Skip to main content
DORA Auditor

ICT Incident Reporting under DORA

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

DORA's incident-reporting pillar (Articles 17–23) requires financial entities to detect, manage, classify, and report major ICT-related incidents to their competent authority using a harmonised template and defined timelines.

Classification

Incidents are assessed against criteria such as the number of clients affected, duration, geographic spread, data losses, and economic impact to determine whether they are major and therefore reportable.

Reporting timelines

Major incidents follow a three-stage flow, an initial notification, an intermediate report, and a final report, with deadlines set out in the regulatory technical standards. Our incident classifier helps estimate whether an incident is reportable.

Articles 21-23: the rest of the pillar

The pillar runs to Article 23, not Article 20, and the last three articles cover ground beyond classification and timelines. See Article 21 on the feasibility report for centralising incident reporting through a single EU hub, Article 22 on the supervisory feedback competent authorities give back to reporting entities, and Article 23, which folds payment-related operational and security incidents into the same reporting regime, replacing the equivalent duty entities previously had under PSD2.

Frequently asked questions

What counts as a major incident under DORA?
Do Articles 21-23 add new reporting duties?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex