Resource center · Operational Resilience

DORA incident reporting and how it relates to the register.

Two obligations, one dependency map. The register is an annual dataset; incident reporting is a clock that starts the moment an incident is classified. What connects them is the function and provider data underneath both.

Q & A DORA · European Union · incident reporting

Classifying an incident as major

Delegated Regulation (EU) 2024/1772 sets out the criteria for classifying ICT-related incidents and the materiality thresholds attached to them. The criteria cover clients, financial counterparts and transactions affected; reputational impact; duration and service downtime; geographical spread; data losses affecting availability, authenticity, integrity or confidentiality; and the criticality of the services disrupted.

The determination is quantitative rather than impressionistic, which has a practical consequence: the measurements have to be available during an incident, not reconstructed afterwards. A firm that cannot count affected clients while the incident is running cannot classify it on time.

Classification starts the clock, not detection. The reporting time limits run from the point of classification, with an outer bound tied to detection. That makes the speed of the classification decision itself a control worth designing.

The three-stage cycle

The reporting sequence
StagePurpose
Initial notificationTells the authority an incident has been classified as major, with what is known at that point. Estimates are permitted where precise data is not yet available.
Intermediate reportUpdates the picture. Required even where the status and handling have not changed — silence is not an option.
Final reportRoot cause analysis, full impact assessment and the remediation completed.

Content and time limits are set out in Commission Delegated Regulation (EU) 2025/301, and the templates in the corresponding implementing standards. Significant cyber threats can be notified voluntarily under a separate, lighter template.

What the reports need

Across the three stages the reports draw on: the affected functions and whether they are critical or important; the ICT third-party service providers involved; the clients, counterparties and transactions affected; the duration and downtime against recovery objectives; the member states affected; the classification criteria met and the values behind them; and, by the final report, root cause and remediation.

The first two of those are exactly what the register holds. The rest are operational measurements that no annual dataset can supply.

Where the register helps

  • Provider identification. When an incident originates at a supplier, the register already carries its legal identity and identification code — which is faster and more accurate than a procurement search at three in the morning.
  • Function mapping. The service-to-function mapping answers “which functions does this affect” directly, including whether any is critical or important.
  • Supply chain. Where the failure is at a subcontractor, the ranked chain shows how it reaches you.
  • Consistency. Naming a provider one way in an incident report and another in the register invites a question neither answer survives well.

Where they are genuinely separate

The register is a periodic supervisory dataset with fixed templates and an annual rhythm. Incident reporting is event-driven, runs on hours and days, and asks for measurements the register does not hold. Building one process to serve both fails in the same way combining EMIR and MiFIR does: the shared part is the reference data, not the workflow.

Official sources

Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.

  1. Regulation (EU) 2022/2554 (DORA), Articles 17 to 23EUR-Lex · Regulation · ICT-related incident management and reporting
  2. Commission Delegated Regulation (EU) 2024/1772 specifying the criteria for the classification of ICT-related incidents and cyber threats, and materiality thresholdsEUR-Lex · Delegated Regulation · the classification test
  3. Commission Delegated Regulation (EU) 2025/301 on the content and time limits for the initial notification and the intermediate and final reportsEUR-Lex · Delegated Regulation · content and timing · with the corresponding implementing standards for templates
  4. Commission Implementing Regulation (EU) 2024/2956 — register of information templatesEUR-Lex · Implementing Regulation · the shared function and provider data

Questions, answered

Do we still send an intermediate report if nothing has changed?

Yes. The intermediate report is required within its time limit even where the status or handling of the incident has not changed since the initial notification. Teams that treat it as conditional on new information miss it routinely.

Can we use estimates in the initial notification?

Yes, where precise data is not yet available — that is the point of a staged cycle. What matters is that estimates are identified as such and updated in the later reports rather than left standing.

Does an incident at a provider count as ours to report?

If it is an ICT-related incident affecting your functions, the reporting obligation is yours regardless of where it originated. This is why the register's provider and supply-chain data is operationally useful during an incident, not just annually.

Does the register need updating after an incident?

Not because of the incident itself. It needs updating when the arrangement, the provider, the supply chain or the criticality of a function changes — which an incident sometimes causes but does not automatically mean.

REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.

Keep reading

More on this framework, and the module that produces the filing.

All operational resilience resources

The reference data has to be right before the incident.

A maintained register is the fastest source of provider identity and function impact when the clock is already running.