- Dora
- 21st Sep 2026
- 1 min read
DORA Article 45 Explained: Information-Sharing Rules
- Written by
In Short..
- Article 45 creates a permission: it establishes the legal basis for exchanging cyber threat intelligence between financial entities, and leaves the decision to join with you.
- Three conditions apply together: the exchange must serve digital operational resilience, stay inside trusted communities of financial entities, and run under rules of conduct covering confidentiality, GDPR and competition policy.
- Joining and leaving both trigger a notification: Article 45(3) requires you to tell your competent authority when membership is validated, and again once cessation takes effect.
- Evidence is what a supervisor asks for: receipt, assessment and action on each intelligence item, with a recorded rationale where the assessment led to no change.
Article 45 is the one DORA pillar that exists to improve the other four, and it only does that when what arrives gets triaged, routed and recorded.
Introduction
Article 45 of DORA (the EU’s Digital Operational Resilience Act, Regulation (EU) 2022/2554) lets financial entities exchange cyber threat information and intelligence with each other, provided the exchange meets three conditions at once: it aims to enhance digital operational resilience, it takes place within trusted communities of financial entities, and it runs through arrangements governed by rules of conduct that respect business confidentiality, personal data protection and competition policy. Joining is your choice. The obligations that attach to membership bind you from the day it is validated.
Expert View
|
Matt Davies Chief Product Officer, SureCloud |
What our experts say about joining a DORA information-sharing arrangement
"The pattern we see is a firm that joined a community, notified its regulator, and eighteen months later can’t produce a single assessment record. Membership is easy to evidence. What you did with what arrived is the part that takes work." |
What Article 45 Actually Requires
Article 45 sits alone in Chapter VI of DORA. One chapter, one article, and the legal text carries the full weight here. DORA gives the European Supervisory Authorities no mandate to write technical standards or guidelines beneath it, and they haven’t: their Joint Guidelines on oversight cooperation (JC/GL/2024/36) run to Articles 31 to 44, the oversight framework for critical ICT third-party service providers, and stop there.
The operative sentence reads: "Financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques, and procedures, cyber security alerts and configuration tools, to the extent that such information and intelligence sharing:". Three conditions follow. DORA says financial entities "may" exchange, so nothing here obliges you to join anything.
The three conditions
The exchange has to aim at improving digital operational resilience, through raising awareness of cyber threats, limiting their ability to spread, supporting defence capabilities and detection techniques, or supporting mitigation, response and recovery. It has to happen inside trusted communities of financial entities, a phrase DORA leaves undefined in its Article 3 definitions. Publishing to the open web, or sharing with entities outside the financial sector, generally sits outside what Article 45 permits.
And it has to run through arrangements that protect the sensitive nature of what is shared, under rules of conduct respecting business confidentiality, personal data protection in accordance with Regulation (EU) 2016/679 (the EU General Data Protection Regulation, or GDPR) and guidelines on competition policy. Miss one and the exchange loses its Article 45 cover, however useful the intelligence is. That’s true inside an otherwise well-run community as much as outside it.
What the arrangement’s terms have to define
Article 45(2) puts the governance burden on the arrangement itself. Its terms must define the conditions for participation and, where appropriate, set out the involvement of public authorities and the capacity in which they may be associated with it, the involvement of ICT third-party service providers, and operational elements including the use of dedicated IT platforms. Ask to see that documentation before you commit. An arrangement that can’t produce it falls short of the Article 45 standard, and at the next supervisory review the gap is yours to explain.
The notification obligation
Article 45(3) carries the one binding duty in the article. Once your membership is validated you notify your competent authority, meaning the authority designated for your entity type under Article 46. When membership ceases you notify again, once the cessation takes effect. Put both events in the compliance calendar alongside your register of information updates, because they’re easy to lose in a year when nothing else about the arrangement changes.
What You Can Share, and What Stays Inside
Article 45(1) names the shareable categories directly, and the safeguards condition in point (c) draws the line on the other side. The permission covers information and intelligence, which are separate things in DORA’s own vocabulary: Article 3 reserves threat intelligence for material "aggregated, transformed, analysed, interpreted or enriched" to the point where it gives a decision-maker the context to act. A raw list of hashes is shareable either way. What it gives your triage step is a lookup, and the enriched version is what tells you whether to act.
|
Shareable under Article 45 |
Withhold, or handle under a documented protocol |
|
Indicators of compromise: malicious IPs, domains, file hashes, URLs |
Personal data about individuals, whether staff or customers, where GDPR applies |
|
Tactics, techniques and procedures: attacker methodologies, kill-chain stages |
Detail that exposes your own unremediated weaknesses and creates fresh risk |
|
Cyber security alerts: active threat warnings, campaign notifications |
Commercially sensitive material such as pricing, market strategy or client lists |
|
Configuration tools: detection rules, YARA signatures, SIEM queries |
Material under legal privilege or a separate regulatory confidentiality duty |
|
Threat actor profiles: attribution intelligence, behavioural patterns |
Operational detail identifying individual staff or their incident response roles |
The GDPR boundary catches teams more often than the competition one. Threat feeds carry email addresses, usernames and device identifiers tied to individuals, and those stay personal data whatever the cyber framing around them. Most summaries of Article 45 stop at "GDPR applies", where Recital 34 goes further and directs these mechanisms to operate on one or more of the legal bases in Article 6 GDPR, naming legitimate interest as an example. So the question to put to legal is which Article 6 basis applies here, and where that reasoning gets written down.
The competition boundary comes up less often and carries the same weight. Recital 34 points at the Commission’s Communication of 14 January 2011 on applying Article 101 of the Treaty on the Functioning of the European Union (TFEU) to horizontal co-operation agreements. Worth knowing before you draft anything: the Commission replaced it with revised Horizontal Guidelines in 2023, so terms written against the 2011 text are citing a superseded source even though DORA’s recital still points there. Keep shared content to technical threat data and the question rarely surfaces at all.
Which Trusted Community Fits Your Entity
DORA binds financial entities authorised or registered in the EU. A UK-headquartered group meets Article 45 through its EU-authorised entities, while its UK-only businesses sit under the separate Prudential Regulation Authority and Financial Conduct Authority operational resilience regime. That distinction shapes which community is the right one, because the governance terms that satisfy a competent authority in Dublin or Frankfurt are the ones Article 45(2) describes.
For most EU financial entities the practical route is an established sector body. FS-ISAC, the Financial Services Information Sharing and Analysis Center, runs global membership with regional structures, and its UK arm became steward of the Financial Sector Cyber Collaboration Centre in November 2025. CIISI-EU, the Cyber Information and Intelligence Sharing Initiative created by members of the Euro Cyber Resilience Board that the European Central Bank convenes, is a closed community by design: its members are pan-European financial infrastructures, central banks acting in an operational capacity, critical service providers, ENISA (the EU Agency for Cybersecurity) and Europol, so a bank or insurer will look elsewhere. Several national competent authorities run or endorse their own sector communities too, and that’s a call worth making before you look further afield.
Building your own arrangement stays open to you. Article 45 requires membership of no particular body, and a bilateral arrangement between two firms qualifies as long as its terms meet Article 45(2). The work sits in drafting those terms and keeping them current, and that work lands on whoever convenes the arrangement.
Run an Ingest, Assess, Act Loop
Membership and operation are separate achievements, and the gap between them is where most Article 45 programmes lose their evidence trail.
- Ingest means each item lands in a logged, access-controlled channel carrying its source and a timestamp.
- Assess means triaging it against your asset register and current risk profile: does this indicator exist in your environment, and would your detection rules catch this technique?
- Act means a control update, an alert to your security operations centre (SOC), a detection rule change or an escalation into incident response, with the reasoning recorded on the occasions where the right answer was to change nothing.
That loop is only as good as the links between its three stages, and those links are what a supervisory review actually reads. SureCloud holds the asset register, control library and incident workflow in the same environment the intelligence lands in, so a triage decision references live control coverage and an action traces back to the item that prompted it. Gracie AI Agents with Personas and Skills performs the assessment activities that otherwise queue behind one analyst, working to Skills your own team has codified once, so the hundredth triage matches the first. Every action an agent takes is written to an immutable reasoning log, which is the kind of record a supervisory review of your arrangement will ask to see.
Senior Agent Collaboration picks up the items that span domains. A campaign against a critical provider touches the risk register, control coverage and vendor management at once, and each part reaches its owner the same day.
How Pillar 5 Feeds the Other Four
Information sharing is the fifth of DORA’s five core requirements, and the only one measured by what it does to the other four.
|
Pillar |
What Pillar 5 intelligence changes |
|
ICT risk management |
New actor tactics and indicators update the risk register. A campaign against your sector’s cloud providers is a risk event, and it should trigger a review of asset criticality ratings and control coverage. |
|
Incident management and reporting |
Shared intelligence sharpens detection ahead of the event. A flagged phishing campaign using a known domain pattern becomes a detection rule change today rather than a post-incident finding next quarter. |
|
Digital operational resilience testing |
The threat landscape analysis that opens a threat-led penetration test draws on the sector-level intelligence an arrangement supplies, which usually makes your scope easier to defend to the authority reviewing it. |
|
ICT third-party risk management |
Intelligence about attacks on shared providers adds signal to vendor assessments. An actively targeted critical provider changes your concentration risk position, sometimes before the provider tells you. |
Name an owner on each of those four receiving ends before the first item lands, or triage output stops at the triage queue. Two of the four carry obligations of their own the moment intelligence reaches them: an escalation has to clear the reporting clocks set out in DORA’s incident response governance requirements, and an input to testing scope has to survive the authority’s review of your threat-led penetration testing plan. Both of those routes get looked at in a review, so write down who owns each one.
Where Article 45 Programmes Stall
The feed collector
The firm joins, integrates, and starts receiving. Six months on, the feed lands in a shared inbox or a chat channel with no named owner, no triage step and no route to the risk register. Background noise, effectively. The tooling is usually fine, and what’s missing is a person whose job it is to read what arrives.
Article 45 leaves you free to conclude that a given item needs nothing from you, and on its own it asks for no record of that decision. The documentation obligation sits elsewhere in DORA: Article 6(1) requires a well-documented ICT risk management framework, and Article 13(1) requires capabilities and staff to gather information on vulnerabilities and cyber threats. Assign a named owner for triage, set a minimum weekly cadence, and log the outcome even when the outcome is "no exposure in our environment". Those log entries are what you show when someone asks what the membership produced.
The legal freeze
The second pattern runs the other way. The firm wants to contribute, legal raises GDPR and competition concerns, nobody can agree a scrubbing protocol, and contribution stalls. Both concerns are legitimate. They’re usually settled once someone writes the protocol down and legal signs it.
For GDPR, establish a pre-sharing pseudonymisation step, identify which Article 6 basis covers any residual personal data, and document both. For competition law, limit contributions to technical threat data and exclude commercial, strategic and operational context by rule, so nobody has to make the same judgement call twice. Once legal and compliance have signed off a repeatable process, contributions can go out without a fresh legal review each time.
Governance Checklist: What the Arrangement’s Terms Must Cover
Use this when evaluating a community to join, or when drafting terms of your own. The first four come straight from Article 45(2) and the fifth from Article 45(3); the rest are what supervisory reviews have been asking to see.
- Participation conditions: who is eligible, how membership is validated, and the grounds for removal.
- Public authority involvement: whether competent authorities or other public bodies take part, and in what capacity.
- ICT third-party involvement: whether managed service providers or cloud platforms can participate, and under what constraints.
- Operational platform detail: which systems carry the exchange, and the security controls applied to them.
- Notification process: how members notify their competent authority on joining and on cessation, under Article 45(3).
- Information classification rules: what may be shared, and how members label content before it goes out.
- Data protection protocol: how personal data is identified and removed, and the Article 6 GDPR basis for anything that remains.
- Competition compliance: explicit exclusion of commercial, pricing and strategic information, with the applicable guidelines named.
- Confidentiality obligations: what members may do with intelligence received, and what requires the originator’s consent.
- Escalation pathway: how an active or imminent threat reaches members, and authorities, faster than the standard cadence.
An arrangement that can evidence all ten has done the Article 45(2) work for you. Where it can only evidence some of them, the rest become yours to document, and it’s you the competent authority will ask.
Build an Article 45 programme that evidences itself
Found this useful?
Choose SureCloud as a preferred source in Google and you will see more of our GRC guidance in Top Stories, AI Overviews and AI Mode. It takes one click and you can undo it at any time.
Let Gracie get the work done.
Gracie drafts summaries, evidence requests and audit narratives across your programme — you stay in control.
See Gracie in action or book a full platform demo →See what SureCloud costs
A short form, no sales call. Pricing built around your GRC estate.
Get PricingIDC names SureCloud the industry's first cross-domain agentic GRC platform"
Read the independent analyst view on how SureCloud is redefining risk and compliance.
Download for freeFAQ’s
What counts as cyber threat information and intelligence under Article 45?
Article 45(1) names indicators of compromise, tactics, techniques and procedures, cyber security alerts and configuration tools. The word "including" in front of that list keeps it open, so the governing test is the purpose test in Article 45(1)(a): does the exchange aim to enhance digital operational resilience. Technical threat data serving that purpose is in scope. Commercial, strategic and personal data sits outside it.
Do I have to join a formal ISAC?
No. What Article 45 tests is the arrangement, so a bilateral exchange between two firms passes on the same terms a sector body does. What differs is documentation effort: an established Information Sharing and Analysis Centre arrives with participation conditions, platform security detail and authority-involvement clauses already drafted and kept current, where a bespoke arrangement makes all of that a standing obligation of yours. Maintaining those terms is usually the part that gets underestimated.
How does Article 45 interact with GDPR?
GDPR applies in full: Article 45(1)(c) requires rules of conduct respecting "protection of personal data in accordance with Regulation (EU) 2016/679". The part firms miss is which regulator hears about a failure. Sharing personal data without a basis is a matter for your data protection authority, on its own timetable and its own penalty regime, quite separately from anything your DORA competent authority does. Write the anonymisation protocol into the arrangement’s rules of conduct so every member carries it contractually.
Does Article 45 apply to every financial entity in scope for DORA?
It is available to every financial entity in DORA’s scope, and it compels none of them. The notification duty in Article 45(3) bites only once you choose to participate. Smaller entities applying the simplified ICT risk management framework under Article 16 are equally free to join, and the simplified framework gives them no relief from Article 45’s conditions once they do.
What happens if I join an arrangement and then leave?
Article 45(3) requires you to notify your competent authority of the cessation of membership once it takes effect, the same way you notified on joining. The regulation leaves the format open, so check your authority’s preferred channel and required content well before the exit itself. Keep the notification and its acknowledgement on file, since that’s the record which closes the loop on a membership a supervisor can still ask about years later.
Can ICT third-party providers take part in an information-sharing arrangement?
Article 45(1)(b) confines the exchange to trusted communities of financial entities, while Article 45(2) separately requires the arrangement’s terms to set out the involvement of ICT third-party service providers where appropriate. Read together, those two allow providers to be associated with an arrangement on terms the arrangement defines, with the community itself remaining one of financial entities. If providers are already inside the community you’re joining, get the capacity in which they participate in writing before your membership is validated.
Platform +
Frameworks +
Products +
Industries +
Resources +
Company +
London Office
Esavian House 181A High Holborn, London, WC1V 7QX, United Kingdom
US Headquarters
6010 W. Spring Creek Pkwy., Plano, TX 75024, United States of America
© SureCloud 2026. All rights reserved.
