What starts a DORA regulatory report?
A financial entity first classifies the ICT-related incident against DORA criteria and thresholds. A major incident then follows the harmonised initial, intermediate, and final reporting sequence.
Operating sequence
- 01
Capture affected services, clients, duration, geography, data loss, criticality, economic impact, and recurrence.
- 02
Assign classification authority and preserve the exact time the major-incident threshold was met.
- 03
Prepare staged reporting so new facts update the record without rewriting the earlier state.
Failure modes to avoid
- Treating every technical alert as a major incident.
- Waiting for root cause before sending the initial report.
- Running DORA and NIS2/GDPR reports as unrelated investigations.
The source remains the authority.
Commission Delegated Regulation (EU) 2024/1772 — EUR-Lex