within one month of the intermediate one. The deferral to noon of the next working day does not apply, for the first two reports, to credit institutions, central counterparties and operators of trading venues (paragraph 5).

3. Resilience testing (Chapter IV, Articles 24–27)

A testing programme as part of the framework; the tests are carried out by independent parties, internal or external (Article 24). Cadence: at least yearly for all systems supporting critical or important functions (Article 24(6)). The top tier is TLPT — threat-led penetration testing (Article 26): once every three years, but only for entities identified by the competent authority; it applies neither to entities under Article 16(1) nor to microenterprises, and the identification criteria come from Regulation 2025/1190. It runs on live production and without the defenders knowing. The framework is TIBER-EU — the Czech National Bank joined it in September 2024 and issued the TIBER-CZ Implementation Guide in March 2025.

4. Third-party providers and the register of information (Chapter V, Articles 28–44)

Responsibility always stays with the financial entity, even where the service is bought in (Article 28(1)). Before contracting: due diligence and a risk assessment covering the aggravation of ICT concentration risk and conflicts of interest (paragraphs 4 and 5); for critical or important functions, a tested exit strategy (paragraph 8). The contract has to carry the minimum content of Article 30. The register of information (paragraph 3) is kept at entity level and on a consolidated basis and distinguishes arrangements supporting critical functions; the format comes from Implementing Regulation 2024/2956 — fifteen interlinked templates, with identification by LEI code.

5. Cyber threat information sharing (Chapter VI, Article 45)

Taking part in arrangements for sharing indicators of compromise, tactics, techniques and procedures is voluntary — but participation has to be notified to the competent authority (Article 45(3)). It is the only hard obligation in the whole chapter and, because it hangs off a voluntary activity, it is the one most often overlooked. In the Czech Republic, failing to notify is a separate administrative offence.

The simplified framework under Article 16 — who it covers

It is not relief "for the small", it is a named list: small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366, institutions exempted under Directive 2013/36/EU for which the Member State did not exercise the option in Article 2(4), electronic money institutions exempted under Directive 2009/110/EC and small institutions for occupational retirement provision. Articles 5 to 15 do not apply to them — instead they meet eight obligations under the second subparagraph of Article 16(1) and are subject neither to TLPT nor to the strategy on ICT third-party risk (Article 26(1), Article 28(2)). Being a microenterprise does not mean the simplified framework — a microenterprise is not exempted, its scope is merely narrowed in places.

The records that evidence compliance

Supervision and penalties in the Czech Republic

The competent authority is the Czech National Bank (Section 9 of Act No. 31/2025 Coll.). Fines under Section 18: up to CZK 50,000,000 for the ICT risk management framework (Article 6), the ICT business continuity policy (Article 11), reporting of major incidents (Article 19), testing and third-party risk management; up to CZK 20,000,000 for the remaining ICT risk management duties and for the incident management process and classification (Articles 17 and 18); up to CZK 10,000,000 for failing to notify information sharing and for not cooperating with the Czech National Bank. Compliance is enforced through coercive fines of up to CZK 5,000,000 individually and CZK 20,000,000 in aggregate (Section 14).

Recommended first steps

First
Establish whether you meet the full framework or the simplified one under Article 16, and whether you are a microenterprise. The scope of everything else follows from that.
Within 30 days
Minutes of the management body approving the framework and the strategy, a check that your LEI code is valid, an inventory of contractual arrangements against the templates of Regulation 2024/2956.
Within 60 days
The classification rule of Regulation 2024/1772 written straight into the incident response plan, and a rehearsed submission to SDAT within the four-hour deadline.
Within 90 days
A plan for the annual testing of critical systems, a review of the contracts against Article 30 and an exit strategy for the provider that is hardest to replace.

We can help with the implementation

Not sure
where to start?

We will assess your situation against DORA, prepare the inputs for the register of information, rehearse an incident report with you or go through the contract addendum from your bank. The consultation is non-binding.