Skip to main content
DORA Auditor

Article 22: Supervisory feedback

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

Article 22 requires competent authorities to acknowledge receipt of major-incident reports and provide feedback or guidance to the reporting entity, which may include anonymised information on similar threats and remedial measures, without imposing additional fees for that feedback.

Chapter III, ICT-related incident management · Pillar: ICT Incident Reporting

Key points

  • Competent authorities must acknowledge and respond to major-incident reports
  • Feedback can include relevant, anonymised threat intelligence
  • No fee may be charged to the entity for this supervisory feedback

How this fits DORA

Article 22 sits within the ICT Incident Reporting pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.

Read the official text

This is an editorial summary. Read the binding text of Article 22 in the consolidated regulation on EUR-Lex.

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex