Regulation (EU) 2022/2554

DORA’s ICT incident reporting clock

Build classification, initial notification, intermediate reporting, and final reporting as one owned operational path.

Written and reviewed by Fredrik Surtell ·

What starts a DORA regulatory report?

A financial entity first classifies the ICT-related incident against DORA criteria and thresholds. A major incident then follows the harmonised initial, intermediate, and final reporting sequence.

Operating sequence

  1. 01

    Capture affected services, clients, duration, geography, data loss, criticality, economic impact, and recurrence.

  2. 02

    Assign classification authority and preserve the exact time the major-incident threshold was met.

  3. 03

    Prepare staged reporting so new facts update the record without rewriting the earlier state.

Failure modes to avoid

  • Treating every technical alert as a major incident.
  • Waiting for root cause before sending the initial report.
  • Running DORA and NIS2/GDPR reports as unrelated investigations.

The source remains the authority.

Commission Delegated Regulation (EU) 2024/1772 — EUR-Lex