Article 22: Supervisory feedback
Last updated: 1 authoritative sourceDORA Auditor Editorial Team
Article 22 requires competent authorities to acknowledge receipt of major-incident reports and provide feedback or guidance to the reporting entity, which may include anonymised information on similar threats and remedial measures, without imposing additional fees for that feedback.
Chapter III, ICT-related incident management · Pillar: ICT Incident Reporting
Key points
- Competent authorities must acknowledge and respond to major-incident reports
- Feedback can include relevant, anonymised threat intelligence
- No fee may be charged to the entity for this supervisory feedback
How this fits DORA
Article 22 sits within the ICT Incident Reporting pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.
Read the official text
This is an editorial summary. Read the binding text of Article 22 in the consolidated regulation on EUR-Lex.