EIOPA · DORA037 - 2992
DORA037 - 2992
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- Article 11
- Submitted
- 2024-02-14
- Answered
- 2025-02-20
Question
Financial entities shall keep readily accessible records of activities before and during disruption events when their ICT business continuity plans and ICT response and recovery plans are activated. Is the phrase "when their ICT business continuity plans and ICT response and recovery plans are activated" is to be understood as a condition? When does "before" start? We understand this requirement as follows: Every financial entity must keep constant records. This is because an incident must be expected at all times. How long is the period for which records must be kept retrospectively from the event?
Answer
This question has been rejected because it seeks confirmation of a requirement already clearly set out in the regulation. (This requirement flows directly from the explicit phrasing of the provision, i.e. records of activities must be kept before and during disruption events.)
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
Other DORA topics
Answered 2025-11-20
Understandig of timelimits of intermediate repots for major related ICT-incidents
Answered 2024-04-15
Obligation to maintain a register of information for FEs exempt under article 16
Answered 2025-08-08
ICT third-party risk management (DORA)
Answered 2025-11-20
Critical Services Affected
Answered 2024-12-11
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.