Deep Dive: Understanding EU DORA Major ICT Incident Classification
The Digital Operational Resilience Act (DORA) (Regulation EU 2022/2554) represents a landmark shift in how European financial institutions must prepare for, manage, and report security events. Effective from 17 January 2025, DORA introduces a highly unified, rigorous incident reporting regime (Article 19) to ensure that national supervisory authorities (and ultimately the European Supervisory Authorities - ESAs) can track systemic financial sector risks in real time.
The Two-Step Classification Methodology
Under Commission Delegated Regulation (EU) 2024/1772, incident response managers must follow a strict, sequential two-step process to decide if a registered security incident rises to the level of a "Major Incident":
- The Criticality Gate (Step 1): First, assess if the incident directly affects ICT services supporting critical or important functions of the organization. If the impacted systems only support non-critical back-office administrative tasks, the incident cannot be classified as a DORA Major Incident, regardless of its duration or technical severity.
- The Materiality Evaluation (Step 2): If the Criticality Gate is passed, the incident must be classified as major if either:
- It is a successful, malicious cyber-attack with data loss potential (Automatic Major rule).
- Or, it triggers at least two or more of the six primary quantitative and qualitative criteria.
The Six Materiality Criteria Explained
The regulatory technical standards outline six specific domains that constitute materiality thresholds:
1. Clients & Transactions
Triggers if affected clients exceed 10% of total active clients of that service, or 100,000 clients in absolute terms. It also covers incidents affecting more than 30% of counterparts or having direct daily transactional values exceeding €15,000,000 or 10% of regular daily volume.
2. Duration & Downtime
Downtime is defined as the interval where the service is unavailable. If critical function services remain offline for over 2 hours, or if the overall incident duration (from detection to fully-verified service restoration) exceeds 24 hours, this criterion is met.
3. Data Loss
Triggers if there is an adverse impact on data availability, integrity, confidentiality, or authenticity, and that breach materially hinders the institution's key business operations, customer trust, or legal compliance duties.
4. Economic Impact
Direct and indirect costs must be assessed. This includes remediation, legal fees, contract penalties, and lost revenues. The threshold is triggered if these total costs exceed €100,000, or 1% of the company's Tier 1 Capital (whichever is lower).
5. Geographical Spread
Because cross-border financial resilience is critical to the Eurozone, any incident that extends its operational impact (such as customer access outages or branch disruptions) to two or more EU Member States instantly triggers this criterion.
6. Reputational Impact
Evaluated qualitatively: Did the event lead to national or European media coverage? Have you received repeated, systemic complaints from clients? Or does the incident cause a direct breach of regulatory requirements and SLAs?
Strict Article 19 Reporting Timelines
Once an incident is classified as a major incident, the regulatory timer begins. DORA requires three distinct stages of reporting:
- Initial Notification (Stage 1): Must be submitted within 4 hours of incident classification. (Additionally, standard guidelines specify that classification must happen without undue delay, typically within 24 hours of detection).
- Intermediate Report (Stage 2): Must be submitted within 72 hours of the previous report. It provides updated metrics, threat attribution, and remediation steps.
- Final Report (Stage 3): Due within 1 month from the intermediate report, providing exhaustive root-cause analysis and actual financial cost details.
Why contemporaneous compliance memos are best-practice
European regulators require firms to maintain clear documentation of why any given incident was classified as Major or Non-Major. Should a future audit reveal an incident was misclassified as minor to avoid reporting, the entity could face severe administrative fines. Keeping a signed, contemporaneous memorandum detailing the inputs and thresholds checked guarantees a reliable audit trail for compliance officers and external examiners.