DORA major ICT incident reporting: classification criteria and deadlines
DORA requires financial entities to classify ICT-related incidents and report major ones to their competent authority on a strict timetable. This page covers the classification thresholds of Delegated Regulation (EU) 2024/1772 and the time limits of Delegated Regulation (EU) 2025/301.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
When an incident becomes major
An incident is major when it has affected critical services and either involves a successful, malicious and unauthorised access to network and information systems that may result in data losses, or meets two or more of the other materiality thresholds.
Those thresholds include: more than 10 % of the clients using the affected service, or more than 100 000 such clients; an incident lasting longer than 24 hours, or service downtime longer than 2 hours for ICT services supporting critical or important functions; an impact in two or more Member States; and costs and losses that exceed or are likely to exceed 100 000 euro.
Recurring incidents that are not major on their own count as one major incident if they occurred at least twice within 6 months, share the same apparent root cause and together meet the criteria. Entities assess this monthly, except microenterprises and Article 16(1) entities.
Time limits for the three reports
The initial notification is due as early as possible and within four hours of classifying the incident as major, and no later than 24 hours after becoming aware of it. If classification happens after those 24 hours, the four hours run from classification.
The intermediate report is due within 72 hours of the initial notification, even if nothing has changed, and must be updated when regular activities have been recovered. The final report is due no later than one month after the latest intermediate report.
Frequently asked questions
What happens if a deadline falls on a weekend or bank holiday?
The entity may submit by noon of the next working day. This relief does not apply to initial notifications and intermediate reports from credit institutions, central counterparties, trading venue operators and entities identified as essential or important under Directive (EU) 2022/2555.
What if we cannot meet a reporting deadline?
You must inform the competent authority without undue delay, and no later than the deadline itself, explaining the reasons for the delay.
Can significant cyber threats be reported too?
Yes, on a voluntary basis under Article 19(2) of DORA. Delegated Regulation (EU) 2025/301 sets out the content of such a voluntary notification, starting with general information about the notifying entity.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs β¬0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=eu-dora-ict-resilienceClaude Code, Cursor and other clients
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_β¦"{
"mcpServers": {
"kopik-eu-dora-ict-resilience": {
"url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
"headers": {
"Authorization": "Bearer kpk_β¦"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
-H "Authorization: Bearer kpk_β¦" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_β¦with your key. - Full details (responses, errors, JS and Python examples): developer docs.