DORA major incident reporting: classify first, then the clock starts

Updated 12 min read cyberincidentreporting.eu

DORA is the only one of the four EU reporting regimes whose first deadline does not run from the moment you find out. It runs from the moment you decide, and that single design choice changes how the whole first day has to be organized.

Who Article 19 binds, and who only looks like it

Article 19(1) of Regulation (EU) 2022/2554 requires financial entities to report major ICT-related incidents to the relevant competent authority referred to in Article 46. Where an entity is supervised by more than one national competent authority, the Member State designates a single relevant one. A credit institution classified as significant under Article 6(4) of Regulation (EU) No 1024/2013 reports to the relevant national competent authority designated under Article 4 of Directive 2013/36/EU, which must immediately transmit the report to the European Central Bank.

Article 2(1) lists twenty types at points (a) to (t): credit institutions; payment institutions including exempted ones; account information service providers; electronic money institutions including exempted ones; investment firms; crypto-asset service providers and issuers of asset-referenced tokens; central securities depositories; central counterparties; trading venues; trade repositories; managers of alternative investment funds; management companies; data reporting service providers; insurance and reinsurance undertakings; insurance, reinsurance and ancillary insurance intermediaries; institutions for occupational retirement provision; credit rating agencies; administrators of critical benchmarks; crowdfunding service providers; and securitisation repositories.

Article 2(3) carves several populations back out again: small managers of alternative investment funds under Article 3(2) of Directive 2011/61/EU, undertakings under Article 4 of Directive 2009/138/EC, institutions for occupational retirement provision with no more than fifteen members in total, persons exempted under Articles 2 and 3 of Directive 2014/65/EU, insurance and reinsurance intermediaries and ancillary intermediaries that are micro, small or medium-sized enterprises, and post office giro institutions. Article 2(4) lets a Member State exclude the entities listed in Article 2(5), points (4) to (23) of Directive 2013/36/EU that are located on its territory.

Classification is the trigger

Article 19 does not tell you when an incident is major. Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 does, and the whole timetable hangs off it.

Article 8(1) of that Regulation states the gate. An incident is a major incident where it has affected critical services as referred to in Article 6, and where either the materiality threshold in Article 9(5), point (b) is met, or two or more of the other materiality thresholds in Article 9(1) to (6) are met. Article 6 defines "affected critical services" as whether the incident affects ICT services or systems that support critical or important functions; affects financial services requiring authorisation, registration or supervision; or constitutes a successful, malicious and unauthorised access to the entity's network and information systems.

The asymmetry in Article 8(1) is the thing to internalise. One threshold, and only one, makes an incident major on its own.

The materiality thresholds in Article 9 of Delegated Regulation (EU) 2024/1772
CriterionThresholdOn its own?
Clients, financial counterparts and transactions, Art. 9(1)More than 10 per cent of clients using the affected service, or more than 100 000 clients; more than 30 per cent of financial counterparts; more than 10 per cent of the daily average number or value of transactions; or any client or counterpart identified as relevant under Article 1(3)No, needs a second
Reputational impact, Art. 9(2)The incident has been reflected in the media, or produced repetitive complaints from different clients or counterparts, or you will or may be unable to meet regulatory requirements as a result, or you will or may lose clients or counterparts with material effectNo, needs a second
Duration and service downtime, Art. 9(3)Duration longer than 24 hours, or service downtime longer than 2 hours for ICT services supporting critical or important functionsNo, needs a second
Geographical spread, Art. 9(4)Impact in two or more Member StatesNo, needs a second
Data losses, Art. 9(5)(a)Any impact on availability, authenticity, integrity or confidentiality of data that has or will adversely affect your business objectives or your ability to meet regulatory requirementsNo, needs a second
Data losses, Art. 9(5)(b)Any successful, malicious and unauthorised access to network and information systems where such access may result in data lossesYes, on its own
Economic impact, Art. 9(6)Costs and losses incurred that have exceeded or are likely to exceed EUR 100 000No, needs a second
Article 8(2) also aggregates recurring incidents: two or more within six months with the same apparent root cause that collectively satisfy Article 8(1) count as one major incident. Entities must assess recurrence monthly. This does not apply to microenterprises or to the entities listed in DORA Article 16(1).

Article 9(5)(b) is why a ransomware intrusion at a bank is almost always major. A successful, malicious and unauthorised access that may result in data losses satisfies the standalone limb, and the same access simultaneously satisfies Article 6(c), which asks whether the incident constitutes such an access. The gate and the threshold are both cleared by one fact.

Measuring the inputs you will be asked for

Two of the thresholds are quantities that have to be measured, and the Regulation says how.

Article 3(1) measures duration from the moment the incident occurs until it is resolved. Where the entity cannot determine when it occurred, duration runs from detection; where the entity later learns that the incident predates detection, it runs from the moment it is recorded in network or system logs or other data sources. Where resolution is not yet known, estimates apply. Article 3(2) measures service downtime from the moment the service is fully or partially unavailable to clients, counterparts or other users, until regular activities have been restored to the pre-incident service level, extended to the point at which a delayed service is fully provided.

Article 7 defines economic impact and is unusually specific about what counts. It includes expropriated funds and assets lost to theft; replacement or relocation of software, hardware or infrastructure; staff costs including replacement, extra recruitment, overtime and recovery of lost skills; fees for non-compliance with contractual obligations; redress and compensation to customers; forgone revenue; internal and external communication costs; and advisory costs including legal counselling, forensic services and remediation. It expressly excludes day-to-day maintenance, post-incident enhancements and upgrades, and insurance premiums. Article 7(1) requires the sum to be taken without accounting for financial recoveries, which are reported separately.

The EUR 100 000 threshold is reached faster than most firms model, because forensic and legal advisory costs are inside it and general maintenance is not.

The three filings and their time limits

Commission Delegated Regulation (EU) 2025/301 of 23 October 2024, adopted under Article 20 of DORA, carries the deadlines. Article 5(1) sets them out.

Time limits under Article 5(1) of Delegated Regulation (EU) 2025/301
FilingDeadlineRuns from
Initial notificationAs early as possible, and in any case within 4 hours, and no later than 24 hours from becoming aware of the incidentClassification of the incident as a major ICT-related incident
Intermediate reportAt the latest within 72 hours, even where the status or handling of the incident has not changed. Updated without undue delay, and in any case once regular activities have been recoveredSubmission of the initial notification
Final reportNo later than one monthSubmission of the intermediate report, or of the latest updated intermediate report
Article 5(2) covers late classification: where an entity has not classified the incident as major within 24 hours of becoming aware of it but classifies it as major later, the initial notification is due within four hours of that classification.

Two features of the first row matter more than the number itself. The four hours run from classification, so the practical question on day one is not "when must we file?" but "when must we decide?". And the 24-hour cap is measured from awareness, so an entity that spends twenty hours deliberating has four hours left, not four hours more.

The intermediate report is unconditional. Article 5(1)(b) requires it within 72 hours of the initial notification even where nothing about the incident has changed. That is a genuine difference from the NIS2 chain, where the intermediate report exists only if the CSIRT asks for one.

What each filing must contain

Article 1 of Delegated Regulation (EU) 2025/301 sets general information that appears in all three: the type of submission; the name of the financial entity, its LEI code and its Article 2(1) type; the name and identification code of whoever is submitting on its behalf; the names and LEI codes of all entities covered by an aggregated submission where applicable; the contact details of the people responsible for communicating with the competent authority; the identification of the group parent undertaking where applicable; and, where there is monetary impact, the currency the amounts are based on.

Article 2 adds the initial notification: your own incident reference code; the date and time of detection and of classification under Article 8 of Delegated Regulation (EU) 2024/1772; a description of the incident; the criteria in Articles 1 to 8 of that Regulation on which you classified it as major; the Member States impacted; how the incident was discovered; information about its origin where available; whether a business continuity plan has been activated; information about reclassification from major to non-major where applicable; and any other relevant information available.

Article 3 adds the intermediate report: the incident reference code the competent authority gave you; the date and time the incident occurred; the date and time regular activities were recovered where applicable; how the 2024/1772 criteria were fulfilled; the type of incident; the threats and techniques used by the threat actor where applicable; affected functional areas and business processes; affected infrastructure components supporting business processes; the impact on the financial interest of clients; information about reporting the incident to other authorities; temporary actions or measures taken or planned; and indicators of compromise where applicable.

Article 4 adds the final report: the root causes; the dates and times the incident was resolved and the root causes addressed; information on the resolution; information relevant for resolution authorities where applicable; direct and indirect costs and losses and information about financial recoveries; and information about recurring incidents where applicable.

Weekends, bank holidays and who does not get the relief

Article 5(4) provides that where a time limit falls on a weekend day or a bank holiday in the entity's Member State, the entity may submit by noon of the next working day. It is a real and useful concession, and a large part of the market does not have it.

Article 5(5) removes the relief, for the initial notification and the intermediate report, from credit institutions, central counterparties, operators of trading venues, and any other financial entity identified as an essential or important entity under Article 3 of Directive (EU) 2022/2555. Article 5(6) lets a competent authority remove it from other financial entities that are significant or of systemic character nationally or at Union level, by notifying them; that decision applies only to incidents reported after the notification.

Read Article 5(5) carefully if you are a mid-sized entity. Being identified as essential or important under national NIS2 rules withdraws your weekend relief under DORA, even though the NIS2 reporting duty itself has been disapplied for you by Article 4(1) of the Directive. The identification survives the disapplication.

Missing a deadline in the only permissible way

Article 5(3) requires an entity that is unable to submit within a time limit to inform the competent authority without undue delay, and no later than the respective time limit, and to explain the reasons for the delay. That is the difference between a late filing and a breach: the notice about the delay is itself due before the deadline it concerns.

Where the report goes next

Article 19(6) obliges the competent authority, on receipt of the initial notification and of each report, to provide details of the incident in a timely manner to EBA, ESMA or EIOPA; to the ECB for the entities in Article 2(1)(a), (b) and (d); to the competent authorities, single points of contact or CSIRTs designated under NIS2; to the resolution authorities under Article 3 of Directive 2014/59/EU and to the Single Resolution Board for the relevant entities; and to other relevant public authorities under national law.

That routing is the mechanism by which DORA satisfies NIS2 Article 4(2)(b), and it is why a financial entity does not file separately with its CSIRT. Article 19(1), sixth subparagraph, does allow a Member State to require some or all financial entities to provide the same notification and reports to the NIS2 authorities or CSIRTs as well, using the same templates, so check whether yours has.

Article 19(5) permits outsourcing the reporting obligation to a third-party service provider in accordance with Union and national sectoral law, while leaving the financial entity fully responsible for the fulfilment of the requirements.

Clients, and the voluntary threat notification

Article 19(3) is a separate duty on a separate trigger. Where a major incident has an impact on the financial interests of clients, the entity must inform those clients about the incident and the measures taken to mitigate its adverse effects, without undue delay as soon as it becomes aware. For a significant cyber threat rather than an incident, the entity must where applicable inform potentially affected clients of appropriate protective measures.

Article 19(2) allows voluntary notification of significant cyber threats to the competent authority where the entity considers the threat relevant to the financial system, service users or clients. Article 6 of Delegated Regulation (EU) 2025/301 sets out what that notification contains, including the classification criteria in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 that would have been triggered had the threat materialised. Significant credit institutions may notify their national authority, which transmits to the ECB.

What DORA switches off, and what it does not

Article 1(2) states that in relation to financial entities identified as essential or important entities under national rules transposing Article 3 of Directive (EU) 2022/2555, DORA is a sector-specific Union legal act for the purposes of Article 4 of that Directive. Article 4(1) of the Directive then disapplies its relevant provisions, supervision and enforcement included. A bank runs one chain, not two.

The GDPR is untouched. If personal data are in the incident, Article 33 runs to the data protection supervisory authority on its own 72 hours from having become aware, in parallel with everything above, and the standalone Article 9(5)(b) trigger means the incident that made your DORA filing major is very often the same one that made a personal data breach notifiable.

If the entity also places a connected product on the EU market, Cyber Resilience Act Article 14 adds a manufacturer clock running to the coordinator CSIRT and ENISA. The reporting clock finder lays all of these out together for a given selection.

Sources

  1. Regulation (EU) 2022/2554 (DORA) EUR-Lex · 2022 Article 1(2) for the lex specialis declaration, Article 2 for scope, Article 19 for the reporting obligation and onward routing, Article 20 for the mandate behind the RTS, Article 30 for the key contractual provisions and Article 46 for the competent authorities.
  2. Commission Delegated Regulation (EU) 2025/301 EUR-Lex · 2025 Articles 1 to 4 for the content of the initial notification and the intermediate and final reports, Article 5 for the time limits and the weekend relief, and Article 6 for the voluntary cyber-threat notification.
  3. Commission Delegated Regulation (EU) 2024/1772 EUR-Lex · 2024 Articles 1 to 7 for the classification criteria and how duration, downtime and economic impact are measured, Article 8 for the major-incident gate and recurring incidents, and Article 9 for the materiality thresholds.
  4. Directive (EU) 2022/2555 (NIS2) EUR-Lex · 2022 Article 3 for the essential and important entity identification that Article 5(5) of Delegated Regulation (EU) 2025/301 refers to, and Article 4 for the disapplication of the Directive where a sector-specific act applies.

Questions

Related questions

Does the four-hour DORA deadline run from the incident or from finding out about it?
From neither. Article 5(1)(a) of Delegated Regulation (EU) 2025/301 runs the four hours from classification of the incident as a major ICT-related incident, with an outer limit of 24 hours from the moment the entity became aware of it. Article 5(2) then handles the case where classification comes later than 24 hours after awareness: the four hours run from that classification.
Does an ICT provider to a bank report under DORA?
Not under Article 19. ICT third-party service providers are in DORA scope under Article 2(1)(u), but Article 2(2) defines financial entities as points (a) to (t) only, and Article 19 obliges financial entities. The provider's duties are contractual: Article 30(2)(f) requires assistance to the financial entity at no additional cost or at a cost fixed in advance when an ICT incident related to the service occurs, and Article 30(2)(g) requires full cooperation with the financial entity's competent and resolution authorities. The same firm may separately be a NIS2 managed service provider with its own Article 23 clock.
Is a single incident that only meets one threshold ever major?
Yes, in exactly one case. Article 8(1)(a) of Delegated Regulation (EU) 2024/1772 makes an incident major where it affected critical services and the Article 9(5)(b) threshold is met: any successful, malicious and unauthorised access to network and information systems where such access may result in data losses. Every other threshold needs a second one alongside it under Article 8(1)(b).
Do we still file with our national CSIRT as well?
Only if your Member State says so. The default under DORA Article 19(6)(c) is that your financial competent authority passes the details to the NIS2 competent authorities, single points of contact and CSIRTs itself. Article 19(1), sixth subparagraph, allows a Member State to additionally require some or all financial entities to provide the same notification and reports to those bodies directly, so the answer is national.