Batch Register
Regime

What DORA (Regulation (EU) 2022/2554) sets on each scheduled job

Article 25 sets at least yearly testing of critical ICT systems; the Article 19 reporting timelines are referred to, not stated, in the held text. Tick DORA on the register and every job in these classes carries its row below. A lit cell is a figure the clause states; a row that reads no clock stays that way, because the register never fills a blank the standard left open.

The clock each rule sets

Consumer classClockClause
Security monitoring and log review
Security event log review exportno clockDORA Art. 10 Detectionpromptly
Security alert and monitoring reportno clockDORA Art. 10 Detectionpromptly
Backup, restore and replication
Backup restore test8,760hDORA Art. 25 Testing of ICT tools and systemscritical ICT systems tested at least yearly
no clockDORA Art. 11 Response and recoveryregular testing
Full backupno clockDORA Art. 12 Backup policies and procedures, restoration and recovery
Incremental or differential backupno clockDORA Art. 12 Backup policies and procedures, restoration and recovery
Database snapshotno clockDORA Art. 12 Backup policies and procedures, restoration and recovery
Replication and failover syncno clockDORA Art. 12 Backup policies and procedures, restoration and recovery
Incident and breach reporting
Breach notification report packno clockDORA Art. 19 Reporting of major ICT-related incidentsthe prescribed timelines
Incident and service reportno clockDORA Art. 17 ICT-related incident management process
Incident response exercise or drill8,760hDORA Art. 25 Testing of ICT tools and systemsat least yearly
Regulator incident notificationno clockDORA Art. 19 Reporting of major ICT-related incidentsthe prescribed timelines
Customer-facing feeds and statements
Customer statement and notification feedno clockDORA Art. 11 Response and recovery
Payment file and settlement batchno clockDORA Art. 11 Response and recovery
Pricing and rates feedno clockDORA Art. 11 Response and recovery

The clauses in full

DORA Art. 10 Detectionthe standard's page

Financial entities shall have mechanisms to promptly detect anomalous activities, ICT network performance issues and ICT-related incidents, with multiple layers of control, defined alert thresholds and detection processes that enable timely incident response.

What an assessor asks to see: Anomaly/incident detection mechanisms with defined alert thresholds; Monitoring coverage records. Where it usually falls short: No anomaly detection or alerting

DORA Art. 25 Testing of ICT tools and systemsthe standard's page

The testing programme shall include a range of assessments and tests (e.g. vulnerability assessments and scans, open-source analyses, network security assessments, gap analyses, physical security reviews, questionnaires, source-code reviews, scenario-based tests, compatibility/performance tests, end-to-end and penetration testing), with critical ICT systems tested at least yearly.

What an assessor asks to see: Test plans and results across the required assessment types; At least-yearly testing of critical ICT systems. Where it usually falls short: Critical systems not tested annually

DORA Art. 11 Response and recoverythe standard's page

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

What an assessor asks to see: ICT business continuity policy + response/recovery plans; Records of plan testing. Where it usually falls short: No ICT continuity/response/recovery plans

DORA Art. 12 Backup policies and procedures, restoration and recoverythe standard's page

Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.

What an assessor asks to see: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests. Where it usually falls short: No tested backups

DORA Art. 19 Reporting of major ICT-related incidentsthe standard's page

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

What an assessor asks to see: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines. Where it usually falls short: Late or missing major-incident reporting

DORA Art. 17 ICT-related incident management processthe standard's page

Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents, including early warning indicators, procedures to identify/track/log/categorise incidents by priority and severity, roles and responsibilities, and communication plans.

What an assessor asks to see: Documented ICT incident management process with logging, categorisation and roles. Where it usually falls short: No structured incident management process

Requirement text quoted from the standards themselves, published at compliance.theartofservice.com, the same publisher as this register, read against the held text of each standard: our statement of each clause, not the instrument verbatim. Every regime: the index.