ICT Incident Reporting under DORA
DORA's incident-reporting pillar (Articles 17–23) requires financial entities to detect, manage, classify, and report major ICT-related incidents to their competent authority using a harmonised template and defined timelines.
Classification
Incidents are assessed against criteria such as the number of clients affected, duration, geographic spread, data losses, and economic impact to determine whether they are major and therefore reportable.
Reporting timelines
Major incidents follow a three-stage flow, an initial notification, an intermediate report, and a final report, with deadlines set out in the regulatory technical standards. Our incident classifier helps estimate whether an incident is reportable.
Articles 21-23: the rest of the pillar
The pillar runs to Article 23, not Article 20, and the last three articles cover ground beyond classification and timelines. See Article 21 on the feasibility report for centralising incident reporting through a single EU hub, Article 22 on the supervisory feedback competent authorities give back to reporting entities, and Article 23, which folds payment-related operational and security incidents into the same reporting regime, replacing the equivalent duty entities previously had under PSD2.
Frequently asked questions
What counts as a major incident under DORA?
An incident that meets thresholds across criteria such as clients affected, duration, data loss, and economic impact, as defined in the RTS on classification.
Do Articles 21-23 add new reporting duties?
Not new duties on top of Articles 17-20. Article 21 concerns a feasibility study on centralised EU reporting, Article 22 covers the feedback entities receive from supervisors, and Article 23 brings payment-related incidents (formerly reported under PSD2) into the same DORA regime.