Article 23: Operational or security payment-related incidents
Last updated: 1 authoritative sourceDORA Auditor Editorial Team
Article 23 extends DORA's incident-reporting rules to operational or security payment-related incidents at credit institutions, payment institutions, account information service providers, and e-money institutions, replacing the equivalent PSD2 reporting duty so entities report once rather than under two overlapping regimes.
Chapter III, ICT-related incident management · Pillar: ICT Incident Reporting
Key points
- Applies incident reporting to payment-related operational and security incidents
- Covers credit institutions, payment institutions, AISPs, and e-money institutions
- Replaces, rather than duplicates, the equivalent PSD2 reporting obligation
How this fits DORA
Article 23 sits within the ICT Incident Reporting pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.
Read the official text
This is an editorial summary. Read the binding text of Article 23 in the consolidated regulation on EUR-Lex.