Free tool · No account needed

DORA major incident classification

Not every ICT incident is reportable — only major ones, and the deadline starts running the moment you classify. It is a two-step test rather than a judgement call: a primary gate, then either a confirmed malicious breach or two materiality criteria. One criterion is not enough.

DORA Art. 18 · RTS (EU) 2024/1772 Art. 8 · gate then two · nothing stored

Classify one incident

Runs in your browser · nothing uploaded

Do not enter incident detail here — this tool takes only your assessment against each criterion. Estimates are acceptable at the initial and intermediate stages, so mark anything you cannot yet quantify as Unsure rather than guessing it away.

Step 1 · the primary gate

Does the incident pass the entry condition?

Nothing below matters unless one of these is true. An incident that affects no critical or important function and involves no malicious access does not reach the materiality test at all.

Are critical or important functions affected? The same determination you make under Article 3(22). If you have not made it for the affected service, that is the first problem to solve.
Has successful malicious unauthorised access been established, with possible data loss? Where this is confirmed alongside critical service impact, the incident is major on that basis alone — the two-criteria test does not need to be reached.

Step 2 — materiality criteria

RTS (EU) 2024/1772 · at least two required

Each criterion has its own threshold. Meeting one does not make an incident major; meeting two does.

Clients, financial counterparts and transactions affected More than 10% of clients, or more than 10% of transactions, or an absolute number the RTS specifies for your entity type. Reputational impact is folded in here — media attention, repeated complaints from different clients, loss of clients or regulatory enforcement all bear on this criterion.
Duration and service downtime Incident duration longer than 24 hours, or service downtime exceeding 2 hours for ICT services supporting critical or important functions.
Geographical spread Impact in the territory of at least two Member States.
Data losses Impact on the availability, authenticity, integrity or confidentiality of data that has or will have an adverse effect on your business objectives or on meeting regulatory requirements.
Economic impact Direct and indirect costs above €100,000 — replacement, staff, compensation, forgone revenue. The RTS allows reasonable estimates for the initial and intermediate reports.
What this means: an indicative classification from your own assessment. The RTS sets materiality thresholds that vary by entity type, and several turn on figures you may only be able to estimate mid-incident. Recurring incidents that are individually below threshold may need aggregating where they are related and fall within the same window. The classification decision must be documented and defensible, and this tool is an aid to that rather than a substitute. This is not legal or regulatory advice.

The clock starts at classification, not at resolution. The DORA module keeps the incident register, applies the RTS criteria consistently and pre-populates the notification templates from the record — with free record keeping to start.

Create free account
Why the structure matters

A gate, then a count — not a score

The most common classification errors come from treating this as an overall impression rather than the two-step test it is.

Error 1

One severe criterion is enough

It is not. An incident affecting critical services and registering material impact on only one criterion does not qualify. Severity on a single axis does not substitute for breadth across two.

Error 2

Reputation is its own criterion

It is folded into the clients and transactions criterion, assessed through media attention and repeated complaints alongside client and transaction numbers — not counted separately towards the two.

Error 3

Classify when you are certain

The reporting clock starts at classification. Delaying the decision until every figure is confirmed does not extend the deadline — and the RTS expressly allows estimates in the initial and intermediate reports for that reason.

Rules reviewed 21 August 2026 · Regulation (EU) 2022/2554 Art. 18 and 19 · Commission Delegated Regulation (EU) 2024/1772

Scope

What this tool does

It doesApply the two-step test

  • Tests the primary gate before any materiality criterion.
  • Applies the malicious-access route, which qualifies on its own.
  • Requires at least two criteria, and says so where only one is met.
  • Distinguishes criteria confirmed from criteria you could not yet assess.
  • Sets out the reporting deadlines that follow a major classification.
  • Notes where an unresolved criterion would change the outcome.

It does notMeasure the thresholds

  • Apply the entity-type-specific materiality thresholds in the RTS.
  • Calculate client percentages, downtime or economic impact from your data.
  • Aggregate recurring incidents that are individually below threshold.
  • Determine whether a service supports a critical or important function.
  • Handle the interaction with GDPR breach notification, which runs on its own clock.
  • Generate or submit any notification. It is a test, not a report.

The gate depends on a determination you make in advance

Whether a service supports a critical or important function is not a question to answer during an incident. It should already be recorded.

Critical or important function test

Nothing you enter here leaves your browser

This tool takes no incident detail. Your answers are held in the page and discarded when you close or reload it. Nothing is sent to REGREP, written to a log, saved, or passed to any analytics tool.

An live incident is the worst possible time for data to leave your control, which is why this one asks for assessments rather than facts.

Questions

About incident classification

What makes an incident major?

Under Article 8 of Delegated Regulation (EU) 2024/1772, the incident must first affect critical services. It is then major where successful malicious unauthorised access with possible data loss is established, or where at least two of the remaining materiality criteria meet their thresholds. An incident affecting critical services but registering on only one criterion does not qualify.

What are the criteria?

Clients, financial counterparts and transactions affected; reputational impact; duration and service downtime; geographical spread; data losses; criticality of services affected; and economic impact. Reputational impact is assessed within the clients and transactions criterion rather than counted separately.

What are the headline thresholds?

Commonly cited figures include more than 10% of clients or transactions affected, service downtime exceeding two hours for services supporting critical or important functions, incident duration beyond 24 hours, impact across at least two Member States, and economic impact above €100,000 counting both direct and indirect costs. Several thresholds vary by entity type, so check the RTS for your own.

When do I have to report?

Three stages: an initial notification, an intermediate report, and a final report. The widely applied timings are four hours from classification for the initial notification and no later than 24 hours from detection, 72 hours for the intermediate report, and one month for the final report. Confirm the exact timings and templates applicable to your entity with your competent authority.

Can I use estimates?

Yes, and you are expected to. The RTS expressly allows reasonable estimates of costs and losses in the initial notification and intermediate report, with more accurate figures in the final report. Waiting for confirmed numbers before classifying does not pause the clock.

What about incidents that are individually small?

Recurring incidents that are individually below threshold may need to be aggregated where they are related and fall within the same window. A pattern of small outages on the same service is not automatically outside the regime.

Do you store my answers?

No. The tool takes no incident detail and stores nothing.

Four hours is not long to be deciding what the rules mean.

Create a free account and keep the incident register, the criteria and the templates in one place before you need them.

No card required · free record keeping and validation · nothing stored from this tool