Back to glossaryLaw & regulation

Major incident reporting

Obligation on financial entities to report every major information technology incident to their supervisor, in three stages, against classification criteria harmonized across the Union.

Definition

Before DORA, reporting of information technology incidents depended on the sector, the country and sometimes the supervisor's mood, which made any aggregate view of European operational risk impossible. The regulation harmonizes three things. The classification criteria first: number of clients affected, duration and service downtime, geographic spread, data losses, criticality of services affected, economic impact, with an incident being major once the combined thresholds are crossed. The procedure next, in three stages: a very fast initial notification after classification, an intermediate report when normal activity resumes or when the situation changes materially, then a final report documenting root causes and corrective measures. The content last, through standardized forms. Two effects follow. The internal chain must be able to classify an incident within hours, which presupposes preset criteria rather than a crisis deliberation. And the regime coexists with GDPR data breach notification and with NIS2 obligations, which share neither thresholds nor recipients, so one incident often triggers several distinct filings.

Example

Regulation (EU) 2022/2554, applicable since January 17, 2025, supplemented by technical standards setting the deadline for each stage. Ransomware encrypting a European insurer's claims system on a Friday evening in practice starts three separate clocks: the DORA one toward the financial supervisor, the GDPR one toward the data protection authority within seventy-two hours, and the cyber policy one toward the entity's own insurer.

Related terms
Also known as

déclaration d'incident DORA, major ICT-related incident, notification en trois temps, incident lié aux TIC