Regmindr
Guides

DORA incident reporting deadlines: 4 hours, 72 hours, 1 month

Updated

Under DORA Article 19 and Delegated Regulation (EU) 2025/301, a financial entity reports a major ICT-related incident to its competent authority in three steps: an initial notification within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within a month of the latest intermediate report.

Timeline of DORA major ICT-related incident reporting: hour 0, you become aware and classify the incident (DORA Art. 18); 4 hours, initial notification from classifying it as major and within 24 hours of becoming aware; 72 hours, intermediate report from the initial notification, even if nothing has changed; 1 month, final report from the latest intermediate report, with the root cause (Delegated Regulation 2025/301 Art. 5).
The three reports and their time limits. A deadline on a weekend or bank holiday can move to noon the next working day, except for some firms.

What makes an incident major

You classify every ICT-related incident against the criteria in DORA Art. 18: clients and transactions affected, duration, geographical spread, data losses, criticality of the services and economic impact. Under Delegated Regulation (EU) 2024/1772, an incident is major when it affects critical services and either involves malicious, unauthorised access that may lead to data losses, or meets two or more of the other materiality thresholds (Art. 8).

Smaller incidents can add up. Incidents that happen at least twice in 6 months with the same apparent root cause, and together meet the major criteria, count as one major incident. Check for them monthly. This doesn't apply to microenterprises or firms under the simplified framework.

The three reports

  • Initial notification: as early as possible, within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it. If you classify it as major later than that, you have 4 hours from the classification.
  • Intermediate report: within 72 hours of the initial notification, even if nothing has changed. Send an updated one without undue delay, and in any case when regular activities have been recovered.
  • Final report: within a month of the intermediate report, or of the latest updated one.

Reports use the templates set under DORA Art. 20 and go to your competent authority. If you can't meet a time limit, tell the authority before it passes and explain why (Delegated Regulation 2025/301, Art. 5).

Weekends and bank holidays

If a time limit falls on a weekend or a bank holiday in your member state, you can report by noon on the next working day. This doesn't apply to initial notifications or intermediate reports from credit institutions, central counterparties, trading venue operators and essential or important entities under NIS2, and authorities can remove it for other significant firms.

Clients and cyber threats

  • If a major incident affects your clients' financial interests, tell them without undue delay, with the measures you've taken (Art. 19(3)).
  • You can also notify significant cyber threats to your authority voluntarily, when you consider them relevant to the financial system or your clients (Art. 19(2)).

Be ready before it happens

Four hours leaves no time to work out the process. Have the classification criteria, the authority's reporting channel and the people who sign off written down, and rehearse them in your yearly continuity test. The DORA compliance checklist puts those tests and reviews on dates.

Get reminded before each deadline

Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related