RTS on ICT Risk Management Framework

Commission Delegated Regulation (EU) 2024/1774

Digital Operational Resilience Act (DORA)

Regulation Number: Commission Delegated Regulation (EU) 2024/1774

Adoption Date: March 13, 2024

Publication Date: June 25, 2024 (Official Journal)

Application Date: January 17, 2025

Official Source: EUR-Lex (eur-lex.europa.eu/eli/reg_del/2024/1774/oj/eng)

Executive Summary

Objective: This RTS establishes the regulatory technical standards specifying the ICT risk management tools, methods, processes and policies, as well as the simplified ICT risk management framework for small financial entities.

Scope of Application

Entities Covered

Components of the ICT Risk Management Framework

1. Governance and Organization

Article 3 - Roles and Responsibilities:

2. Identification and Classification of ICT Assets

Article 4 - Asset Inventory:

3. ICT Risk Assessment and Management

Article 5 - Assessment Methodology:

Protection and Prevention Measures

4. Information Security (Article 6-12)

Domain Key Requirements
Access Control • Multi-factor authentication (MFA)
• Principle of least privilege
• Periodic review of access rights
• Logging of privileged access
Cryptography • Encryption of sensitive data at rest
• Encryption of communications (TLS 1.2+)
• Secure management of cryptographic keys
• Use of approved algorithms
Vulnerability Management • Regular vulnerability scanning
• Patch management within required timeframes
• Annual penetration testing minimum
• Monitoring of emerging threats
Network Security • Network segmentation
• Firewalls and intrusion detection systems
• Network traffic monitoring
• DDoS protection

5. Physical and Environmental Security (Article 18)

Business Continuity and Recovery

6. ICT Continuity Policy (Article 24)

Mandatory components of the BCP/DRP policy:

7. Business Continuity and Disaster Recovery Plans (Article 39)

Documentation requirements:

Mandatory testing:

Monitoring and Reporting

8. Continuous Monitoring (Article 20)

Monitoring Type Frequency Key Metrics
System availability Real-time Uptime, response time, latency
Security events Real-time Intrusion attempts, anomalies, SIEM alerts
Performance Continuous CPU, memory, storage, bandwidth
Control compliance Quarterly Compliance rate, exceptions, deviations

9. Reporting to the Management Body

Mandatory reports:

Report content:

Simplified Framework for Small Entities

Entities eligible for the simplified framework:

Authorized simplifications:

⚠ Requirements maintained despite simplification:

✓ Compliance Checklist

Step Required Actions Priority
1. Governance ☐ Designate ICT risk management function
☐ Define roles and responsibilities
☐ Establish ICT risk strategy
☐ Obtain management body approval
HIGH
2. Inventory ☐ Inventory all ICT assets
☐ Classify by criticality
☐ Identify interdependencies
☐ Update inventory
HIGH
3. Risk Assessment ☐ Choose assessment methodology
☐ Conduct initial assessment
☐ Document identified risks
☐ Define treatment plans
HIGH
4. Security Controls ☐ Implement MFA
☐ Data encryption
☐ Network segmentation
☐ Security monitoring (SIEM)
MEDIUM
5. Continuity ☐ Perform BIA (Business Impact Analysis)
☐ Define RTO/RPO
☐ Write BCP/DRP plans
☐ Test the plans
HIGH
6. Documentation ☐ Comprehensive ICT policies
☐ Operational procedures
☐ Registers and logs
☐ Evidence of compliance
MEDIUM
7. Testing and Audits ☐ Vulnerability testing
☐ Penetration testing
☐ Internal audits
☐ Compliance review
MEDIUM
8. Reporting ☐ Establish KRIs/KPIs
☐ Monitoring dashboards
☐ Quarterly reports
☐ Annual review
NORMAL

Practical Recommendations

For Large Institutions

For Small Entities (Simplified Framework)

Resources and References

Official Documents

Reference Standards

Need Help Implementing These Requirements?

Our experts can guide your institution through DORA compliance, from gap analysis to full implementation.

Free Gap Analysis Consulting Services Download All Guides

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
163
certificates issued
105
certified professionals
21
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join the Webinar Waiting List