DORA Article 45: cyber threat information sharing arrangements
Article 45. The voluntary-but-governed pillar made operational: trusted communities (FS-ISAC, CSIRTs, MISP), the competent-authority notification duty, TLP v2.0 handling, GDPR & competition safeguards, a sharing operating model and 10 KRIs.
What this solves
Article 45 is voluntary, which is exactly why it gets skipped — and then raised in a supervisory conversation as evidence of maturity. Sharing threat intelligence with peers is permitted, encouraged, and hedged with conditions on data protection, confidentiality and how the arrangement is notified.
The practical questions are unglamorous: what may leave the building, under which traffic light protocol marking, approved by whom, and how do you show you thought about it.
What is inside
- Article 45 conditions & the CA notification duty (Art. 45(3))
- Trusted-community landscape — FS-ISAC, CSIRTs, ENISA, MISP
- Traffic Light Protocol (TLP v2.0) handling rules
- GDPR, competition-law & confidentiality safeguards
- Sharing arrangement template & membership register
- Intake–triage–dissemination operating model + RACI
- 10 KRIs and a 5-level participation readiness scorecard
What it covers in the regulation
- Article 45 — information and intelligence sharing arrangements
- Interaction with GDPR and confidentiality duties
- Traffic Light Protocol handling
- Notification of participation to the competent authority
Who uses it, and when
Threat intelligence leads and CISOs joining an ISAC or a peer sharing group, and the compliance officer who has to approve what may be disclosed.
How to work through it
- Decide what categories of intelligence you are willing to share, and what you will never share.
- Adopt the TLP handling rules so classification is a habit, not a judgement call.
- Put the arrangement on paper, including the data protection position.
- Notify participation where required, and keep the record.