Chapter 9 of 15
DORA Regulation (EU) 2022/2554 — ICT Incident Classification and Reporting
A disruption becomes a regulatory event through classification and reporting rules. Chapter III follows an incident from detection and impact assessment through initial, intermediate, and final reports, authority coordination, and possible future centralisation.
1. From Technical Disruption to Regulatory Event
The Chapter III sequence
DORA moves from detection to management, classification, reporting, authority coordination, and supervisory feedback.
Not every recorded incident is externally reportable. Article 19 requires reports for major ICT-related incidents; significant cyber-threat notification is voluntary.
Read the verbs carefully: shall is mandatory, while may creates permission rather than a duty.
2. Article 17: Build the Incident-Management Process
A process, not a paper policy
Article 17(1) says financial entities shall define, establish and implement a process to detect, manage, and notify ICT-related incidents.
"Financial entities shall record all ICT-related incidents and significant cyber threats." Records support monitoring, follow-up, root-cause identification, documentation, and prevention.
The process shall include early warnings, classification procedures, assigned roles, communication and escalation plans, management reporting, and timely secure restoration.
3. Worked Example: A Mobile-Banking Outage
Detect and log
Failed logins and payments trigger early warnings. The entity identifies, tracks, logs, categorises, and classifies the outage.
Different roles activate: technical response, communications, customer-complaint handling, internal escalation, and information for counterparts as appropriate.
Recovery is not enough. Article 17(2) requires the root cause to be identified, documented, and addressed to prevent recurrence.
4. Article 18: Classify Impact Before You Report
Six impact criteria
Classify incidents through affected people and transactions, duration, geography, data losses, service criticality, and economic impact.
Geography must include "the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States".
Article 18 distinguishes an ICT-related incident from a significant cyber threat and uses separate classification criteria for each.
5. Knowledge Check: Classification Criteria
Choose the best answer
Under Article 18(1), which statement is accurate?
Does an ICT-related incident affecting more than two Member States automatically become a major ICT-related incident under Article 18(1)?
- Yes. Article 18(1) makes cross-border impact across more than two Member States an automatic major-incident threshold.
- No. It is one geographical-spread criterion to consider when classifying impact; Article 18(1) does not state that it automatically makes the incident major.
- No. Geography is irrelevant because only duration and data loss determine classification.
- Yes. But only where no clients are affected.
Show Answer
Answer: B) No. It is one geographical-spread criterion to consider when classifying impact; Article 18(1) does not state that it automatically makes the incident major.
Article 18(1)(c) requires assessment of geographical spread, particularly where more than two Member States are affected. The provision does not say that this fact alone automatically determines that an incident is major.
6. Article 19(1)-(3): Mandatory Reports, Voluntary Threat Notices, and Clients
Mandatory: major incidents
"Financial entities shall report major ICT-related incidents to the relevant competent authority". Multiple national supervisors require one designated relevant authority.
A significant credit institution reports to its relevant national competent authority, which shall immediately transmit the report to the ECB.
Threat notification differs: entities may, on a voluntary basis, notify significant cyber threats when they deem them relevant to the stated interests.
Client information is mandatory without undue delay where a major incident affects clients' financial interests; threat advice applies where applicable.
7. Article 19(4)-(5): The Three-Stage Reporting Sequence
Stage 1: initial notification
Article 19(4) requires an initial notification within time limits laid down under Article 20. Article 19 itself gives no numeric deadline.
Stage 2 is "an intermediate report after the initial notification referred to in point (a)" when status or handling changes significantly.
Stage 3 is the final report: root-cause analysis completed and actual impact figures available, even if mitigation measures have not all been implemented.
Reporting may be outsourced under applicable Union and national sectoral law, but the financial entity remains fully responsible.
8. Articles 19(6)-(8), 22 and 23: Information Flows and Feedback
Competent-authority distribution
After receiving reports, the competent authority shall share details in a timely manner with listed recipients, as applicable to their competences.
The ESAs and ECB assess cross-border relevance with ENISA and the relevant competent authority. Other Member State authorities are notified as soon as possible.
Authorities shall acknowledge receipt and may, where feasible, give feedback. That feedback does not remove the entity's full responsibility.
Article 23 applies Chapter III requirements also to specified operational or security payment-related incidents involving the listed financial entities.
9. Articles 20-21: Harmonised Templates and the Possible EU Hub
Article 20: common reporting architecture
The ESAs shall develop technical standards for report content, time limits, threat-notification content, and standard forms, templates, and procedures.
Time limits may reflect financial-sector specificities as appropriate, but DORA requires a consistent approach to ICT-incident reporting.
Article 21 requires a feasibility assessment of a single EU Hub. It does not itself establish the Hub.
"The ESAs shall submit the report referred to in paragraph 1 to the European Parliament, to the Council and to the Commission by 17 January 2025."
10. Flashcards: Core Reporting Rules
Flip each card before moving on
Use the exact distinction between mandatory reporting and voluntary notification.
- Article 17 recordkeeping rule
- "Financial entities shall record all ICT-related incidents and significant cyber threats."
- When is Article 19 reporting mandatory?
- For major ICT-related incidents: "Financial entities shall report major ICT-related incidents to the relevant competent authority".
- Are significant cyber threats reported in the same mandatory way?
- No. Financial entities may, on a voluntary basis, notify significant cyber threats when they deem the threat relevant to the financial system, service users, or clients.
- Name the three Article 19(4) reporting stages
- An initial notification; an intermediate report after the initial notification; and a final report.
- When is the final report submitted?
- When root-cause analysis is completed and actual impact figures are available to replace estimates, regardless of whether mitigation measures have already been implemented.
- Does outsourcing reporting remove responsibility?
- No. The financial entity remains fully responsible for fulfilling incident-reporting requirements.
11. Scenario Challenge: Choose the Correct Sequence
A major incident evolves
A financial entity has classified an event as a major ICT-related incident. It has sent its initial notification. New forensic evidence changes the understanding of the incident's scope. Root-cause analysis is not yet complete, and the entity still has estimated rather than actual impact figures.
Choose the response that best reflects Article 19(4).
What should the entity do next?
- Wait until all mitigation measures are fully implemented, then submit only one final report.
- Submit an intermediate report after the initial notification because the incident status or handling has changed significantly based on new information; provide updated notifications as appropriate when relevant status updates are available or when specifically requested.
- Submit a voluntary significant-cyber-threat notification instead of further major-incident reporting.
- Stop reporting because the competent authority, rather than the entity, is responsible for further communications.
Show Answer
Answer: B) Submit an intermediate report after the initial notification because the incident status or handling has changed significantly based on new information; provide updated notifications as appropriate when relevant status updates are available or when specifically requested.
Article 19(4)(b) requires an intermediate report after the initial notification when the original incident's status has changed significantly or handling has changed based on new information. Updated notifications follow as appropriate when relevant updates are available and upon a specific request. The final report comes when root-cause analysis is complete and actual figures can replace estimates.
Key Terms
- ESA
- A European Supervisory Authority: EBA, ESMA, or EIOPA, depending on the relevant financial sector.
- CSIRT
- A computer security incident response team designated or established in accordance with Directive (EU) 2022/2555, referred to in Article 19 information flows and Article 22.
- final report
- The Article 19(4) report submitted after root-cause analysis is complete and actual impact figures are available to replace estimates.
- single EU Hub
- A possible centralised reporting arrangement assessed in the Article 21 joint report; Article 21 itself requires a feasibility assessment rather than establishing the Hub.
- intermediate report
- A report after the initial notification when the incident's status or handling changes significantly based on new information, followed by updates as appropriate or on specific request.
- ICT-related incident
- An incident that Article 17 requires financial entities to detect, manage, notify, and record; Article 18 requires it to be classified using specified impact criteria.
- initial notification
- The first of the Article 19(4) reporting stages for a major ICT-related incident.
- significant cyber threat
- A cyber threat classified under Article 18(2) based on criticality of services at risk, targeted clients or counterparts, and geographical spread of areas at risk; Article 19(2) provides for voluntary notification under its stated condition.
- major ICT-related incident
- An ICT-related incident subject to the mandatory reporting obligation in Article 19(1), with materiality further specified through the technical-standard framework contemplated by Article 18 and Article 20.
- relevant competent authority
- The authority referred to in Article 46 that receives Article 19 reports. Where more than one national competent authority supervises an entity, Member States shall designate one relevant competent authority for Article 19 functions and duties.