Get Demo
↑

DORA ICT Risk Management Framework (Articles 5–16): Requirements

Articles 5–16 of Regulation (EU).

Published: September 2026 Compliance · DORA 8–12 min read

The ICT risk management framework is DORA’s operational core. Articles 5–16 span management-body accountability through detection, response, backup strategies, and post-incident learning.

Related: DORA hub · Five pillars · Article 10.

Framework span: Treat Articles 5–16 as one integrated framework. Article 5 puts the management body in charge; later articles operationalise identification (Art. 8), protection (Art. 9), detection (Art. 10), response and recovery (Art. 11), backup and restoration strategies (Art. 12), learning and evolution (Art. 13), and communication (Art. 14), with related obligations through Article 16 themes for simplified regimes where applicable.

Article Map (Themes)

Management-Body Expectation

Boards must approve and oversee the ICT risk management framework — not treat it as a purely technical CISO document. Annual review cadences and residual-risk acceptance belong in governance packs.

RTO / RPO Note

Backup and restoration strategies reference recovery time and recovery point objectives. Specific hours or minutes are organisation-specific — derived from business impact analysis and critical-function mapping, not from a universal DORA number.

How CyberSilo Helps

Map Articles 5–16 to Living Controls

CSA tracks framework evidence; ThreatHawk supports Article 10 detection proof.

Frequently Asked Questions

Which articles cover the ICT risk framework?

Articles 5–16 of Regulation (EU) 2022/2554 set out the ICT risk management framework themes from governance through detection, response, backup, learning, and communication.

Does DORA prescribe a single RTO number?

No. Recovery objectives are set by the financial entity based on critical functions and impact analysis — there is no universal RTO/RPO number in DORA.

How does this relate to ISO 27001?

ISO 27001 can support many control themes, but DORA still requires financial-sector-specific governance, reporting, testing, and third-party artefacts — see DORA vs ISO 27001.

Hub · Checklist · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!