Banque & financeVérifiée par Kopik: Sources officielles relues et réponses testées par Kopik

DORA major ICT incident reporting: classification criteria and deadlines

DORA requires financial entities to classify ICT-related incidents and report major ones to their competent authority on a strict timetable. This page covers the classification thresholds of Delegated Regulation (EU) 2024/1772 and the time limits of Delegated Regulation (EU) 2025/301.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

When an incident becomes major

An incident is major when it has affected critical services and either involves a successful, malicious and unauthorised access to network and information systems that may result in data losses, or meets two or more of the other materiality thresholds.

Those thresholds include: more than 10 % of the clients using the affected service, or more than 100 000 such clients; an incident lasting longer than 24 hours, or service downtime longer than 2 hours for ICT services supporting critical or important functions; an impact in two or more Member States; and costs and losses that exceed or are likely to exceed 100 000 euro.

Recurring incidents that are not major on their own count as one major incident if they occurred at least twice within 6 months, share the same apparent root cause and together meet the criteria. Entities assess this monthly, except microenterprises and Article 16(1) entities.

Time limits for the three reports

The initial notification is due as early as possible and within four hours of classifying the incident as major, and no later than 24 hours after becoming aware of it. If classification happens after those 24 hours, the four hours run from classification.

The intermediate report is due within 72 hours of the initial notification, even if nothing has changed, and must be updated when regular activities have been recovered. The final report is due no later than one month after the latest intermediate report.

Questions fréquentes

What happens if a deadline falls on a weekend or bank holiday?

The entity may submit by noon of the next working day. This relief does not apply to initial notifications and intermediate reports from credit institutions, central counterparties, trading venue operators and entities identified as essential or important under Directive (EU) 2022/2555.

What if we cannot meet a reporting deadline?

You must inform the competent authority without undue delay, and no later than the deadline itself, explaining the reasons for the delay.

Can significant cyber threats be reported too?

Yes, on a voluntary basis under Article 19(2) of DORA. Delegated Regulation (EU) 2025/301 sets out the content of such a voluntary notification, starting with general information about the notifying entity.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=eu-dora-ict-resilience
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-eu-dora-ict-resilience "https://kopik.io/api/mcp?base=eu-dora-ict-resilience" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-eu-dora-ict-resilience": {
      "url": "https://kopik.io/api/mcp?base=eu-dora-ict-resilience",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/eu-dora-ict-resilience/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.