Implementation

DORA Article 45: cyber threat information sharing arrangements

Article 45. The voluntary-but-governed pillar made operational: trusted communities (FS-ISAC, CSIRTs, MISP), the competent-authority notification duty, TLP v2.0 handling, GDPR & competition safeguards, a sharing operating model and 10 KRIs.

€69 excl. VAT
PDF · 19 pages · one-time · instant download
Buy & download →

What this solves

Article 45 is voluntary, which is exactly why it gets skipped — and then raised in a supervisory conversation as evidence of maturity. Sharing threat intelligence with peers is permitted, encouraged, and hedged with conditions on data protection, confidentiality and how the arrangement is notified.

The practical questions are unglamorous: what may leave the building, under which traffic light protocol marking, approved by whom, and how do you show you thought about it.

What is inside

  • Article 45 conditions & the CA notification duty (Art. 45(3))
  • Trusted-community landscape — FS-ISAC, CSIRTs, ENISA, MISP
  • Traffic Light Protocol (TLP v2.0) handling rules
  • GDPR, competition-law & confidentiality safeguards
  • Sharing arrangement template & membership register
  • Intake–triage–dissemination operating model + RACI
  • 10 KRIs and a 5-level participation readiness scorecard

What it covers in the regulation

  • Article 45 — information and intelligence sharing arrangements
  • Interaction with GDPR and confidentiality duties
  • Traffic Light Protocol handling
  • Notification of participation to the competent authority

Who uses it, and when

Threat intelligence leads and CISOs joining an ISAC or a peer sharing group, and the compliance officer who has to approve what may be disclosed.

How to work through it

  1. Decide what categories of intelligence you are willing to share, and what you will never share.
  2. Adopt the TLP handling rules so classification is a habit, not a judgement call.
  3. Put the arrangement on paper, including the data protection position.
  4. Notify participation where required, and keep the record.

Questions

Is Article 45 mandatory?

No, it is voluntary. It is also one of the cheapest maturity signals available, which is why supervisors ask about it.

Does it cover the GDPR angle?

It sets out the data protection and confidentiality conditions that sharing has to respect.

Is this the fifth pillar?

Yes — information and intelligence sharing is the fifth DORA pillar, and the one most often left out of programme plans.

Delivery?

PDF, personal download link, immediately after checkout.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar