From the journal

Major ICT Incidents under DORA

EU financial entities must report major information and communication technology (ICT) incidents under the Digital Operational Resilience Act (DORA). The question is how the joint supervisory staff instructions dated 16 September 2026 affect classification, reporting deadlines and the information submitted. This analysis addresses the EU rules, with particular attention to insurance and occupational pensions.

Illia ProkopievCo-Founder and CEO27 min read

Summary

  • A major incident must affect critical services and satisfy the prescribed additional test. Except for the specified malicious-access route, at least two other materiality criteria must be met. Selecting two alternatives within one criterion does not satisfy that requirement. (Delegated Regulation (EU) 2024/1772, Arts. 6, 8(1) and 9.)
  • Initial notification is due as early as possible, within four hours of major classification and ordinarily within 24 hours of awareness. Later classification has a specific exception. The intermediate deadline runs from the actual initial submission; the final deadline runs from the intermediate or latest updated intermediate report. (Delegated Regulation (EU) 2025/301, Art. 5.)
  • Monthly intermediate reports are a staff expectation for incidents awaiting finalisation. They do not provide an unconditional right to defer the final report. Completion depends on root-cause analysis and actual impact figures; delay requires timely notice to the authority. (DORA, Art. 19(4); Delegated Regulation 2025/301, Art. 5(1)–(3); Operational Instructions, item 4.)
  • Monetary fields use thousands of the currency identified in the report. Classification uses the underlying gross loss calculation, without deducting recoveries. Reporting scale and rounding cannot change whether the EUR 100,000 threshold is exceeded. (Delegated Regulation 2024/1772, Arts. 7 and 9(6); Implementing Regulation (EU) 2025/302, Annex II, fields 1.15, 3.11 and 4.13–4.14.)
  • Staff instructions require careful reconciliation with the binding annex. The final-report requirement for field 4.12 remains material even when economic impact did not trigger classification. Field 3.17 has a broader staff completion expectation than its annex condition. Neither difference warrants silently rewriting the regulation. (Implementing Regulation 2025/302, Annex II, fields 3.17 and 4.12; Operational Instructions, items 10 and 14.)
  • Delegating submission leaves the financial entity responsible. A shared provider incident qualifies for aggregated reporting only under specified conditions, including individual major classification and supervisory permission. An incident reference must remain stable through corrections. (DORA, Art. 19(5); Implementing Regulation 2025/302, Arts. 6–7; Operational Instructions, items 5–6.)

The instructions do not amend DORA or the Commission's reporting regulations. Staff of the European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) issued the five-page document on 16 September 2026. Together, these bodies are the European Supervisory Authorities (ESAs). They describe it as a best-efforts aid for competent authorities' engagement with financial entities. The disclaimer expressly excludes legal interpretation and an official ESAs position. Agreement with relevant competent authorities gives the document operational relevance, but does not remove that limitation. (Operational Instructions, p. 1.)

DORA imposes the reporting duty, with classification criteria and thresholds prescribed by Delegated Regulation 2024/1772. Delegated Regulation 2025/301 requires specified content within reporting deadlines. Forms, field instructions and submission procedures are governed by Implementing Regulation 2025/302. The Commission adopted the latter two instruments under DORA Article 20. Staff instructions can explain their practical use; their disclaimer provides no basis for changing a threshold or waiving an express annex requirement. (DORA, Arts. 18–20; Delegated Regulation 2024/1772, Arts. 8–9; Delegated Regulation 2025/301, Arts. 1–5; Implementing Regulation 2025/302, Art. 1.)

DORA has applied since 17 January 2025. Regulations 2025/301 and 2025/302 entered into force on 12 March 2025, twenty days after their Official Journal publication. The September 2026 staff document contains no new legislative commencement date or transition period. For a historical incident, the legal version and national arrangements applicable at that time must be established separately. (DORA, Art. 64; Delegated Regulation 2025/301, Art. 7; Implementing Regulation 2025/302, Art. 9; Operational Instructions, p. 1.)

The financial entity reports to the authority designated under DORA Article 46. That authority then transmits relevant information to the ESAs and other designated recipients under Article 19(6). For insurance undertakings, intermediaries and occupational pension institutions, Article 46(k)–(m) identifies the sectoral competent authorities. EIOPA's publication of the document does not substitute EIOPA for those recipients. Where several national authorities supervise an entity, the Member State must designate a single reporting authority. Significant banks report to the relevant national authority, which immediately transmits the report to the ECB. (DORA, Arts. 19(1), 19(6) and 46.)

The competent authority must acknowledge receipt and may provide supervisory feedback. An acknowledgement establishes receipt without deciding that the entity has complied with every reporting requirement. Article 22(1) preserves the entity's responsibility for handling the incident and its consequences despite that feedback. Submission records therefore need to distinguish delivery confirmation from a supervisory decision. (DORA, Art. 22(1).)

The English-template instruction concerns the competent-authority-to-ESA stage. It covers headers and predefined answers; free text may use the applicable national language. A firm must therefore distinguish the ESA transmission format from its own supervisor's submission requirements. An instruction to file every national report entirely in English cannot be inferred from this document. (Operational Instructions, p. 1 and item 1; Implementing Regulation 2025/302, Art. 4.)

Covered entities and proportionate treatment

The insurance and pensions perimeter requires an entity-level assessment. DORA covers insurance and reinsurance undertakings, insurance-related intermediaries and institutions for occupational retirement provision. It excludes undertakings within Article 4 of Directive 2009/138/EC (Solvency II), pension institutions whose schemes together have no more than 15 members, and intermediaries that qualify as micro, small or medium-sized enterprises. A group's regulated status does not establish the status of every subsidiary. The relevant definitions and authorisation records must be applied to each entity. (DORA, Art. 2(1)(n)–(p), (2)–(4), and Art. 3.)

A smaller in-scope firm does not obtain a general exemption from major-incident reporting. DORA Article 4 requires proportionate implementation, with proportionality in Chapter III applying as specifically provided in its relevant rules, while Article 19 imposes the reporting duty. Article 16 simplifies specified ICT risk-management requirements for listed entities, including small occupational pension institutions. That simplification does not disapply Chapter III. A separate exemption does relieve microenterprises and Article 16(1) entities from the recurring-incident aggregation rule discussed below. (DORA, Arts. 4, 16 and 19; Delegated Regulation 2024/1772, Art. 8(2).)

The same architecture applies across the other financial sectors listed in DORA Article 2, subject to their exclusions. ICT service providers appear separately in Article 2(1)(u); they do not become financial entities merely because DORA regulates aspects of their activities. Their involvement in an incident does not transfer the customer's Article 19 duty. No conclusion about a third-country branch, EEA incorporation or a particular national extension follows without the relevant territorial facts and legal instrument. (DORA, Art. 2(1)–(4), Art. 19(5).)

The payments perimeter extends beyond ICT failures. Article 23 applies Chapter III to operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers and electronic money institutions. The definition includes events that need not be ICT-related. A procedure confined to cyberattacks or technology outages would therefore be too narrow for those entities. (DORA, Arts. 3(9) and 23.)

The major-incident test

A reportable major incident requires the conjunction in Article 8(1) of Delegated Regulation 2024/1772. First, critical services must be affected under Article 6. Second, either the special threshold in Article 9(5)(b) is met, or at least two other materiality criteria are met. The staff instruction to include critical services in field 2.5 should be applied within that test. Its reference to at least one other applicable criterion cannot reduce the ordinary two-criterion requirement. (Delegated Regulation 2024/1772, Arts. 6, 8(1) and 9; Operational Instructions, item 7.)

Article 6 treats services as critical where an incident affects ICT supporting critical or important functions, affects financial services requiring authorisation, registration or supervision, or constitutes successful malicious unauthorised system access. The special Article 9(5)(b) route concerns successful malicious unauthorised access, outside Article 9(5)(a), that may result in data losses. That route can apply before a large measured loss or prolonged outage emerges. An unsuccessful access attempt alone does not satisfy its successful-access condition. Other classification routes still require assessment. (Delegated Regulation 2024/1772, Arts. 6 and 9(5).)

The malicious-access shortcut expressly excludes access already covered by Article 9(5)(a). Where that exclusion applies, the ordinary combination requires assessment without counting the data-loss criterion twice. Recital 10 emphasises intrusion risks affecting critical or important functions, but does not repeal that express condition. A claim that every successful intrusion automatically satisfies Article 8(1)(a) would omit a qualification in its cross-referenced threshold. (Delegated Regulation 2024/1772, recital 10, Arts. 8(1) and 9(5).)

The clients, financial counterparts and transactions criterion has alternative triggers. These include more than 10% of clients using the affected service, more than 100,000 affected-service clients, or more than 30% of financial counterparts carrying out activities related to that service. More than 10% of the prescribed daily average transaction number or value also qualifies. An affected client or financial counterpart identified as relevant under Article 1(3) provides another alternative. Clients include the contractual beneficiaries specified in Article 1(1). The entity must use the prescribed population and reference data, rather than substitute its entire customer base for the affected-service denominator. (Delegated Regulation 2024/1772, Arts. 1 and 9(1).)

Reputational impact qualifies when an Article 2 condition exists. Those conditions address media attention, repetitive complaints by different clients or counterparts about client-facing services or critical business relationships, actual or likely regulatory non-compliance, and likely or actual loss of clients or counterparts with material business consequences. Duration qualifies when the incident lasts longer than 24 hours. Service downtime longer than two hours also qualifies where ICT supports critical or important functions. These duration and downtime alternatives belong to one criterion. (Delegated Regulation 2024/1772, Arts. 2–3 and 9(2)–(3).)

The geographical threshold requires effects in two or more Member States. The ordinary data-loss threshold requires an adverse effect, actual or expected, on business objectives or the ability to meet regulatory requirements. It covers availability, authenticity, integrity and confidentiality. Economic impact qualifies when costs and losses exceed, or are likely to exceed, EUR 100,000. Equality with a strict numerical threshold does not satisfy a rule requiring that threshold to be exceeded. (Delegated Regulation 2024/1772, Arts. 4–5 and 9(4)–(6).)

The counting rule has a concrete consequence. Exceeding the client percentage and the transaction percentage satisfies the single Article 9(1) criterion. Without the special malicious-access route, critical services plus those two percentages still lacks a second distinct criterion. The same applies to an incident that exceeds the duration and downtime limits but no other criterion. The firm must retain each criterion's calculation and factual basis, including estimates allowed by the regulation. Otherwise, a form can appear complete while its major classification rests on double counting. (Delegated Regulation 2024/1772, Arts. 1(5), 3, 7(3), 8(1) and 9.)

Recurring incidents and reassessment

DORA requires financial entities to record all ICT-related incidents and significant cyber threats. The reporting threshold does not limit that recording duty. Major incidents must reach relevant senior management, and the management body must receive information on impact, response and additional controls. The incident register supplies the records needed to test recurrence and justify classification decisions. (DORA, Art. 17(2), (3)(e).)

Repeated non-major incidents can collectively become one major incident. Article 8(2) requires at least two occurrences within six months, the same apparent root cause, and collective satisfaction of the major-incident test. In-scope entities must assess recurrence monthly, except microenterprises and the entities listed in DORA Article 16(1). Monthly recurrence review is a binding duty distinct from the staff expectation for monthly intermediate reports on an already reported major incident. (Delegated Regulation 2024/1772, Art. 8(2); Operational Instructions, item 4.)

Recurrence should be assessed from the incident register, even where each individual disruption was below threshold. A common supplier alone does not prove a common apparent root cause. The firm must link the events and assess their combined effects under Article 8(1). Implementing Regulation 2025/302 Article 3 requires the reporting form to contain aggregated information for qualifying recurring incidents. The exemption from this special aggregation rule does not excuse reporting an individually major incident. (DORA, Art. 17(2); Delegated Regulation 2024/1772, Art. 8; Implementing Regulation 2025/302, Art. 3.)

Notification deadlines and permissible extensions

The initial deadline combines an urgency requirement with two outer limits. The entity must notify as early as possible, within four hours after major classification and ordinarily within 24 hours after awareness. Where classification occurs within the first 24 hours, the earlier outer limit governs. These are constraints on one initial notification, not two successive notification stages. (Delegated Regulation 2025/301, Art. 5(1)(a).)

A derived timing illustration exposes the difference. Assume awareness at 08:00 UTC on 17 September 2026 and major classification at 06:00 UTC on 18 September. Adding four hours to classification gives 10:00 UTC; adding 24 hours to awareness gives 08:00 UTC. The earlier limit is 08:00 UTC on 18 September, subject to the duty to notify as early as possible. These assumed times describe no actual incident. (Delegated Regulation 2025/301, Art. 5(1)(a).)

Where the entity classifies the incident as major only after the first 24 hours, Article 5(2) permits notification within four hours of that classification. The exception prevents treating every later escalation as automatically late under the awareness limit. It does not excuse deficient detection or a deliberately postponed classification assessment. Those matters remain subject to DORA's incident-management and classification duties. (Delegated Regulation 2025/301, Art. 5(2); DORA, Arts. 17–18.)

The first intermediate report is due within 72 hours after the initial notification was actually submitted, even without a status change. A relevant status or handling change can require an earlier update. The authority may also request an updated intermediate report. Updated intermediate information must be submitted without undue delay and, in any event, when regular activities recover. The final report is due no later than one month after the intermediate report or, where applicable, its latest update. A calendar month must not be replaced automatically with 30 days. (DORA, Art. 19(4)(b); Delegated Regulation 2025/301, Art. 5(1)(b)–(c).)

Weekend and bank-holiday relief depends on the entity and report stage. Article 5(4) permits submission by noon on the next working day when the deadline falls on a weekend or bank holiday in the entity's Member State. Article 5(5) removes that relief for initial and intermediate reports by credit institutions, central counterparties, trading-venue operators and other financial entities identified as essential or important under Directive (EU) 2022/2555 (NIS2). Its exclusion does not extend to final reports. (Delegated Regulation 2025/301, Art. 5(4)–(5).)

A competent authority may also withdraw initial and intermediate relief for other significant or systemic financial entities. It must notify the entity; the decision applies to incidents reported after that notification. No such notice has been supplied for this matter. An entity unable to meet any reporting deadline must inform its authority without undue delay, no later than that deadline, and explain the delay. Article 5(3) creates that notification duty without granting an automatic extension. (Delegated Regulation 2025/301, Art. 5(3), (6).)

Required information and finalisation

A staged report must provide the information required at that stage, with estimates identified where permitted. The initial notification includes entity and contact data, the incident reference, detection and classification times, a description, triggering criteria and relevant cross-border effects. It also addresses discovery, known external origin and business-continuity activation. Initial uncertainty does not justify waiting for a completed forensic investigation. Implementing Regulation 2025/302 Article 1(3) requires estimated values, where possible, when accurate information is unavailable at the initial and intermediate stages. (Delegated Regulation 2025/301, Arts. 1–2; Implementing Regulation 2025/302, Art. 1 and Annex II, sections 1–2.)

The intermediate report adds operational detail: occurrence and recovery information, quantified effects, incident type, affected functions and infrastructure, client financial interests, temporary measures and relevant indicators of compromise. The final report adds root causes, resolution information, costs and recoveries, and applicable recurrence or resolution-authority information. Later reports must retain required earlier-stage information and incorporate updates. A file containing only changed cells is insufficient where the reporting rules require a complete updated report. (Delegated Regulation 2025/301, Arts. 3–4; Implementing Regulation 2025/302, Art. 1(4).)

Finalisation turns on the conditions in DORA Article 19(4)(c): completed root-cause analysis and actual impact figures that replace estimates. Implementation of every remedial measure need not be complete. The firm must therefore distinguish restored business activity, completed analysis and completion of permanent remediation. Treating the last remediation project as a necessary condition for a final report would add a condition that Article 19(4)(c) expressly rejects. (DORA, Art. 19(4)(c); Delegated Regulation 2025/301, Art. 4.)

Item 4 of the staff instructions expects at least one intermediate report per month until a final report is submitted. Article 5(1)(c) of Regulation 2025/301 also refers to the latest updated intermediate report when fixing the final deadline. Those provisions support genuine continuing updates while analysis remains open. They do not establish an unrestricted entitlement to defer closure through repetitive filings after the statutory finalisation conditions exist. Where completion cannot meet the applicable deadline, the firm must notify and explain the delay under Article 5(3). (Operational Instructions, item 4; DORA, Art. 19(4); Delegated Regulation 2025/301, Art. 5.)

A rapidly resolved incident can permit combined reporting. Implementing Regulation 2025/302 Article 2 allows two or all stages to be combined where regular activities have recovered or root-cause analysis is complete, provided every applicable deadline is met. Combining stages changes the submission arrangement, not the information required or the latest permitted notification time. (Implementing Regulation 2025/302, Art. 2.)

Report identity, corrections and reclassification

A correction should preserve the incident's identity and contain the latest complete information. Staff item 5 calls for a new version of the most recent report type: a corrected intermediate report follows an intermediate report. Item 6 identifies fields 1.3a/1.3b and 2.1 as stable identifiers. In the binding annex, field 1.3 identifies the submitting entity and field 2.1 is the incident reference. The annex does not itself split field 1.3 into those operational subfields. The firm must map the supervisor's template to the legal field definitions. (Operational Instructions, items 5–6; Implementing Regulation 2025/302, Art. 1(4), Annex II, fields 1.3 and 2.1.)

Field 2.1 must not be confused with the detection or classification timestamps. Those appear in fields 2.2 and 2.3. The staff instruction to preserve identifiers does not prohibit correcting an inaccurate factual timestamp. A change of submitting provider requires coordination with the authority so that truthful reporter information does not create a duplicate incident. Preserving the incident reference and the sequence of corrected reports addresses that risk. (Implementing Regulation 2025/302, Annex II, fields 1.3 and 2.1–2.3; Operational Instructions, items 5–6.)

Reclassification as non-major has a narrower legal condition than recovery. Article 5 of Implementing Regulation 2025/302 applies where further review establishes that the incident did not satisfy the major criteria at any time. An incident that genuinely crossed those thresholds remains historically major after services recover. The entity must explain a valid reclassification through the prescribed submission type and other-information fields. A later fall in losses or downtime does not itself establish that the original classification was wrong. (Implementing Regulation 2025/302, Art. 5, Annex II, fields 1.1 and 2.10.)

Monetary scale, gross losses and economic-impact fields

The report must distinguish an amount's reporting scale from the calculation used to classify the incident. Staff item 2 specifies thousands for fields 3.11, 4.13 and 4.14, in the currency declared in field 1.15. The annex already illustrates the conversion in field 3.11. Expressed with an English decimal point, EUR 2,500 divided by 1,000 gives 2.5. A derived conversion is amount divided by 1,000: EUR 125,000 becomes 125. This is a format conversion; the Article 9(6) threshold remains EUR 100,000. (Operational Instructions, item 2; Implementing Regulation 2025/302, Annex II, fields 1.15, 3.11 and 4.13–4.14; Delegated Regulation 2024/1772, Art. 9(6).)

The underlying amount must be tested before permitted rounding. EUR 100,001 exceeds EUR 100,000 even if a rounded thousands field displays 100. Conversely, exactly EUR 100,000 does not meet a threshold requiring an excess. A firm reporting in another currency needs a documented conversion for the euro-denominated classification test. The September instructions require a consistent reporting currency but do not prescribe a universal exchange-rate source or valuation time. (Delegated Regulation 2024/1772, Art. 9(6); Operational Instructions, item 2.)

Costs and losses are assessed gross. Article 7 includes incident-related asset losses, replacement costs, staff costs, contractual charges, customer compensation, foregone revenue, communications and advisory expenses. It excludes ordinary operational maintenance, post-incident business improvements and insurance premiums. Estimates apply when actual costs cannot yet be determined. Recoveries must not be deducted from the classification calculation or field 4.13; field 4.14 records them separately. Thus, an assumed EUR 125,000 loss with EUR 100,000 recovered still exceeds the economic threshold. (Delegated Regulation 2024/1772, Arts. 7 and 9(6); Implementing Regulation 2025/302, Annex II, fields 4.13–4.14.)

Field 4.12 presents a material difference between the annex and staff instructions. The annex marks it mandatory for the final report without an express condition. Staff item 14 expects completion when economic impact appears in field 2.5, while also permitting information for incidents classified under other criteria. The strongest argument for omission is that no reached economic threshold exists to describe. The contrary mandatory marker remains express. A defensible completion states whether the threshold was reached and explains the calculation, rather than silently treating the field as optional. (Implementing Regulation 2025/302, Art. 1(5), Annex II, field 4.12; Operational Instructions, item 14.)

The same annex description cites Articles 7 and 14 of Regulation 2024/1772. That regulation ends at Article 13; the economic threshold is in Article 9(6). This cross-reference defect does not erase Article 7's cost rules or the final report's cost and recovery requirements. A firm should record the correct substantive basis and seek clarification where its authority's validation rules prevent accurate completion. Fields 4.13 and 4.14 remain final-report requirements even where another criterion triggered major classification. (Delegated Regulation 2024/1772, Arts. 7, 9(6) and 13; Delegated Regulation 2025/301, Art. 4(e); Implementing Regulation 2025/302, Annex II, fields 4.12–4.14.)

Staff item 14 links an EBA answer on staff-cost calculation. Joint ESAs Q&A 2025_7439 clarifies that staff time clearly attributable to incident handling is included, even where resources were already assigned to incident response or overtime is compensated through time off. Routine preventive training is excluded; training to restore skills lost or impaired because of the incident is included. The Q&A does not prescribe a calculation methodology. The entity must identify costs attributable to the incident and distinguish excluded ordinary operating costs. The gross-cost field remains mandatory. (Delegated Regulation 2024/1772, Art. 7(1)(c), (2)–(3); Implementing Regulation 2025/302, Annex II, field 4.13; Joint ESAs Q&A 2025_7439, final answer published 14 November 2025; Operational Instructions, item 14, footnote 1.)

Duration, geographical spread and threat coding

Duration and service downtime require separate factual measurements. Incident duration runs from occurrence to resolution; uncertainty about the starting point or resolution requires the prescribed use of available records and estimates. Service downtime concerns full or partial unavailability and restoration of the affected service, including delayed service where applicable. A system restart does not establish that all affected services have recovered. (Delegated Regulation 2024/1772, Art. 3; Implementing Regulation 2025/302, Annex II, fields 3.15–3.16.)

Field 3.15 is mandatory for intermediate and final reports. The annex makes field 3.17, which identifies actual or estimated duration and downtime, conditional on the duration and downtime criterion being met. Staff item 10 expects field 3.17 whenever those stages are submitted, because duration itself must be reported. Completing the estimate indicator is consistent with accurate interpretation of that duration. Its broader staff expectation should not be misdescribed as a textual amendment to the annex condition. (Implementing Regulation 2025/302, Annex II, fields 3.15–3.17; Operational Instructions, item 10.)

Staff item 8 excludes the affected entity's home country from the country list in field 2.6. Article 9(4) separately sets the geographical threshold at effects in two or more Member States. Reading the threshold with Article 4, effects in the home Member State and one other Member State can satisfy it. The shortened field list does not require two foreign Member States. The firm should retain the full geographical assessment, even though the submission omits its home country. EEA-specific applications require the applicable incorporation rules. (Delegated Regulation 2024/1772, Arts. 4 and 9(4); Implementing Regulation 2025/302, Annex II, field 2.6; Operational Instructions, item 8.)

Field 3.25 contains inconsistent English descriptions of data exfiltration and manipulation. Its narrative excludes identity theft, while one selectable label includes it; identity theft also has a separate option. Staff item 11 prefers the narrative description. That reading avoids collapsing distinct categories and is a practical interpretation of the inconsistency. It does not constitute a legislative corrigendum. Where a portal retains the conflicting label, the entity should follow the authority's accepted coding and describe the actual technique accurately. (Implementing Regulation 2025/302, Annex II, field 3.25; Operational Instructions, item 11.)

Provider origin and conditional free text

Field 2.8 identifies the external source of an incident. Staff item 9 recommends a semicolon-separated sequence containing the provider's full legal name, identifier, identifier type and relevant additional information. The annex requires the external-origin information where the incident originates with a third-party provider or another financial entity. A company that merely submits the report is not necessarily the incident's source. The origin field should therefore be based on the incident evidence, rather than copied from the reporter details. (Implementing Regulation 2025/302, Annex II, field 2.8; Operational Instructions, item 9.)

Free-text fields that are non-mandatory and inapplicable should remain blank under staff item 3. Mandatory fields require relevant information, and conditionally mandatory fields require an assessment of their condition. An unknown fact is not automatically inapplicable. Available estimates and express descriptions of uncertainty are preferable to invented precision. Where the annex specifies a structure, including the functional-area and business-process information in field 3.27, the firm should follow it where feasible. (Implementing Regulation 2025/302, Art. 1(2)–(5), Annex II, field 3.27; Operational Instructions, item 3.)

Resolution fields 4.10 and 4.11 have their own conditions. Field 4.10 concerns risk to critical functions for bank-resolution purposes under Directive 2014/59/EU Article 2(1)(35). Field 4.11 concerns effects on the entity's or group's resolvability. Those conditions do not arise merely because DORA's critical-services criterion is met. The annex addresses entities within that directive's scope. Staff items 12–13 recommend leaving the fields blank where their conditions fail or the information is inapplicable. An insurer must not treat ordinary incident repair as a bank-resolution event. (Implementing Regulation 2025/302, Annex II, fields 4.10–4.11; Operational Instructions, items 12–13.)

Outsourced submissions and multi-entity reports

Outsourcing submission does not outsource legal responsibility. DORA Article 19(5) keeps the financial entity fully responsible for reporting. Implementing Regulation 2025/302 Article 6 requires notice of the arrangement as soon as it is concluded and before the first delegated submission, with the prescribed provider information. The authority must also be informed when the arrangement ends. A contract should allocate evidence delivery, approval, deadline escalation and access to acknowledgements so that the entity can discharge its retained duty. That allocation is an implementation recommendation, not an additional statutory checklist. (DORA, Art. 19(5); Implementing Regulation 2025/302, Art. 6.)

A provider may submit an aggregated report only when Article 7's conditions are met. The incident must originate from or be caused by an ICT service provider that supplies the relevant service to more than one financial entity or to a group. Every affected financial entity in the report must have classified the incident as major. The incident must affect financial entities within a single Member State. The aggregated report must cover entities supervised by the same competent authority, which must expressly permit aggregation for that entity type. A common outage across a multinational group does not itself satisfy these conditions. (Implementing Regulation 2025/302, Art. 7(1).)

Significant credit institutions, operators of trading venues and central counterparties cannot use this aggregated route. The competent authority can require an individual notification or report even where aggregation is otherwise permitted. This arrangement differs from aggregation of recurring incidents under Article 3. Combining reports for several entities cannot be used to manufacture a major classification that none of them reaches individually. (Implementing Regulation 2025/302, Arts. 3 and 7(1)–(3).)

Threat notifications, client communications and submission failure

A significant cyber threat has a separate voluntary notification route under DORA Article 19(2). The entity considers whether the threat is relevant to the financial system, service users or clients. Delegated Regulation 2024/1772 Article 10 requires potential effects on the entity's critical or important functions, or on other financial entities, providers, clients or financial counterparts. A high probability of materialisation is also required. Potential materiality must also satisfy Article 6 criticality, the Article 9(1) clients, counterparts and transactions threshold, or the Article 9(4) geographical threshold. Other listed materiality thresholds may inform the assessment where appropriate. Probability depends on the specified vulnerability, threat-actor and persistence factors. A threat that has not materialised should not be forced into the major-incident timetable. Its notification uses the separate content and forms prescribed for threats. (DORA, Art. 19(2); Delegated Regulation 2024/1772, Art. 10; Delegated Regulation 2025/301, Art. 6; Implementing Regulation 2025/302, Art. 8 and Annexes III–IV.)

Client communication is independently triggered. Where a major incident affects clients' financial interests, the entity must inform them without undue delay after awareness and explain the measures taken to reduce adverse effects. For significant cyber threats, potentially affected clients must receive information on appropriate protective measures where applicable. Reporting to the authority does not itself satisfy either communication duty. (DORA, Art. 19(3).)

DORA Article 1(2) treats DORA as a sector-specific Union act for covered entities under NIS2. That relationship does not justify assuming that every other notification obligation disappears. Article 19(1) allows Member States to require an additional copy for the designated NIS authority or CSIRT. Personal-data breach reporting also requires separate assessment. The entity's privacy obligations and any national duplicate-submission requirement cannot be determined without its jurisdiction and incident facts. (DORA, Arts. 1(2) and 19(1); Delegated Regulation 2024/1772, recital 15.)

The normal submission channel must be secure. Where it is unavailable, Implementing Regulation 2025/302 Article 4 permits alternative secure means agreed with the competent authority, followed by resubmission through the usual channel if required. DORA Article 19(1) also addresses technical impossibility affecting use of the initial template. An unavailable portal does not suspend the deadline by itself. The firm should retain attempted-submission records, its contact with the authority and evidence of delivery through the agreed alternative. (DORA, Art. 19(1); Implementing Regulation 2025/302, Art. 4; Delegated Regulation 2025/301, Art. 5(3).)

Enforcement and the evidence needed for an entity-specific decision

Failure to classify or report correctly can engage national supervisory powers under DORA Article 50. Those powers include access to records, inspections, corrective requirements and sanctions provided by Member States. DORA does not establish a single harmonised monetary fine for every reporting breach. Article 51 requires consideration of intent or negligence and the breach's materiality, gravity and duration. Other relevant factors include responsibility, financial strength, gains or avoided losses, third-party losses, cooperation and previous infringements. Article 52 also permits Member States to use criminal penalties. No monetary exposure can be calculated without the relevant national provisions and facts. (DORA, Arts. 50–52.)

A firm facing criticism may rely on a statutory exemption, an unmet threshold, permitted estimates or valid holiday relief. Each position depends on evidence of its conditions. A documented inability to submit requires timely notice under Article 5(3) of Delegated Regulation 2025/301; it does not itself extend the deadline or create an exemption. Prompt correction and cooperation can matter to supervisory assessment without erasing an earlier breach. Reliance on staff instructions is strongest where they clarify an ambiguous field; it is weaker where the annex contains an express contrary requirement. Supervisory decisions imposing penalties or remedial measures must be reasoned and subject to appeal under DORA Article 50(6). (DORA, Arts. 50(6) and 51(2); Delegated Regulation 2025/301, Art. 5; Implementing Regulation 2025/302, Art. 1.)

The immediate decision requires the entity's authorisation and size information, its competent authority's current submission rules, and any notice withdrawing holiday relief. For an actual incident, the decisive records are awareness and classification times, affected functions, criterion calculations, root-cause evidence, gross loss records and each submission acknowledgement. Reporter delegation and aggregation permission must be documented separately. Without those records, the EU duties can be stated, but a finding of timely compliance or breach would exceed the available facts. (DORA, Arts. 2, 17–19 and 46; Delegated Regulation 2025/301, Art. 5; Implementing Regulation 2025/302, Arts. 6–7.)

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.