Major ICT-Related Incident
A major ICT-related incident is an ICT incident that meets DORA's classification thresholds and must therefore be reported to the competent authority. Classification (Article 18) considers factors such as clients affected, duration, geographic spread, data losses, and economic impact.
Detailed explanation
DORA harmonises how financial entities decide which incidents are serious enough to report. An incident is assessed against materiality criteria set out in the regulation and its technical standards; if the relevant thresholds are crossed, it is 'major' and triggers mandatory reporting on a defined timeline, an initial notification, an intermediate report as understanding develops, and a final report with root-cause analysis. Entities must also notify affected clients where appropriate. Getting classification right matters: over-reporting wastes resources, while under-reporting risks supervisory penalties. Commission Delegated Regulation (EU) 2024/1772 sets out the classification methodology in detail: an incident is major if it meets at least two of the specified materiality criteria (clients or financial counterparties affected, transactions affected, reputational impact, duration and service downtime, geographic spread, data losses, and disruption to a critical or important function), or a single criterion combined with an economic-impact threshold of EUR 100,000 in gross direct and indirect costs. Classification is not a one-time judgement made at detection: entities must keep reassessing an incident against the thresholds as facts emerge, since something that looks minor when first spotted can cross the major threshold hours later. Once an incident is classified as major, the reporting clock starts, an initial notification within four hours of classification and no later than twenty-four hours after the entity first became aware of the incident, an intermediate report within seventy-two hours, and a final report within one month. If an entity later reclassifies a major incident as non-major, or the reverse, it must notify the competent authority of the change and its reasoning. On 3 June 2026 the ESAs published their first Article 22 report on major ICT-related incidents, covering the 2025 reporting year: financial entities across the EU reported 3,383 major incidents in total, an average of 0.18 per entity in scope, with more than 60% concentrated in credit institutions and a further 16% in payment services. Almost a third of reported incidents traced back to failures involving a third party, whether an ICT provider, another financial institution, or shared infrastructure, which is a useful early data point when weighing how much scrutiny to put on third-party dependencies under the third-party-risk pillar. Cybersecurity-related causes accounted for only 10% of major incidents in this first cycle, well below what many entities had budgeted supervisory attention for, though the ESAs flagged that this baseline could shift as AI-enabled attack tooling becomes more widely available.
In context
This term relates to the ICT Incident Reporting pillar and is grounded in DORA Article 18.