Skip to content

2026

DORA Article 16: the simplified regime is lighter, not optional

So far this series has walked the full ICT risk management framework, Articles 5 to 15. Article 16 is for the entities that do not have to do all of that. It is proportionality written into the regulation. It is also widely misread as an exemption, which it is not. Today, who qualifies for the simplified framework, and what they still have to do.

DORA Articles 13 and 14: the quiet articles that decide if you improve

Most of DORA is about preventing and surviving incidents. Articles 13 and 14 are about what happens afterwards: do you learn, and do you communicate. They are easy to skim past because they do not come with hard thresholds. They are also, in my experience, where the difference between a mature function and a box-ticking one actually shows. Today, learning and communication.

The document list BaFin walks in with

Most DORA readiness work starts from the regulation and tries to guess what a supervisor will ask for. You do not have to guess. BaFin published the list.

The awkward part is what happens when you lay your existing policy stack next to it.

DORA Articles 11 and 12: what "recover" has to actually mean

Detection tells you something broke. Articles 11 and 12 are about getting back up. This is the part of DORA that auditors love, because continuity and backup are testable in a way that policies are not: either you restored within your stated objective or you did not. Today, business continuity and backup, and the RTS that says testing them once is not enough.

DORA Article 10: detection, and the exact numbers that make an incident "major"

Article 9 was about keeping attackers out. Article 10 accepts that some get in, and asks whether you would notice. It is short, but it connects to the most consequential numbers in the whole regulation: the thresholds in RTS 2024/1772 that decide when an incident stops being an internal matter and becomes something you must report to your supervisor. Today, detection and classification.

The DPIA and the FRIA are one assessment, not two

An AI system that processes personal data lands on your desk. Two obligations attach to it, from two regulations, answerable to two different authorities.

Almost everyone runs them as two projects. The legal text does not ask for that, and the second risk register is where the trouble starts.