RoutineMetric

EU DORA Major ICT Incident Classifier

Classify ICT-related incidents under the EU Digital Operational Resilience Act (DORA) (Regulation EU 2022/2554) and Commission Delegated Regulation (EU) 2024/1772, and calculate strict Article 19 reporting deadlines.

Load Demo Scenarios:

1. Entity & Timeline Context

Used to calculate the 1% Tier 1 Capital threshold for Economic Impact.
Direct and indirect costs to evaluate the Economic Impact criterion.

2. Criticality & Incident Nature

DORA defines critical or important functions as those whose disruption would materially impair financial performance or regulatory compliance.

Automatic Major Rule: Successful malicious network access with potential data loss automatically triggers "Major Incident" status under DORA.

3. Materiality Criteria (DORA Article 18)

Assess the 6 regulatory criteria under Commission Delegated Regulation (EU) 2024/1772. The incident is classified as Major if at least **two** of these are checked.

Criterion 1: Clients, Financial Counterparts & Transactions

Criterion 2: Duration & Service Downtime

Criterion 3: Critical Data Loss

Criterion 4: Economic Impact

Criterion 5: Geographical Spread

Criterion 6: Reputational Impact

Live Incident StatusMINOR

Classification Basis
Incident affects a critical/important function but meets 0 of the 6 materiality criteria. Classed as a minor incident; standard internal log retention applies.
DORA Materiality Criteria Met0 of 6
Requires 2 or more criteria to be met for MAJOR classification under Article 18.

Standard Internal Log Only

This incident does not meet the major or significant thresholds under the current DORA regulatory standards. No mandatory supervisory notification is triggered.

Recommended action: Standard internal logging, root-cause review, and close out standard tickets.
Generates an audit-ready written memo suitable for CISO and regulatory filing.
Advertisement
Bottom Banner Ad (728x90)

Deep Dive: Understanding EU DORA Major ICT Incident Classification

The Digital Operational Resilience Act (DORA) (Regulation EU 2022/2554) represents a landmark shift in how European financial institutions must prepare for, manage, and report security events. Effective from 17 January 2025, DORA introduces a highly unified, rigorous incident reporting regime (Article 19) to ensure that national supervisory authorities (and ultimately the European Supervisory Authorities - ESAs) can track systemic financial sector risks in real time.

The Two-Step Classification Methodology

Under Commission Delegated Regulation (EU) 2024/1772, incident response managers must follow a strict, sequential two-step process to decide if a registered security incident rises to the level of a "Major Incident":

  1. The Criticality Gate (Step 1): First, assess if the incident directly affects ICT services supporting critical or important functions of the organization. If the impacted systems only support non-critical back-office administrative tasks, the incident cannot be classified as a DORA Major Incident, regardless of its duration or technical severity.
  2. The Materiality Evaluation (Step 2): If the Criticality Gate is passed, the incident must be classified as major if either:
    • It is a successful, malicious cyber-attack with data loss potential (Automatic Major rule).
    • Or, it triggers at least two or more of the six primary quantitative and qualitative criteria.

The Six Materiality Criteria Explained

The regulatory technical standards outline six specific domains that constitute materiality thresholds:

1. Clients & Transactions

Triggers if affected clients exceed 10% of total active clients of that service, or 100,000 clients in absolute terms. It also covers incidents affecting more than 30% of counterparts or having direct daily transactional values exceeding €15,000,000 or 10% of regular daily volume.

2. Duration & Downtime

Downtime is defined as the interval where the service is unavailable. If critical function services remain offline for over 2 hours, or if the overall incident duration (from detection to fully-verified service restoration) exceeds 24 hours, this criterion is met.

3. Data Loss

Triggers if there is an adverse impact on data availability, integrity, confidentiality, or authenticity, and that breach materially hinders the institution's key business operations, customer trust, or legal compliance duties.

4. Economic Impact

Direct and indirect costs must be assessed. This includes remediation, legal fees, contract penalties, and lost revenues. The threshold is triggered if these total costs exceed €100,000, or 1% of the company's Tier 1 Capital (whichever is lower).

5. Geographical Spread

Because cross-border financial resilience is critical to the Eurozone, any incident that extends its operational impact (such as customer access outages or branch disruptions) to two or more EU Member States instantly triggers this criterion.

6. Reputational Impact

Evaluated qualitatively: Did the event lead to national or European media coverage? Have you received repeated, systemic complaints from clients? Or does the incident cause a direct breach of regulatory requirements and SLAs?

Strict Article 19 Reporting Timelines

Once an incident is classified as a major incident, the regulatory timer begins. DORA requires three distinct stages of reporting:

  • Initial Notification (Stage 1): Must be submitted within 4 hours of incident classification. (Additionally, standard guidelines specify that classification must happen without undue delay, typically within 24 hours of detection).
  • Intermediate Report (Stage 2): Must be submitted within 72 hours of the previous report. It provides updated metrics, threat attribution, and remediation steps.
  • Final Report (Stage 3): Due within 1 month from the intermediate report, providing exhaustive root-cause analysis and actual financial cost details.

Why contemporaneous compliance memos are best-practice

European regulators require firms to maintain clear documentation of why any given incident was classified as Major or Non-Major. Should a future audit reveal an incident was misclassified as minor to avoid reporting, the entity could face severe administrative fines. Keeping a signed, contemporaneous memorandum detailing the inputs and thresholds checked guarantees a reliable audit trail for compliance officers and external examiners.

Advertisement