Under DORA Article 19 and Delegated Regulation (EU) 2025/301, a financial entity reports a major ICT-related incident to its competent authority in three steps: an initial notification within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report within a month of the latest intermediate report.

What makes an incident major
You classify every ICT-related incident against the criteria in DORA Art. 18: clients and transactions affected, duration, geographical spread, data losses, criticality of the services and economic impact. Under Delegated Regulation (EU) 2024/1772, an incident is major when it affects critical services and either involves malicious, unauthorised access that may lead to data losses, or meets two or more of the other materiality thresholds (Art. 8).
Smaller incidents can add up. Incidents that happen at least twice in 6 months with the same apparent root cause, and together meet the major criteria, count as one major incident. Check for them monthly. This doesn't apply to microenterprises or firms under the simplified framework.
The three reports
- Initial notification: as early as possible, within 4 hours of classifying the incident as major and no later than 24 hours after becoming aware of it. If you classify it as major later than that, you have 4 hours from the classification.
- Intermediate report: within 72 hours of the initial notification, even if nothing has changed. Send an updated one without undue delay, and in any case when regular activities have been recovered.
- Final report: within a month of the intermediate report, or of the latest updated one.
Reports use the templates set under DORA Art. 20 and go to your competent authority. If you can't meet a time limit, tell the authority before it passes and explain why (Delegated Regulation 2025/301, Art. 5).
Weekends and bank holidays
If a time limit falls on a weekend or a bank holiday in your member state, you can report by noon on the next working day. This doesn't apply to initial notifications or intermediate reports from credit institutions, central counterparties, trading venue operators and essential or important entities under NIS2, and authorities can remove it for other significant firms.
Clients and cyber threats
- If a major incident affects your clients' financial interests, tell them without undue delay, with the measures you've taken (Art. 19(3)).
- You can also notify significant cyber threats to your authority voluntarily, when you consider them relevant to the financial system or your clients (Art. 19(2)).
Be ready before it happens
Four hours leaves no time to work out the process. Have the classification criteria, the authority's reporting channel and the people who sign off written down, and rehearse them in your yearly continuity test. The DORA compliance checklist puts those tests and reviews on dates.
Get reminded before each deadline
Regmindr sets up your compliance calendar from a template in about two minutes, and emails your team before each deadline is due.
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 18 to 20
- Commission Delegated Regulation (EU) 2025/301: content and time limits for incident reports
- Commission Delegated Regulation (EU) 2024/1772: classification of ICT-related incidents
This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.