SkarpSkarp

Chapter 9 of 15

DORA Regulation (EU) 2022/2554 — ICT Incident Classification and Reporting

A disruption becomes a regulatory event through classification and reporting rules. Chapter III follows an incident from detection and impact assessment through initial, intermediate, and final reports, authority coordination, and possible future centralisation.

22 min readen

1. From Technical Disruption to Regulatory Event

The Chapter III sequence

DORA moves from detection to management, classification, reporting, authority coordination, and supervisory feedback.

Not every recorded incident is externally reportable. Article 19 requires reports for major ICT-related incidents; significant cyber-threat notification is voluntary.

Read the verbs carefully: shall is mandatory, while may creates permission rather than a duty.

2. Article 17: Build the Incident-Management Process

A process, not a paper policy

Article 17(1) says financial entities shall define, establish and implement a process to detect, manage, and notify ICT-related incidents.

"Financial entities shall record all ICT-related incidents and significant cyber threats." Records support monitoring, follow-up, root-cause identification, documentation, and prevention.

The process shall include early warnings, classification procedures, assigned roles, communication and escalation plans, management reporting, and timely secure restoration.

3. Worked Example: A Mobile-Banking Outage

Detect and log

Failed logins and payments trigger early warnings. The entity identifies, tracks, logs, categorises, and classifies the outage.

Different roles activate: technical response, communications, customer-complaint handling, internal escalation, and information for counterparts as appropriate.

Recovery is not enough. Article 17(2) requires the root cause to be identified, documented, and addressed to prevent recurrence.

4. Article 18: Classify Impact Before You Report

Six impact criteria

Classify incidents through affected people and transactions, duration, geography, data losses, service criticality, and economic impact.

Geography must include "the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States".

Article 18 distinguishes an ICT-related incident from a significant cyber threat and uses separate classification criteria for each.

5. Knowledge Check: Classification Criteria

Choose the best answer

Under Article 18(1), which statement is accurate?

Does an ICT-related incident affecting more than two Member States automatically become a major ICT-related incident under Article 18(1)?

  1. Yes. Article 18(1) makes cross-border impact across more than two Member States an automatic major-incident threshold.
  2. No. It is one geographical-spread criterion to consider when classifying impact; Article 18(1) does not state that it automatically makes the incident major.
  3. No. Geography is irrelevant because only duration and data loss determine classification.
  4. Yes. But only where no clients are affected.
Show Answer

Answer: B) No. It is one geographical-spread criterion to consider when classifying impact; Article 18(1) does not state that it automatically makes the incident major.

Article 18(1)(c) requires assessment of geographical spread, particularly where more than two Member States are affected. The provision does not say that this fact alone automatically determines that an incident is major.

6. Article 19(1)-(3): Mandatory Reports, Voluntary Threat Notices, and Clients

Mandatory: major incidents

"Financial entities shall report major ICT-related incidents to the relevant competent authority". Multiple national supervisors require one designated relevant authority.

A significant credit institution reports to its relevant national competent authority, which shall immediately transmit the report to the ECB.

Threat notification differs: entities may, on a voluntary basis, notify significant cyber threats when they deem them relevant to the stated interests.

Client information is mandatory without undue delay where a major incident affects clients' financial interests; threat advice applies where applicable.

7. Article 19(4)-(5): The Three-Stage Reporting Sequence

Stage 1: initial notification

Article 19(4) requires an initial notification within time limits laid down under Article 20. Article 19 itself gives no numeric deadline.

Stage 2 is "an intermediate report after the initial notification referred to in point (a)" when status or handling changes significantly.

Stage 3 is the final report: root-cause analysis completed and actual impact figures available, even if mitigation measures have not all been implemented.

Reporting may be outsourced under applicable Union and national sectoral law, but the financial entity remains fully responsible.

8. Articles 19(6)-(8), 22 and 23: Information Flows and Feedback

Competent-authority distribution

After receiving reports, the competent authority shall share details in a timely manner with listed recipients, as applicable to their competences.

The ESAs and ECB assess cross-border relevance with ENISA and the relevant competent authority. Other Member State authorities are notified as soon as possible.

Authorities shall acknowledge receipt and may, where feasible, give feedback. That feedback does not remove the entity's full responsibility.

Article 23 applies Chapter III requirements also to specified operational or security payment-related incidents involving the listed financial entities.

9. Articles 20-21: Harmonised Templates and the Possible EU Hub

Article 20: common reporting architecture

The ESAs shall develop technical standards for report content, time limits, threat-notification content, and standard forms, templates, and procedures.

Time limits may reflect financial-sector specificities as appropriate, but DORA requires a consistent approach to ICT-incident reporting.

Article 21 requires a feasibility assessment of a single EU Hub. It does not itself establish the Hub.

"The ESAs shall submit the report referred to in paragraph 1 to the European Parliament, to the Council and to the Commission by 17 January 2025."

10. Flashcards: Core Reporting Rules

Flip each card before moving on

Use the exact distinction between mandatory reporting and voluntary notification.

Article 17 recordkeeping rule
"Financial entities shall record all ICT-related incidents and significant cyber threats."
When is Article 19 reporting mandatory?
For major ICT-related incidents: "Financial entities shall report major ICT-related incidents to the relevant competent authority".
Are significant cyber threats reported in the same mandatory way?
No. Financial entities may, on a voluntary basis, notify significant cyber threats when they deem the threat relevant to the financial system, service users, or clients.
Name the three Article 19(4) reporting stages
An initial notification; an intermediate report after the initial notification; and a final report.
When is the final report submitted?
When root-cause analysis is completed and actual impact figures are available to replace estimates, regardless of whether mitigation measures have already been implemented.
Does outsourcing reporting remove responsibility?
No. The financial entity remains fully responsible for fulfilling incident-reporting requirements.

11. Scenario Challenge: Choose the Correct Sequence

A major incident evolves

A financial entity has classified an event as a major ICT-related incident. It has sent its initial notification. New forensic evidence changes the understanding of the incident's scope. Root-cause analysis is not yet complete, and the entity still has estimated rather than actual impact figures.

Choose the response that best reflects Article 19(4).

What should the entity do next?

  1. Wait until all mitigation measures are fully implemented, then submit only one final report.
  2. Submit an intermediate report after the initial notification because the incident status or handling has changed significantly based on new information; provide updated notifications as appropriate when relevant status updates are available or when specifically requested.
  3. Submit a voluntary significant-cyber-threat notification instead of further major-incident reporting.
  4. Stop reporting because the competent authority, rather than the entity, is responsible for further communications.
Show Answer

Answer: B) Submit an intermediate report after the initial notification because the incident status or handling has changed significantly based on new information; provide updated notifications as appropriate when relevant status updates are available or when specifically requested.

Article 19(4)(b) requires an intermediate report after the initial notification when the original incident's status has changed significantly or handling has changed based on new information. Updated notifications follow as appropriate when relevant updates are available and upon a specific request. The final report comes when root-cause analysis is complete and actual figures can replace estimates.

Key Terms

ESA
A European Supervisory Authority: EBA, ESMA, or EIOPA, depending on the relevant financial sector.
CSIRT
A computer security incident response team designated or established in accordance with Directive (EU) 2022/2555, referred to in Article 19 information flows and Article 22.
final report
The Article 19(4) report submitted after root-cause analysis is complete and actual impact figures are available to replace estimates.
single EU Hub
A possible centralised reporting arrangement assessed in the Article 21 joint report; Article 21 itself requires a feasibility assessment rather than establishing the Hub.
intermediate report
A report after the initial notification when the incident's status or handling changes significantly based on new information, followed by updates as appropriate or on specific request.
ICT-related incident
An incident that Article 17 requires financial entities to detect, manage, notify, and record; Article 18 requires it to be classified using specified impact criteria.
initial notification
The first of the Article 19(4) reporting stages for a major ICT-related incident.
significant cyber threat
A cyber threat classified under Article 18(2) based on criticality of services at risk, targeted clients or counterparts, and geographical spread of areas at risk; Article 19(2) provides for voluntary notification under its stated condition.
major ICT-related incident
An ICT-related incident subject to the mandatory reporting obligation in Article 19(1), with materiality further specified through the technical-standard framework contemplated by Article 18 and Article 20.
relevant competent authority
The authority referred to in Article 46 that receives Article 19 reports. Where more than one national competent authority supervises an entity, Member States shall designate one relevant competent authority for Article 19 functions and duties.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself