ICT Risk Management
Articles 5–16 — Governance, risk framework, protection, detection, response & recovery
ICT-Related Incident Management
Articles 17–23 — Classification, reporting, and major incident handling
Digital Operational Resilience Testing
Articles 24–27 — Testing programme, TLPT, and vulnerability assessments
ICT Third-Party Risk Management
Articles 28–44 — Outsourcing, contractual requirements, and oversight
Information Sharing Arrangements
Article 45 — Cyber threat intelligence, voluntary sharing, and cross-sector collaboration