DORA Article 45: Sharing Cyber Threat Intelligence Compliantly

DORA Article 45 allows financial entities in the EU to exchange cyber threat information and intelligence with each other on a voluntary basis. The exchange must take place within trusted communities, run through formal information-sharing arrangements, and respect business confidentiality, GDPR and competition rules. Where a financial entity joins or leaves such an arrangement, it must notify its competent authority.
What Is DORA Article 45 on Cyber Threat Intelligence Sharing
Purpose of Article 45 Within the DORA Framework
Article 45 sits in Chapter VI of Regulation (EU) 2022/2554, the Digital Operational Resilience Act, which has applied since 17 January 2025. It gives financial entities a clear legal basis to exchange cyber threat information and intelligence. Before DORA, sharing was often local and informal, and legal uncertainty made many firms cautious.
The article sets the conditions under which sharing is acceptable. The purpose must be to strengthen digital operational resilience, the exchange must happen inside trusted communities, and the arrangement must protect sensitive information through agreed rules of conduct.
Why Information Sharing Matters for Financial Entities
Cyber threats rarely stay with one institution. A phishing campaign, a malware family or an exploited vulnerability can reach several banks, insurers or payment firms within days. The recitals of DORA note that sharing awareness of threats limits the spread of ICT risk and reduces the chance of contagion across financial channels.
For a security team, a shared indicator of compromise can turn a late detection into an early one. For a board, shared intelligence gives a more accurate view of the threat landscape the entity actually faces.
Financial Entities Within the Scope of Article 45
Article 45 refers to financial entities, which DORA defines in Article 2. The list covers credit institutions, payment and e-money institutions, investment firms, insurance and reinsurance undertakings, crypto-asset service providers, central securities depositories, trading venues and several other categories. Entities covered by DORA can use Article 45 as the basis for their participation.
Build Digital Operational Resilience With DORA Compliance. Demonstrate Regulatory Alignment With INTERCERT.
DORA Article 45 Information Sharing Requirements
Voluntary Nature of Information-Sharing Arrangements
Participation is a choice. Article 45 states that financial entities “may” exchange information, so no entity is obliged to join a sharing arrangement. This differs from major ICT-related incident reporting, which is mandatory under Article 19. An entity that chooses not to participate does not breach DORA by that decision alone.
Types of Cyber Threat Information and Intelligence Covered
Article 45 names indicators of compromise, tactics, techniques and procedures, cyber security alerts and configuration tools. In practice this includes malicious IP addresses, domains and file hashes, descriptions of attacker behaviour, early warnings about active campaigns, and settings that reduce exposure to a known threat.
The scope is cyber threat information. Commercial data, client records and strategic business information fall outside what Article 45 is designed to cover.
Conditions for Sharing Under Article 45
Three conditions apply together. The sharing must aim to strengthen digital operational resilience, for example by raising awareness, limiting the spread of a threat, improving detection or improving response and recovery. It must take place within trusted communities of financial entities. It must also run through arrangements that protect sensitive information and follow rules of conduct covering business confidentiality, personal data protection under GDPR and competition policy.
Trusted Communities of Financial Entities
A trusted community is a closed group of financial entities with agreed membership criteria and rules. It is not an open forum. Examples in the EU include sector information sharing and analysis centres and similar national or cross-border groups. The exact form is left to the participants, but members should be vetted and bound by the same confidentiality terms.
DORA Information-Sharing Arrangements for Financial Entities
Structure and Membership of Sharing Arrangements
Article 45(2) requires the arrangement to define the conditions for participation. Where appropriate, it must also describe the role of public authorities, the involvement of ICT third-party service providers and operational elements such as the use of dedicated IT platforms. This means the arrangement itself should state who may join, in what capacity and through which channels.
Rules of Participation and Operating Terms
Operating terms usually cover the handling of shared material, the classification of information, who may receive it, how long it may be retained and what happens when a member leaves. Many communities use a traffic-light style marking so that recipients know how far a piece of intelligence may be passed on. Clear terms also set out what members must not share.
Protecting Confidentiality and Sensitive Information
Threat intelligence can reveal weaknesses in an entity’s own systems. Arrangements should therefore limit access to named roles, use encrypted channels and remove details that identify the contributing entity when that is not necessary. Members should also agree how a suspected leak is reported and investigated.
Handling Business Confidentiality and Competition Considerations
Financial entities are competitors, so the arrangement must stay within cyber security topics. Discussions about pricing, clients, strategy or market positioning do not belong in a threat intelligence exchange and could raise competition law concerns. Agendas, platform rules and moderation should keep the exchange technical.
Data Protection Considerations in Threat Intelligence Sharing
Much threat intelligence contains no personal data, such as file hashes or malicious domains. Some does, for example IP addresses, email addresses of attackers or details drawn from phishing messages. Where personal data is involved, GDPR applies in full. Entities should share only what is necessary, anonymise or pseudonymise where possible and document the legal basis they rely on. Article 45 does not override GDPR.
How to Share Cyber Threat Intelligence Under DORA
Identifying Intelligence Suitable for Sharing
Start by deciding which categories of information add value to peers and carry low risk for your own organisation. Technical indicators and attacker behaviour descriptions are usually the safest. Material that exposes your architecture, names clients or contains unredacted personal data should be filtered before anything leaves the entity.
Selecting a Compliant Sharing Arrangement
Check that the community has defined membership rules, written conduct rules, a stated approach to GDPR and competition law, and a clear position on the role of authorities and ICT third-party providers. If these elements are missing, the arrangement may not meet Article 45(1)(c) and (2). Legal and data protection teams should review the terms before membership is confirmed.
Setting Internal Roles, Approvals and Sharing Procedures
Name the people who may share and receive intelligence, usually from the security operations or threat intelligence function. Define who approves outbound sharing, how sensitive items are escalated to legal or the data protection officer and how decisions are recorded. A short internal procedure prevents informal sharing that sits outside the arrangement.
Securing Channels and Controlling Access to Shared Information
Use the platform agreed by the community or another channel with strong authentication, encryption and logging. Limit access on a need-to-know basis and review it regularly. Shared intelligence should be stored with the same level of protection as other sensitive security data.
Using Shared Intelligence Within Internal Security Processes
Intelligence only creates value when it reaches detection and response. Feed validated indicators into monitoring tools, use attacker behaviour reports to tune detection rules and brief incident response teams on active campaigns. Record which shared items led to action, since that shows the exchange has a practical effect on resilience.
DORA Cyber Threat Information Sharing Compliance
Notifying Competent Authorities About Participation
Article 45(3) requires financial entities to notify their competent authority of their participation in an information-sharing arrangement once their membership is validated. They must also notify the authority when their membership ends, once the cessation takes effect. The notification concerns participation. It does not require the entity to hand over the intelligence it exchanges. The exact notification format and channel are set by each national competent authority, so confirm the local process.
Recording and Retaining Evidence of Sharing Activities
DORA does not prescribe a specific record format for Article 45 activity. Good practice is to keep the membership confirmation, the arrangement terms, the authority notification, approval records for outbound sharing and logs showing how shared intelligence was used. This evidence makes it easier to answer a supervisory question or an audit query.
Linking Article 45 to ICT Risk Management and Incident Reporting
Article 45 works alongside the ICT risk management framework in Chapter II and the incident management provisions in Chapter III. Shared intelligence can improve threat identification and response planning. It does not replace mandatory reporting. Major ICT-related incidents must still be reported to the competent authority under Article 19, and Article 19 also allows voluntary notification of significant cyber threats.
Governance and Management Body Oversight
The management body is responsible for the entity’s ICT risk framework under Article 5 of DORA. Participation in a sharing arrangement should therefore be visible at that level, with a clear owner, a defined risk appetite for what may be shared and periodic reporting on how the arrangement is used. Accountability stays with the financial entity, even when a platform or a third party operates the exchange.
Role of Independent Assurance in Information-Sharing Compliance
Reviewing Controls Around Threat Intelligence Sharing
An independent review can test whether the controls around sharing work as described. Typical points include access control to shared intelligence, handling of personal data, approval records and incident escalation. These controls overlap with information security management requirements, so they are often examined within broader security assessments.
Certification and Assurance Evidence for Financial Entities
DORA does not create a certification scheme for Article 45, so no certificate proves compliance with it directly. Financial entities can still use recognised standards and attestations as supporting evidence of control maturity. ISO/IEC 27001 certification shows that an information security management system has been independently assessed. ISO 22301 addresses business continuity, and SOC 2 reports address controls over security and confidentiality. INTERCERT, an accredited certification and assurance body serving more than 10,000 clients across 28+ countries, provides independent certification and security assessments, including penetration testing, that financial entities can use as evidence in their wider DORA documentation. INTERCERT does not act as an implementer and does not replace the entity’s own compliance accountability.
Common Challenges in Cyber Threat Intelligence Sharing Under DORA
Legal and Confidentiality Concerns
Legal teams often worry about disclosing weaknesses, breaching contracts or crossing competition law lines. Clear arrangement terms, a defined list of what may be shared and legal review before joining address most of these concerns.
Trust and Participation Barriers
Members share more when they trust that information will not be misused or traced back to them. Trust grows through vetted membership, consistent rules and visible handling of breaches of those rules. Small entities may hold back because they fear contributing too little, although receiving intelligence can still improve their detection.
Quality and Timeliness of Shared Intelligence
Intelligence loses value quickly. Indicators that arrive late, without context or with many false positives create work without improving protection. Communities perform better when they set quality expectations, mark confidence levels and remove outdated items.
DORA Article 45 Compliance Checklist for Financial Entities
- Confirm that the entity falls within the scope of DORA Article 2.
- Decide, at management body level, whether and how the entity will participate.
- Select a trusted community with written membership conditions and conduct rules.
- Confirm that the arrangement addresses business confidentiality, GDPR and competition policy.
- Check how the arrangement treats public authorities, ICT third-party providers and dedicated platforms.
- Assign named roles and approval steps for outbound and inbound intelligence.
- Apply data minimisation, anonymisation or pseudonymisation to any personal data.
- Use secured channels with access control and logging.
- Notify the competent authority when membership is validated and when it ends.
- Keep records of membership, approvals and use of shared intelligence.
- Keep Article 19 incident reporting separate and fully operational.
- Review the arrangement and its results on a regular schedule.
Strengthen Digital Resilience Across Financial Operations. Verify Your DORA Compliance With INTERCERT.
Why Choose INTERCERT for DORA
Independent Assurance From an Accredited Body
INTERCERT is a globally accredited certification and assurance organization trusted by more than 10,000 clients across 28+ countries. Financial entities preparing evidence for DORA need an assessor whose findings carry weight with boards, auditors and competent authorities. Because INTERCERT is not an implementor and does not design the controls it assesses, its results stay objective and independent.
Assurance Evidence for the Controls DORA Examines
DORA does not create a certification scheme, so no certificate proves compliance with the regulation itself. What financial entities can show is independent evidence that the controls behind their ICT risk management and information sharing work as intended. INTERCERT delivers ISO/IEC 27001 certification for information security management and ISO 22301 certification for business continuity. It also provides SOC 2 attestation and VAPT services that test systems against real attack techniques. These results sit alongside the entity’s own DORA records as third-party evidence.
Security Testing That Reflects Real Threats
Threat intelligence is only useful if the entity’s defences respond to it. VAPT from INTERCERT tests whether systems resist the attack methods that shared intelligence describes, and gives management a factual view of exposure. As a PCI QSA, INTERCERT also assesses payment card security for organisations in the payments chain.
Experience Across European and Global Markets
With operations spanning the EU, the USA, the Middle East, India, Africa and the Philippines, INTERCERT works with financial entities and ICT providers that operate across borders. This matters under DORA, where a financial entity’s ICT third-party providers often sit in several jurisdictions and are expected to show consistent security standards.