DORA Article 45 Information Sharing: A Practical Guide
DORA Article 45 allows cyber threat intel sharing, but only within trusted arrangements with a notification duty and GDPR basis. Updated August 2026.
Practical guides, regulatory news, and analysis for compliance teams working through DORA. Sourced and dated, like everything else on this site.
11 articles
DORA Article 30 lists the mandatory clauses every ICT contract needs, with a stricter tier for critical or important functions. Updated August 2026.
Read guideAugust 24, 2026
DORA Article 45 allows cyber threat intel sharing, but only within trusted arrangements with a notification duty and GDPR basis. Updated August 2026.
DORA Article 5 puts personal accountability for ICT risk on the management body: approval duties, training, and liability exposure. Updated August 2026.
DORA charges designated critical ICT providers annual oversight fees and gives them a right of appeal. How it works. Updated August 2026.
DORA subcontracting rules require ten checks before a critical ICT service is subcontracted, plus notice-and-objection rights. Updated July 2026.
DORA Article 29 requires assessing ICT concentration risk before outsourcing critical functions. What it covers and how to assess it. Updated July 2026.
How DORA's major-incident classification and reporting timelines apply to payment institutions and fintechs, with a practical readiness checklist.
The ESRB's warning on frontier AI cyber capabilities, backed by the ESAs, and a follow-up ECB letter requiring an action plan by 31 October 2026, both point back to DORA's ICT risk management and resilience testing requirements.
DORA's threat-led penetration testing rules (Articles 26-27, RTS 2025/1190): who must test, how often, and what testers need to meet. Updated July 2026.
ESMA's new Common Supervisory Action tests how crypto-asset service providers apply DORA's ICT-risk and third-party rules to custody operations, from key management to exit strategy.