Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
When must you report a DORA major ICT-related incident?
Updated
Article 19 DORA: financial entities report major ICT-related incidents to the relevant competent authority in three distinct stages — an initial notification, an intermediate report, and a final report — under time limits in the RTS. Classification is Article 18. Not legal advice; does not start a clock.
DORA jurisdiction guide, last verified 8 September 2026 against Regulation (EU) 2022/2554 Articles 18 and 19, Commission Delegated Regulation (EU) 2024/1772 (classification RTS), Commission Delegated Regulation (EU) 2025/301 (content and time-limits RTS), and Commission Implementing Regulation (EU) 2025/302 (templates ITS). ESA Joint Technical Standards pages are ESA materials, not the Level-1 regulation. It is not legal advice, not a filing, not a determination that DORA applies or that you are a financial entity, and not a substitute for counsel.
This is DORA Articles 18–19, not YOUR entity class
Audience: a compliance lead, CISO, or counsel at a financial entity or an ICT third-party service provider triaging an ICT-related incident that may sit under Regulation (EU) 2022/2554. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that DORA applies, that you are a financial entity, that an incident is major, or that you must file.
Articles 18 and 19 are legal requirements only if DORA applies to YOUR facts. Article 2 is the scope article — this page quotes how it names entities; it does not run that test for you. The which-jurisdictions-apply page on this site is the applicability map. Last verified 8 September 2026. Not legal advice.
- Statute versus RTS versus ESA materials: Articles 18 and 19 are Level-1 legal requirements only if DORA applies. Delegated Regulation (EU) 2024/1772 is the classification RTS. Delegated Regulation (EU) 2025/301 is the reporting-content and time-limits RTS. Implementing Regulation (EU) 2025/302 is the templates ITS. ESA Joint Technical Standards pages are ESA materials, not the regulation. This page quotes which kind of text it is relying on.
- This page does not start four hours, 24 hours, 72 hours, or one month, and it does not blend those three stages into one deadline.
- The reporting-deadlines page on this site is the statute table of clocks. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The prepare-regulatory-report page on this site is the field checklist.
- The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is Article 14 of the Cyber Resilience Act, not DORA Article 19, and it does not file with a competent authority. The CRA Article 14 reporting guide on this site.
Scope — financial entities and ICT third-party service providers as Article 2 states
This page does not invent a licence list and does not decide that YOU are in scope. Article 2 names the entities. Article 19's reporting duty is on financial entities as Article 2(2) defines that term. Last verified 8 September 2026. Not legal advice.
- Chapter V of DORA is the Oversight Framework for critical ICT third-party service providers. That chapter is not Article 19's three-stage report. This page does not designate anyone as critical and does not convert Oversight into an Article 19 filing.
- DORA is lex specialis as against NIS2 for in-scope financial entities (NIS2 recital 28). The NIS2 incident-reporting guide on this site is the jurisdiction treatment of Article 23.
- The GDPR breach-notification guide on this site is Articles 33–34. A personal-data breach can sit under GDPR and under DORA at once. Filing one never discharges the other.
| Article | What the text says | Kind of text | What this page does not do |
|---|---|---|---|
| Article 2(1) | Without prejudice to paragraphs 3 and 4, this Regulation applies to the following entities: (a) credit institutions; (b) payment institutions, including those exempted pursuant to Directive (EU) 2015/2366; (c) account information service providers; (d) electronic money institutions, including those exempted pursuant to Directive 2009/110/EC; (e) investment firms; (f) crypto-asset service providers as authorised under the markets-in-crypto-assets Regulation, and issuers of asset-referenced tokens; (g) central securities depositories; (h) central counterparties; (i) trading venues; (j) trade repositories; (k) managers of alternative investment funds; (l) management companies; (m) data reporting service providers; (n) insurance and reinsurance undertakings; (o) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries; (p) institutions for occupational retirement provision; (q) credit rating agencies; (r) administrators of critical benchmarks; (s) crowdfunding service providers; (t) securitisation repositories; (u) ICT third-party service providers. | Legal requirement — Article 2(1). Only if DORA applies. | Does not map YOUR authorisation onto a letter. Does not invent extra licence types. |
| Article 2(2) | For the purposes of this Regulation, entities referred to in paragraph 1, points (a) to (t), shall collectively be referred to as 'financial entities'. Point (u) is therefore in the Regulation's scope and is not inside that collective term. | Legal requirement — Article 2(2). | Does not treat an ICT third-party service provider as a financial entity by renaming it. |
| Article 19(1) | Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 in accordance with paragraph 4 of this Article. | Legal requirement — Article 19(1). The reporter is a financial entity. | Does not decide that YOU are a financial entity. Does not paste Article 19 onto every ICT vendor. |
| Article 19(5) | Financial entities may outsource, in accordance with Union and national sectoral law, the reporting obligations under this Article to a third-party service provider. In case of such outsourcing, the financial entity remains fully responsible for the fulfilment of the incident reporting requirements. | Legal requirement — Article 19(5). | Does not treat an outsourced filing as a shift of legal responsibility. |
| Article 2(3)–(4) | Paragraph 3 lists entities the Regulation does not apply to (including specified AIFMs, certain insurance undertakings, small IORPs, specified MiFID exemptions, SME insurance intermediaries, and post office giro institutions). Paragraph 4 lets a Member State exclude entities referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU located in its territory, with notice to the Commission. | Legal requirement — Article 2(3) and 2(4). | Does not apply those carve-outs to YOUR facts. Does not invent a Member-State list. |
Major-incident classification — RTS (EU) 2024/1772, not the Level-1 hours
Article 18(1) names six classification criteria. The materiality thresholds that turn an ICT-related incident into a major incident for Article 19(1) sit in Commission Delegated Regulation (EU) 2024/1772 — the classification RTS, not the Level-1 regulation. Hours for the three reports sit in a different RTS (2025/301). Do not paste those hours onto classification. Last verified 8 September 2026 against the Official Journal text of 2024/1772. Not legal advice.
- Article 18(1) of the Level-1 regulation names the six criteria. It does not itself set the 10 percent, 100 000, 24-hour, 2-hour, two-Member-State, or 100 000 euro figures. Those figures are RTS, not the Level-1 regulation. If a later RTS revision changes a figure, the last-verified date is how you can see we have not re-checked yet.
- This page does not classify YOUR incident as major. Counsel applies the RTS to YOUR facts.
- Do not paste NIS2's 'significant incident' test or GDPR's 'risk to rights and freedoms' onto DORA classification.
| Criterion | What the RTS says | Kind of text | Last verified |
|---|---|---|---|
| When is an incident major? (RTS Article 8(1)) | An incident shall be considered a major incident for the purposes of Article 19(1) of Regulation (EU) 2022/2554 where it has affected critical services as referred to in Article 6 and where either of the following conditions is fulfilled: (a) the materiality threshold referred to in Article 9(5), point (b), is met; (b) two or more of the other materiality thresholds referred to in Articles 9(1) to (6) are met. | RTS — Delegated Regulation (EU) 2024/1772 Article 8(1). Not the Level-1 regulation. | 8 September 2026 |
| Critical services (RTS Article 6) | Assess whether the incident affects or has affected ICT services or network and information systems that support critical or important functions; or financial services that require authorisation, registration or that are supervised; or constitutes or has constituted a successful, malicious and unauthorised access to the network and information systems of the financial entity. | RTS Article 6, specifying Article 18(1)(e). | 8 September 2026 |
| Clients, financial counterparts and transactions (RTS Article 9(1)) | The threshold is met where any of these is fulfilled: affected clients higher than 10 percent of all clients using the affected service; or higher than 100 000 affected clients using the affected service; or affected financial counterparts higher than 30 percent of all financial counterparts carrying out activities related to the affected service; or affected transactions higher than 10 percent of the daily average number, or the amount higher than 10 percent of the daily average value, of transactions related to the affected service; or clients or financial counterparts identified as relevant under RTS Article 1(3) have been affected. | RTS Article 9(1). Not a number this page invented. | 8 September 2026 |
| Reputational impact (RTS Article 9(2) / Article 2) | Met where any of Article 2 points (a) to (d) is fulfilled: the incident has been reflected in the media; repetitive complaints from different clients or financial counterparts on client-facing services or critical business relationships; the financial entity will not be able to or is likely not to be able to meet regulatory requirements as a result; or the financial entity will or is likely to lose clients or financial counterparts with a material impact on its business. | RTS Articles 2 and 9(2). | 8 September 2026 |
| Duration and service downtime (RTS Article 9(3)) | Met where the duration of the incident is longer than 24 hours, or the service downtime is longer than 2 hours for ICT services that support critical or important functions. | RTS Article 9(3). Duration and downtime are measured as RTS Article 3 specifies. This is a classification threshold, not the Article 19 reporting clock. | 8 September 2026 |
| Geographical spread (RTS Article 9(4)) | Met where the incident has an impact in two or more Member States in accordance with RTS Article 4. | RTS Article 9(4). Article 18(1)(c) of the Level-1 text says 'particularly if it affects more than two Member States'; the RTS threshold is two or more. Quote which text you are applying. | 8 September 2026 |
| Data losses (RTS Article 9(5)) | (a) any impact as referred to in Article 5 on availability, authenticity, integrity or confidentiality of data has or will have an adverse impact on the implementation of the business objectives of the financial entity or on its ability to meet regulatory requirements; (b) any successful, malicious and unauthorised access not covered by point (a) occurs to network and information systems, where such access may result in data losses. Point (b) is the single threshold that RTS Article 8(1)(a) can treat as enough, with critical services, without needing two other thresholds. | RTS Article 9(5). Recital 10 of that RTS: malicious unauthorised access to systems supporting critical or important functions should always be considered as major incidents which are to be reported. | 8 September 2026 |
| Economic impact (RTS Article 9(6)) | Met where the costs and losses incurred by the financial entity due to the incident have exceeded or are likely to exceed 100 000 euro. RTS Article 7 lists the cost types to sum, without accounting for financial recoveries, and excludes day-to-day operating costs, post-incident upgrades, and insurance premiums. | RTS Articles 7 and 9(6). | 8 September 2026 |
| Recurring incidents (RTS Article 8(2)) | Recurring incidents that individually are not major shall be considered as one major incident where they have occurred at least twice within 6 months, have the same apparent root cause as referred to in Article 20, first subparagraph, point (b) of Regulation (EU) 2022/2554, and collectively fulfil Article 8(1). Financial entities shall assess the existence of recurring incidents on a monthly basis. This paragraph does not apply to microenterprises and to financial entities listed in Article 16(1) of Regulation (EU) 2022/2554. | RTS Article 8(2). Not a Level-1 hour. | 8 September 2026 |
Three-stage timeline — initial, intermediate, and final as Article 19 states
Article 19(4) names three submissions: an initial notification, an intermediate report, and a final report. It sends the time limits to Article 20. The hours are in Delegated Regulation (EU) 2025/301 Article 5 — RTS, not the Level-1 article. Do not blend the three stages into one deadline. Last verified 8 September 2026. Not legal advice.
- RTS (EU) 2025/301 Article 5(3): if you cannot submit within the time limits, inform the competent authority without undue delay, but no later than the respective time limits, and explain the reasons for the delay. That is not a licence to skip a stage.
- RTS (EU) 2025/301 Article 5(4): where a time limit falls on a weekend day or a bank holiday in the Member State of the reporting financial entity, the financial entity may submit by noon of the next working day. Article 5(5): that weekend/bank-holiday extension does not apply to the initial notification or the intermediate report by credit institutions, central counterparties, operators of trading venues, and other financial entities identified as essential or important entities pursuant to Article 3 of Directive (EU) 2022/2555. Article 5(6) lets a competent authority switch the extension off for other significant or systemic entities after notifying them.
- Templates are Implementing Regulation (EU) 2025/302 — ITS, not the RTS and not Level-1. Article 19(1) still requires the templates referred to in Article 20.
- Member States may additionally require the same initial notification and each report to NIS2 CSIRTs or competent authorities (Article 19(1), last subparagraph). That extra channel is not a substitute for the Article 19(1) filing with the DORA competent authority.
- Article 19(3) is a separate client-information duty where a major ICT-related incident has an impact on the financial interests of clients — without undue delay as soon as they become aware of it, including the measures taken to mitigate the adverse effects. That is not the competent-authority filing and is not a fourth Article 19(4) stage.
| Stage | What Article 19 says | Time limit (RTS) | Clock-start | Recipient |
|---|---|---|---|---|
| Initial notification | Article 19(4)(a): an initial notification. Article 19(1): after collecting and analysing all relevant information, using the templates referred to in Article 20. If a technical impossibility prevents submission using the template, notify the competent authority via alternative means. | RTS (EU) 2025/301 Article 5(1)(a): as early as possible, but in any case within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident. Article 5(2): if classification as major happens after those 24 hours, submit the initial notification within four hours from that later classification. | Two named events, not one: classification as major (four hours) and awareness of the ICT-related incident (24-hour cap). Not NIS2 'becoming aware of the significant incident'. Not GDPR Article 33(1). This page does not find that YOU classified or became aware. | The relevant competent authority as referred to in Article 46 (Article 19(1)). Where more than one national competent authority under Article 46 supervises the entity, the Member State designates a single relevant competent authority for this Article. Significant credit institutions under SSM Article 6(4) report to the relevant national competent authority designated in accordance with Article 4 of Directive 2013/36/EU, which shall immediately transmit that report to the ECB. |
| Intermediate report | Article 19(4)(b): an intermediate report after the initial notification, as soon as the status of the original incident has changed significantly or the handling of the major ICT-related incident has changed based on new information available, followed, as appropriate, by updated notifications every time a relevant status update is available, as well as upon a specific request of the competent authority. | RTS (EU) 2025/301 Article 5(1)(b): at the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed as referred to in Article 19(4), point (b). Financial entities shall submit an updated intermediate report without undue delay, and in any case when the regular activities have been recovered. | Submission of the initial notification — not awareness, and not classification. The 72 hours is a distinct stage. Do not average it with the four-hour or 24-hour marks, and do not paste NIS2's 72-hour incident notification onto it. | The same relevant competent authority. |
| Final report | Article 19(4)(c): a final report, when the root cause analysis has been completed, regardless of whether mitigation measures have already been implemented, and when the actual impact figures are available to replace estimates. | RTS (EU) 2025/301 Article 5(1)(c): no later than one month after either the submission of the intermediate report, or, where applicable, after the latest updated intermediate report. | Submission of the intermediate report, or the latest updated intermediate report — not awareness. This page does not convert 'one month' into a number of hours. The initial, intermediate, and final marks are not collapsed into one DORA number. | The same relevant competent authority. |
Significant cyber threats — voluntary as Article 19(2) states
Article 19(2): financial entities may, on a voluntary basis, notify significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. Last verified 8 September 2026. Not legal advice.
- The word in Article 19(2) is 'may', on a voluntary basis. It is not Article 19(1)'s 'shall report' for major ICT-related incidents. Do not convert a voluntary significant-cyber-threat notification into a required Article 19(4) stage.
- Classification of a cyber threat as significant is Article 18(2), specified in RTS (EU) 2024/1772 Article 10 (high materiality thresholds). This page does not apply that test to YOUR facts.
- Content of the voluntary notification is RTS (EU) 2025/301 Article 6 — RTS, not Level-1. Recital 6 of that RTS: because the notification is voluntary, the content should not impose a burden and should be more limited than for major ICT-related incidents.
- Significant credit institutions may, on a voluntary basis, notify the relevant national competent authority, which shall immediately transmit the notification to the ECB (Article 19(2), second subparagraph).
- Article 19(3), second subparagraph: in the case of a significant cyber threat, financial entities shall, where applicable, inform their clients that are potentially affected of any appropriate protection measures which the latter may consider taking. That client information is not the voluntary authority notification.
Legal requirement versus RTS/ITS versus ESA guidance
Quote which kind of text you are relying on. A delegated regulation is not a blog post, and an ESA explainer is not Article 19. Last verified 8 September 2026. Not legal advice.
| Instrument | What it is | What it is not |
|---|---|---|
| Regulation (EU) 2022/2554 Articles 18–19 (and Article 20's mandate) | Level-1 legal requirement only if DORA applies. Article 18: classify. Article 19: report major ICT-related incidents; may notify significant cyber threats. Article 19(4) names initial, intermediate, and final. Article 20 tells the ESAs to draft the RTS/ITS for content, time limits, and templates. | Not the hours. Not the materiality percentages. Not a template. |
| Delegated Regulation (EU) 2024/1772 | Classification RTS adopted under Article 18(4). Articles 8 and 9 are the major-incident rule and the materiality thresholds last verified on this page. | Not the three-stage hours. Not Level-1. |
| Delegated Regulation (EU) 2025/301 | Reporting-content and time-limits RTS adopted under Article 20. Article 5 is the four-hour / 24-hour, 72-hour, and one-month cascade last verified on this page. Articles 1–4 are content. Article 6 is voluntary-threat content. | Not classification thresholds. Not Level-1. Not a template. |
| Implementing Regulation (EU) 2025/302 | Templates ITS adopted under Article 20. Standard forms, templates, and procedures for the initial notification, intermediate report, final report, and the voluntary significant-cyber-threat notification. | Not the hours. Not the thresholds. Not Level-1. |
| ESA Joint Technical Standards on major incident reporting (EBA/ESMA/EIOPA page) | ESA materials describing the adopted RTS/ITS. Useful as a map to the Official Journal texts. | Not the regulation. Not a substitute for the OJ text. Not legal advice. |
Checklist
This is a question list, not a filing, and not YOUR notice. Walk it with counsel. The reporting-deadlines page on this site is the statute table. The prepare-regulatory-report page on this site is the field checklist. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The document-your-decision page on this site is the decision record.
- Does DORA apply? Article 2 is the scope test. This page does not run it. Being in the financial sector is not, by itself, a determination. An in-scope mark on an obligation map is not a determination.
- Are you a financial entity under Article 2(2) (points (a) to (t)), or an ICT third-party service provider under Article 2(1)(u)? Article 19(1) names financial entities as the reporters. Article 19(5) outsourcing does not move legal responsibility.
- Classification (UTC): did the incident affect critical services as RTS Article 6 specifies, and did it meet RTS Article 8(1)(a) or 8(1)(b)? Quote the RTS criteria you applied. This page does not classify it.
- Awareness (UTC) and classification-as-major (UTC) are different timestamps. RTS (EU) 2025/301 Article 5(1)(a) uses both for the initial notification. Do not treat reading this page as either event.
- Initial notification: RTS Article 5(1)(a) and, if classification is late, Article 5(2). Content: RTS Articles 1 and 2. Template: ITS (EU) 2025/302. Recipient: the relevant competent authority as Article 19(1) states.
- Intermediate report: RTS Article 5(1)(b) — 72 hours from submission of the initial notification, even if nothing has changed. Updated intermediate when regular activities have been recovered. Do not blend this into the initial mark.
- Final report: RTS Article 5(1)(c) — one month from the intermediate (or latest updated intermediate). Article 19(4)(c) wants root-cause analysis completed and actual impact figures in place of estimates. Do not blend this into the 72 hours.
- Significant cyber threat: Article 19(2) is voluntary. Do not convert it into a required stage.
- Clients: Article 19(3) is a separate duty where the major incident has an impact on the financial interests of clients. It is not the competent-authority filing.
- Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.
Glossary
These are teaching labels for this page. They are not legal conclusions about YOUR facts.
| Term | How this page uses it |
|---|---|
| ICT-related incident | Article 3(8): an event or a series of linked events unplanned by the financial entity that compromises the security of network and information systems and has an adverse impact on the availability, authenticity, integrity or confidentiality of data or on the services provided by the financial entity. |
| Major ICT-related incident | Article 3(10): an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity. Whether YOUR incident is major is RTS (EU) 2024/1772 Articles 8–9, not a feeling that it was serious. |
| Article 18 | Classification of ICT-related incidents and cyber threats. Six criteria in Article 18(1). Thresholds in the classification RTS. |
| Article 19(1) / 19(4) | Financial entities report major ICT-related incidents to the relevant competent authority in three distinct stages: initial notification, intermediate report, final report. Not one blended deadline. |
| Article 19(2) | Voluntary notification of significant cyber threats. 'May', on a voluntary basis — not 'shall'. |
| Article 19(3) | Client information where a major ICT-related incident has an impact on the financial interests of clients — without undue delay as soon as they become aware. Separate from the competent-authority filing. |
| Relevant competent authority | Article 19(1) points to Article 46. One designated authority where more than one national competent authority under Article 46 supervises the entity. Significant credit institutions: national competent authority under CRD, which transmits to the ECB. |
| Classification RTS | Delegated Regulation (EU) 2024/1772. Materiality thresholds. Not the hours. |
| Reporting RTS | Delegated Regulation (EU) 2025/301. Content and time limits for initial, intermediate, and final, and content of the voluntary threat notification. |
| Templates ITS | Implementing Regulation (EU) 2025/302. Forms and procedures. Not the hours and not the thresholds. |
| ICT third-party service provider | Article 2(1)(u), outside the Article 2(2) collective term 'financial entities'. Article 19(1) reporters are financial entities. Chapter V oversight of critical ICT third-party service providers is not the Article 19 three-stage report. |
Where this shows up in ShipReady Metrics
The signed-in app does not decide that DORA applies, does not decide that you are a financial entity, does not classify an ICT-related incident as major, does not start an Article 19 clock, and does not file with a competent authority. None of the surfaces below is an initial notification, an intermediate report, a final report, or an instruction to submit a filing.
If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not a DORA Article 19 clock, not an initial/intermediate/final DORA report, and not a filing with a DORA competent authority. It tracks a clock the organization already recorded. It is not a determination that CRA applies. The CRA Article 14 reporting guide on this site. A named human still submits.
DORA is a bundled framework in the catalog (`dora`, labelled as DORA readiness — a starter subset of Article references, not the full regulation and not the RTS/ITS). The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that DORA applies, not a determination that you are a financial entity under Article 2(2), and not a legal opinion that Articles 18–19 have been triggered. The DORA starter control set is crosswalked to canonical controls; evidence collection and the evidence-review overlay record control-mapped artifacts for that starter subset. Those rows are not an Article 19 pack.
The signed-in DORA incident-reporting collector grades whether incidents the organization itself classified as DORA-reportable were notified to an authority against a recorded detection timestamp. It does not classify the incident as major, does not start Article 19, and does not submit the RTS/ITS templates to a competent authority. Zero reportable incidents is not a claim that no major incident occurred. The cyber risk register lives under Security. None of those surfaces files a DORA Article 19 report.
The public glossary page 'DORA metrics, defined' is the DevOps Research and Assessment four keys (deployment frequency, lead time, change-failure rate, time to restore). Same acronym, different subject — it is unrelated to Regulation (EU) 2022/2554 and is not an Article 19 filing, not a classification, and not engineering evidence that a major ICT-related incident was reported.
Primary sources (last verified 8 September 2026)
Every regulatory or RTS/ITS claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2022/2554 Articles 18 and 19 are legal requirements only when DORA applies. Article 18 is classification. Article 19(1) and 19(4) are the three-stage report of major ICT-related incidents to the relevant competent authority. Article 19(2) is voluntary notification of significant cyber threats. Article 19(3) is client information. Article 19(5) is outsourcing of reporting with residual responsibility. Article 2 is scope, including ICT third-party service providers at point (u) and the Article 2(2) definition of financial entities as points (a) to (t). Article 3(8) and 3(10) define ICT-related incident and major ICT-related incident. Article 20 mandates the RTS/ITS. Commission Delegated Regulation (EU) 2024/1772 is the classification RTS (Articles 8–9 thresholds last verified above). Commission Delegated Regulation (EU) 2025/301 is the content and time-limits RTS (Article 5 hours last verified above). Commission Implementing Regulation (EU) 2025/302 is the templates ITS. The EBA Joint Technical Standards on major incident reporting page is ESA material, not the regulation. The NIS2 incident-reporting guide on this site is Article 23. The CRA Article 14 reporting guide on this site. These are the DORA articles this page treats, not a complete world list of incident-reporting laws. Not legal advice.
The reporting-deadlines page on this site is the statute table of clocks. The reporting-decision-tree page on this site is the branching tree. The GDPR breach-notification guide on this site is Articles 33–34. The NIS2 incident-reporting guide on this site is Article 23. The prepare-regulatory-report page on this site is the field checklist. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The document-your-decision page on this site is the decision record. The supporting-evidence page on this site is the evidentiary record. The failure-to-report-consequences page on this site is the maxima table. The which-jurisdictions-apply page on this site is the applicability map. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. A dedicated HIPAA, Canada PIPEDA, Australia NDB, India DPDP / CERT-In, and UAE/Dubai guide is not on this site yet. Naming them is not a link. A dedicated CRA Article 14 feature page is not on this site yet.
Frequently asked questions
When must you report a DORA major ICT-related incident?
Article 19(4) names three distinct stages, not one deadline. Time limits are RTS (EU) 2025/301 Article 5: initial notification as early as possible, within four hours of classification as major and no later than 24 hours from awareness; intermediate report within 72 hours of submitting the initial notification; final report no later than one month after the intermediate (or latest updated intermediate). Classification is Article 18 plus RTS (EU) 2024/1772. Last verified 8 September 2026. Not legal advice.
Is this legal advice?
No. It is a DORA jurisdiction guide distilled from Regulation (EU) 2022/2554 Articles 18 and 19, Delegated Regulation (EU) 2024/1772, Delegated Regulation (EU) 2025/301, and Implementing Regulation (EU) 2025/302. Whether DORA applies, whether you are a financial entity, whether an incident is major, and whether a clock has started are legal questions for counsel on your facts. This page does not start a reporting clock.
Does ShipReady file DORA reports?
No. The signed-in app does not file Article 19 with a competent authority, does not classify an incident as major, and does not start those clocks. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not Article 19. The obligation map is frameworks marked in-scope, not a determination that DORA applies or that you are a financial entity.
Do ICT third-party service providers file the same Article 19 reports as financial entities?
Article 2(1)(u) puts ICT third-party service providers in the Regulation's scope. Article 2(2) defines 'financial entities' as points (a) to (t). Article 19(1) requires financial entities to report major ICT-related incidents. Article 19(5) lets a financial entity outsource the filing; responsibility stays with the financial entity. Chapter V oversight of critical ICT third-party service providers is not the Article 19 three-stage report. Counsel applies YOUR facts. Not legal advice.
Is DORA's four-hour mark the same as NIS2's 24-hour early warning?
No. They are different instruments. DORA's initial notification uses classification as major (four hours) and awareness of the ICT-related incident (24-hour cap) under RTS (EU) 2025/301 Article 5(1)(a). NIS2 Article 23 uses becoming aware of a significant incident for its early warning. Do not paste one ladder onto the other. The NIS2 incident-reporting guide on this site is Article 23. Not legal advice.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.