Regulation · CELEX 32022R2554
Regulation (EU) 2022/2554 — digital operational resilience
View official text on EUR-Lex →11 obligations
DORA-005 · Regulation (EU) 2022/2554 — digital operational resilience, Article 5
Governance and organisation of ICT risk management
Maintain an internal governance and control framework ensuring effective, prudent ICT risk management for a high level of digital operational resilience. The management body defines, approves, oversees and is responsible for the ICT risk management framework — bearing ultimate responsibility for ICT risk; setting data availability/authenticity/integrity/confidentiality policies; setting clear ICT-function roles/responsibilities and coordination governance; approving the digital operational resilience strategy and ICT risk tolerance; approving and periodically reviewing the ICT business continuity policy and response/recovery plans; approving ICT internal audit plans and material changes; allocating and reviewing budget for digital operational resilience needs including awareness/training; approving and reviewing the ICT third-party service provider policy; and establishing reporting channels on third-party arrangements, planned material changes, and major ICT-related incidents. Entities other than microenterprises establish a dedicated role or senior-management responsibility for overseeing ICT third-party risk exposure, and management body members keep their ICT risk knowledge/skills current via regular training.
Applicable now
DORA-005 · Regulation (EU) 2022/2554 — digital operational resilience, Article 5
Governance and organisation of ICT risk management
Maintain an internal governance and control framework ensuring effective, prudent ICT risk management for a high level of digital operational resilience. The management body defines, approves, oversees and is responsible for the ICT risk management framework — bearing ultimate responsibility for ICT risk; setting data availability/authenticity/integrity/confidentiality policies; setting clear ICT-function roles/responsibilities and coordination governance; approving the digital operational resilience strategy and ICT risk tolerance; approving and periodically reviewing the ICT business continuity policy and response/recovery plans; approving ICT internal audit plans and material changes; allocating and reviewing budget for digital operational resilience needs including awareness/training; approving and reviewing the ICT third-party service provider policy; and establishing reporting channels on third-party arrangements, planned material changes, and major ICT-related incidents. Entities other than microenterprises establish a dedicated role or senior-management responsibility for overseeing ICT third-party risk exposure, and management body members keep their ICT risk knowledge/skills current via regular training.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:921-981
How this is verified
The management body has defined, approved and overseen the ICT risk management framework per Article 5(2)(a)-(i), a dedicated role or senior-management owner monitors ICT third-party arrangements (non-microenterprises), and management body members receive regular ICT risk training
Board-level governance evidence (meeting minutes, approval records) is qualitative and typically requires document review rather than automated verification — draft placeholder pending compliance-expert input on what counts as sufficient evidence.
Last verified against primary law 23 Jul 2026
DORA-006 · Regulation (EU) 2022/2554 — digital operational resilience, Article 6
ICT risk management framework
Maintain a sound, comprehensive, well-documented ICT risk management framework as part of the overall risk management system, including strategies, policies, procedures, ICT protocols and tools protecting all information/ICT assets and physical components/infrastructure from damage and unauthorised access. Minimise ICT risk impact via the framework's deployed measures, and provide complete/updated ICT risk information to competent authorities on request. Entities other than microenterprises assign ICT risk management/oversight to an independent control function with appropriate segregation from ICT risk management and internal audit functions (three-lines-of-defence or equivalent model). The framework is documented and reviewed at least annually (or periodically for microenterprises), and after major ICT-related incidents or supervisory/testing/audit findings, continuously improved from implementation lessons, with a review report available to the competent authority on request. The framework is subject to regular internal audit by appropriately independent, ICT-risk-competent auditors (non-microenterprises), with a formal follow-up process for critical audit findings. The framework includes a documented digital operational resilience strategy covering Article 6(8)(a)-(h): business-strategy alignment, risk tolerance, information security objectives/KPIs, ICT reference architecture, incident detection/prevention mechanisms, resilience-situation evidence, resilience testing per Chapter IV, and an incident communication strategy.
Applicable now
DORA-006 · Regulation (EU) 2022/2554 — digital operational resilience, Article 6
ICT risk management framework
Maintain a sound, comprehensive, well-documented ICT risk management framework as part of the overall risk management system, including strategies, policies, procedures, ICT protocols and tools protecting all information/ICT assets and physical components/infrastructure from damage and unauthorised access. Minimise ICT risk impact via the framework's deployed measures, and provide complete/updated ICT risk information to competent authorities on request. Entities other than microenterprises assign ICT risk management/oversight to an independent control function with appropriate segregation from ICT risk management and internal audit functions (three-lines-of-defence or equivalent model). The framework is documented and reviewed at least annually (or periodically for microenterprises), and after major ICT-related incidents or supervisory/testing/audit findings, continuously improved from implementation lessons, with a review report available to the competent authority on request. The framework is subject to regular internal audit by appropriately independent, ICT-risk-competent auditors (non-microenterprises), with a formal follow-up process for critical audit findings. The framework includes a documented digital operational resilience strategy covering Article 6(8)(a)-(h): business-strategy alignment, risk tolerance, information security objectives/KPIs, ICT reference architecture, incident detection/prevention mechanisms, resilience-situation evidence, resilience testing per Chapter IV, and an incident communication strategy.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:985-1039
How this is verified
A documented ICT risk management framework exists with an independent control function (non-microenterprises), is reviewed at least annually or after major incidents, is subject to regular internal audit with a critical-finding follow-up process, and includes a digital operational resilience strategy covering Article 6(8)(a)-(h)
Audit frequency and what counts as a 'major' ICT-related incident triggering an off-cycle review are entity-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-007 · Regulation (EU) 2022/2554 — digital operational resilience, Article 7
ICT systems, protocols and tools
Use and maintain updated ICT systems, protocols and tools that are appropriate to the scale of operations (per the Article 4 proportionality principle), reliable, equipped with sufficient capacity to accurately process data and handle peak volumes including when new technology is introduced, and technologically resilient enough to handle additional processing needs under stressed market conditions or other adverse situations.
Applicable now
DORA-007 · Regulation (EU) 2022/2554 — digital operational resilience, Article 7
ICT systems, protocols and tools
Use and maintain updated ICT systems, protocols and tools that are appropriate to the scale of operations (per the Article 4 proportionality principle), reliable, equipped with sufficient capacity to accurately process data and handle peak volumes including when new technology is introduced, and technologically resilient enough to handle additional processing needs under stressed market conditions or other adverse situations.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1043-1061
How this is verified
ICT systems, protocols and tools in use are documented as appropriate to operational scale, reliable, sufficiently capacious for peak loads, and resilient under stressed conditions
Capacity/resilience thresholds are entity-specific and scale-dependent — draft placeholder pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-008 · Regulation (EU) 2022/2554 — digital operational resilience, Article 8
Identification of ICT-supported functions, assets and risk sources
As part of the ICT risk management framework, identify, classify and document all ICT-supported business functions, roles, responsibilities, and the information/ICT assets supporting them, reviewing this classification at least yearly. Continuously identify all sources of ICT risk (including exposure to/from other financial entities) and assess relevant cyber threats/vulnerabilities, reviewing risk scenarios at least yearly. Non-microenterprises perform a risk assessment upon each major change to network/information system infrastructure or ICT-supported processes/procedures. Identify all information/ICT assets (including remote sites, network resources, hardware), map critical ones and their configurations/interdependencies. Identify and document all processes dependent on ICT third-party service providers and interconnections supporting critical/important functions. Maintain and periodically update relevant inventories. Non-microenterprises conduct a specific ICT risk assessment on all legacy ICT systems at least yearly and before/after connecting new technologies, applications or systems.
Applicable now
DORA-008 · Regulation (EU) 2022/2554 — digital operational resilience, Article 8
Identification of ICT-supported functions, assets and risk sources
As part of the ICT risk management framework, identify, classify and document all ICT-supported business functions, roles, responsibilities, and the information/ICT assets supporting them, reviewing this classification at least yearly. Continuously identify all sources of ICT risk (including exposure to/from other financial entities) and assess relevant cyber threats/vulnerabilities, reviewing risk scenarios at least yearly. Non-microenterprises perform a risk assessment upon each major change to network/information system infrastructure or ICT-supported processes/procedures. Identify all information/ICT assets (including remote sites, network resources, hardware), map critical ones and their configurations/interdependencies. Identify and document all processes dependent on ICT third-party service providers and interconnections supporting critical/important functions. Maintain and periodically update relevant inventories. Non-microenterprises conduct a specific ICT risk assessment on all legacy ICT systems at least yearly and before/after connecting new technologies, applications or systems.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1063-1079
How this is verified
ICT-supported business functions, assets, risk sources and third-party dependencies are identified, classified, mapped and documented per Article 8(1)-(7), with inventories maintained and reviewed at least yearly or after major changes
The specific mapping granularity and 'major change' threshold are entity-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-009 · Regulation (EU) 2022/2554 — digital operational resilience, Article 9
Protection and prevention
Continuously monitor and control ICT system security/functioning, minimising ICT risk impact via appropriate security tools, policies and procedures. Design, procure and implement ICT security policies/procedures/protocols/tools ensuring resilience, continuity and availability of ICT systems (especially those supporting critical/important functions) and high standards of data availability/authenticity/integrity/confidentiality at rest, in use and in transit — via solutions that secure data transfer, minimise corruption/loss/unauthorised-access risk, prevent availability/integrity/confidentiality breaches, and protect against data-management risks including human error. As part of the framework: develop and document an information security policy; establish a risk-based network/infrastructure management structure (potentially including automated isolation of affected assets during cyber-attacks, with network connections designed to be instantly severable/segmentable); implement access-limiting policies restricting physical/logical access to what's required for legitimate functions, with sound access-rights administration; implement strong-authentication and cryptographic-key-protection policies based on data classification/risk assessment; implement documented, risk-based ICT change management policies ensuring changes are recorded, tested, assessed, approved, implemented and verified in a controlled manner (approved by appropriate management lines with specific protocols); and maintain comprehensive documented patch/update policies.
Applicable now
DORA-009 · Regulation (EU) 2022/2554 — digital operational resilience, Article 9
Protection and prevention
Continuously monitor and control ICT system security/functioning, minimising ICT risk impact via appropriate security tools, policies and procedures. Design, procure and implement ICT security policies/procedures/protocols/tools ensuring resilience, continuity and availability of ICT systems (especially those supporting critical/important functions) and high standards of data availability/authenticity/integrity/confidentiality at rest, in use and in transit — via solutions that secure data transfer, minimise corruption/loss/unauthorised-access risk, prevent availability/integrity/confidentiality breaches, and protect against data-management risks including human error. As part of the framework: develop and document an information security policy; establish a risk-based network/infrastructure management structure (potentially including automated isolation of affected assets during cyber-attacks, with network connections designed to be instantly severable/segmentable); implement access-limiting policies restricting physical/logical access to what's required for legitimate functions, with sound access-rights administration; implement strong-authentication and cryptographic-key-protection policies based on data classification/risk assessment; implement documented, risk-based ICT change management policies ensuring changes are recorded, tested, assessed, approved, implemented and verified in a controlled manner (approved by appropriate management lines with specific protocols); and maintain comprehensive documented patch/update policies.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1081-1135
How this is verified
ICT security policies/procedures/tools per Article 9(4)(a)-(f) are documented and implemented — information security policy, risk-based network management with segmentation capability, least-privilege access controls, strong authentication/key protection, controlled change management, and patch/update policies
Specific technical thresholds (e.g. authentication strength, segmentation triggers) are entity/risk-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-010 · Regulation (EU) 2022/2554 — digital operational resilience, Article 10
Detection
Maintain mechanisms to promptly detect anomalous activities — including ICT network performance issues, ICT-related incidents, and potential material single points of failure — regularly tested per Article 25. Detection mechanisms enable multiple layers of control, define alert thresholds/criteria triggering incident response processes, and include automatic alerts for relevant incident-response staff. Devote sufficient resources/capabilities to monitor user activity and ICT anomalies/incidents, particularly cyber-attacks. Data reporting service providers additionally maintain systems to check trade reports for completeness, identify omissions/errors, and request re-transmission.
Applicable now
DORA-010 · Regulation (EU) 2022/2554 — digital operational resilience, Article 10
Detection
Maintain mechanisms to promptly detect anomalous activities — including ICT network performance issues, ICT-related incidents, and potential material single points of failure — regularly tested per Article 25. Detection mechanisms enable multiple layers of control, define alert thresholds/criteria triggering incident response processes, and include automatic alerts for relevant incident-response staff. Devote sufficient resources/capabilities to monitor user activity and ICT anomalies/incidents, particularly cyber-attacks. Data reporting service providers additionally maintain systems to check trade reports for completeness, identify omissions/errors, and request re-transmission.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- High
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1137-1149
How this is verified
Detection mechanisms exist covering anomalous activity, network performance and single-point-of-failure identification, with defined alert thresholds/criteria and automatic staff alerting, regularly tested per Article 25
Alert thresholds and monitoring resourcing levels are entity-specific — draft placeholder pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-011 · Regulation (EU) 2022/2554 — digital operational resilience, Article 11
Response and recovery
As part of the ICT risk management framework and based on Article 8 identification, maintain a comprehensive ICT business continuity policy implemented via documented arrangements/plans/procedures/mechanisms that ensure continuity of critical/important functions; enable quick, effective incident response limiting damage and prioritising resumption/recovery; activate containment measures without delay per incident type; estimate preliminary impacts/damages/losses; and set out communication/crisis-management actions per Article 14 with competent-authority reporting per Article 19. Implement associated ICT response and recovery plans (independently internally audited for non-microenterprises). Maintain and periodically test ICT business continuity plans, especially for outsourced critical/important functions. Conduct a business impact analysis (BIA) of exposure to severe business disruptions using quantitative/qualitative criteria, considering business-function/process/third-party/asset criticality and interdependencies, ensuring ICT assets/services align with BIA findings including critical-component redundancy. Test business continuity and response/recovery plans (including crisis communication plans) at least yearly and after substantive ICT-system changes, with non-microenterprises including cyber-attack scenarios and primary/redundant-infrastructure switchover testing. Regularly review the policy/plans based on test results and audit/supervisory recommendations. Non-microenterprises maintain a crisis management function for plan activation. Keep readily accessible records of disruption-event activities.
Applicable now
DORA-011 · Regulation (EU) 2022/2554 — digital operational resilience, Article 11
Response and recovery
As part of the ICT risk management framework and based on Article 8 identification, maintain a comprehensive ICT business continuity policy implemented via documented arrangements/plans/procedures/mechanisms that ensure continuity of critical/important functions; enable quick, effective incident response limiting damage and prioritising resumption/recovery; activate containment measures without delay per incident type; estimate preliminary impacts/damages/losses; and set out communication/crisis-management actions per Article 14 with competent-authority reporting per Article 19. Implement associated ICT response and recovery plans (independently internally audited for non-microenterprises). Maintain and periodically test ICT business continuity plans, especially for outsourced critical/important functions. Conduct a business impact analysis (BIA) of exposure to severe business disruptions using quantitative/qualitative criteria, considering business-function/process/third-party/asset criticality and interdependencies, ensuring ICT assets/services align with BIA findings including critical-component redundancy. Test business continuity and response/recovery plans (including crisis communication plans) at least yearly and after substantive ICT-system changes, with non-microenterprises including cyber-attack scenarios and primary/redundant-infrastructure switchover testing. Regularly review the policy/plans based on test results and audit/supervisory recommendations. Non-microenterprises maintain a crisis management function for plan activation. Keep readily accessible records of disruption-event activities.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- Critical
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1151-1207
How this is verified
A documented ICT business continuity policy and response/recovery plans exist covering Article 11(2)(a)-(e), a business impact analysis informs asset/service design, plans are tested at least yearly (including cyber-attack scenarios for non-microenterprises) and reviewed based on results, and disruption-event records are kept accessible
BIA methodology and test scenario coverage are entity-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-012 · Regulation (EU) 2022/2554 — digital operational resilience, Article 12
Backup policies, restoration and recovery procedures
To restore ICT systems and data with minimum downtime/disruption/loss, develop and document backup policies/procedures (specifying backup scope and minimum frequency based on data criticality/confidentiality) and restoration/recovery procedures/methods. Set up backup systems activatable per those policies without jeopardising network/system security or data availability/authenticity/integrity/confidentiality, with periodic testing of backup and restoration/recovery procedures. When restoring from backup using own systems, use ICT systems physically and logically segregated from the source system, securely protected from unauthorised access/corruption, allowing timely service restoration. Non-microenterprises maintain redundant ICT capacities adequate for business needs (microenterprises assess the need based on risk profile). Determine recovery time/point objectives per function considering criticality and market-efficiency impact, ensuring agreed service levels are met in extreme scenarios. When recovering from an incident, perform necessary checks (including multiple checks/reconciliations) to maintain the highest data integrity, including when reconstructing data from external stakeholders.
Applicable now
DORA-012 · Regulation (EU) 2022/2554 — digital operational resilience, Article 12
Backup policies, restoration and recovery procedures
To restore ICT systems and data with minimum downtime/disruption/loss, develop and document backup policies/procedures (specifying backup scope and minimum frequency based on data criticality/confidentiality) and restoration/recovery procedures/methods. Set up backup systems activatable per those policies without jeopardising network/system security or data availability/authenticity/integrity/confidentiality, with periodic testing of backup and restoration/recovery procedures. When restoring from backup using own systems, use ICT systems physically and logically segregated from the source system, securely protected from unauthorised access/corruption, allowing timely service restoration. Non-microenterprises maintain redundant ICT capacities adequate for business needs (microenterprises assess the need based on risk profile). Determine recovery time/point objectives per function considering criticality and market-efficiency impact, ensuring agreed service levels are met in extreme scenarios. When recovering from an incident, perform necessary checks (including multiple checks/reconciliations) to maintain the highest data integrity, including when reconstructing data from external stakeholders.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- Critical
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1209-1251
How this is verified
Documented backup policies (scope, frequency by criticality) and restoration/recovery procedures exist, backup systems are periodically tested and logically/physically segregated from source systems, redundant ICT capacity is maintained (non-microenterprises) or assessed (microenterprises), and recovery time/point objectives are defined per function
Backup frequency and recovery time/point objective thresholds are entity/criticality-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-013 · Regulation (EU) 2022/2554 — digital operational resilience, Article 13
Learning and evolving
Maintain capabilities and staff to gather and analyse information on vulnerabilities, cyber threats and ICT-related incidents and their likely digital-operational-resilience impact. Conduct post-incident reviews after major ICT-related incidents disrupt core activities, analysing disruption causes and required improvements to ICT operations or the business continuity policy — assessing response promptness, forensic-analysis quality/speed, incident-escalation effectiveness, and internal/external communication effectiveness (non-microenterprises report implemented changes to competent authorities on request). Continuously incorporate lessons from resilience testing (Articles 26-27), real incidents, business-continuity-plan activation challenges, and supervisory-review findings into the ICT risk assessment process and framework reviews. Monitor digital operational resilience strategy implementation effectiveness, mapping ICT risk evolution and incident patterns to understand exposure and enhance cyber maturity. Senior ICT staff report findings to the management body at least yearly with recommendations. Develop compulsory ICT security awareness/resilience training for all staff and senior management (including, where appropriate, ICT third-party providers). Non-microenterprises continuously monitor relevant technological developments and keep ICT risk management processes current against evolving cyber-attack forms.
Applicable now
DORA-013 · Regulation (EU) 2022/2554 — digital operational resilience, Article 13
Learning and evolving
Maintain capabilities and staff to gather and analyse information on vulnerabilities, cyber threats and ICT-related incidents and their likely digital-operational-resilience impact. Conduct post-incident reviews after major ICT-related incidents disrupt core activities, analysing disruption causes and required improvements to ICT operations or the business continuity policy — assessing response promptness, forensic-analysis quality/speed, incident-escalation effectiveness, and internal/external communication effectiveness (non-microenterprises report implemented changes to competent authorities on request). Continuously incorporate lessons from resilience testing (Articles 26-27), real incidents, business-continuity-plan activation challenges, and supervisory-review findings into the ICT risk assessment process and framework reviews. Monitor digital operational resilience strategy implementation effectiveness, mapping ICT risk evolution and incident patterns to understand exposure and enhance cyber maturity. Senior ICT staff report findings to the management body at least yearly with recommendations. Develop compulsory ICT security awareness/resilience training for all staff and senior management (including, where appropriate, ICT third-party providers). Non-microenterprises continuously monitor relevant technological developments and keep ICT risk management processes current against evolving cyber-attack forms.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- Medium
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1253-1289
How this is verified
Post-incident reviews are conducted after major incidents assessing Article 13(2)(a)-(d), lessons from testing/incidents/reviews are incorporated into the risk assessment process, senior ICT staff report to the management body at least yearly, and mandatory ICT security awareness/resilience training exists for all staff
Training complexity/frequency and technological-monitoring cadence are entity-specific — draft placeholders pending compliance-expert definition.
Last verified against primary law 23 Jul 2026
DORA-014 · Regulation (EU) 2022/2554 — digital operational resilience, Article 14
Communication
As part of the ICT risk management framework, maintain crisis communication plans enabling responsible disclosure of at least major ICT-related incidents or vulnerabilities to clients, counterparts and, as appropriate, the public. Implement communication policies for internal staff and external stakeholders, differentiating between staff involved in ICT risk management/response-recovery and staff who need to be informed. Designate at least one person responsible for implementing the ICT-incident communication strategy and fulfilling the public/media function.
Applicable now
DORA-014 · Regulation (EU) 2022/2554 — digital operational resilience, Article 14
Communication
As part of the ICT risk management framework, maintain crisis communication plans enabling responsible disclosure of at least major ICT-related incidents or vulnerabilities to clients, counterparts and, as appropriate, the public. Implement communication policies for internal staff and external stakeholders, differentiating between staff involved in ICT risk management/response-recovery and staff who need to be informed. Designate at least one person responsible for implementing the ICT-incident communication strategy and fulfilling the public/media function.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- Medium
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1293-1299
How this is verified
Crisis communication plans exist covering client/counterpart/public disclosure of major incidents/vulnerabilities, internal/external communication policies differentiate staff roles, and a designated person owns the incident communication/media function
None beyond the primary text's own explicit requirements — this is one of the more concretely specified obligations.
Last verified against primary law 23 Jul 2026
DORA-019 · Regulation (EU) 2022/2554 — digital operational resilience, Article 19
Major ICT-related incident reporting
Report major ICT-related incidents to the relevant competent authority using the required templates and timelines.
Applicable now
DORA-019 · Regulation (EU) 2022/2554 — digital operational resilience, Article 19
Major ICT-related incident reporting
Report major ICT-related incidents to the relevant competent authority using the required templates and timelines.
- Applies to
- Financial entities in scope of DORA
- Severity if failed
- Critical
- Applies from
- 17 Jan 2025
- Source
- DORA.txt:1501
How this is verified
Initial notification within 4h of major-incident classification (and ≤24h from awareness), intermediate report within 72h, final report within 1 month
Mirrors the Incident Notification Commitments table above — the 4-hour clock is defined in Delegated Regulation (EU) 2025/301, not Article 19 itself. Major-incident classification thresholds are set elsewhere in DORA and aren't decomposed here yet.
Last verified against primary law 23 Jul 2026