DORA Reporting Deadlines 2026: What Every Financial Entity Must Know
Direct answer: under DORA Regulation (EU) 2022/2554, fully applicable since 17 January 2025, financial entities must report major ICT incidents to their competent authority within 4 hours of classification, submit an intermediate report within 72 hours, and deliver a final root-cause report within one month. Missing any of these deadlines exposes your organisation to supervisory sanctions. This guide sets out every deadline, the required content at each stage, and what the obligations mean in operational terms.
Definition
Major ICT Incident under DORA: an ICT-related incident that has a significant impact on the network and information systems supporting critical or important functions of a financial entity (Art. 3(8), DORA Regulation (EU) 2022/2554). Classification thresholds are specified in the incident classification RTS (Commission Delegated Regulation (EU) 2024/1772).
71%
reduction in incident classification time for financial entities using IgeraRegTech, compared to manual classification processes — IgeraSolutions internal data, 2026.
Key dates — DORA in force
- 17 January 2025 — DORA fully applicable across all EU Member States
- No transitional period for in-scope entities
- RTS/ITS from EBA, ESMA and EIOPA published January 2025 and directly applicable
What Are DORA’s Reporting Deadlines?
Under DORA Regulation (EU) 2022/2554, financial entities subject to the Act must follow a three-stage major ICT incident notification process once an incident has been formally classified. The clock starts at the moment of classification — not at the moment of discovery or initial detection.
- Initial notification (4 hours): an early warning to the competent authority confirming the incident has been classified as major, whether there is a suspected malicious or illegal cause, and whether it may have cross-border impact.
- Intermediate report (72 hours): an updated submission with a preliminary root-cause assessment, current operational status, severity estimate, indicators of compromise (IoCs) where available, and any cross-border dimensions already identified.
- Final report (1 month): a comprehensive post-incident report including the confirmed root cause, actual financial and operational impact, corrective measures implemented and planned, and lessons learnt.
| Stage | Deadline | Required content | Recipient |
|---|---|---|---|
| Initial notification | 4 hours from classification | Incident reference, classification trigger, suspected malicious cause, potential cross-border impact | Competent national authority |
| Intermediate report | 72 hours from classification | Preliminary root-cause, severity, IoCs, operational status, cross-border impact updated | Competent national authority |
| Final report | 1 month from classification | Confirmed root cause, full impact assessment, corrective measures, lessons learnt | Competent national authority |
What Counts as a “Major” ICT Incident Under DORA?
Not every system disruption triggers DORA’s reporting obligations. An ICT incident is classified as “major” under Commission Delegated Regulation (EU) 2024/1772 when it meets specified thresholds across a combination of the following criteria:
- Number of clients affected: a significant proportion of the entity’s retail or institutional clients unable to access critical services.
- Duration: the incident lasts beyond defined minimum time thresholds for critical services.
- Geographical spread: impact across multiple Member States or critical cross-border financial infrastructure.
- Data loss: loss of data integrity, availability or confidentiality that materially affects critical functions.
- Reputational impact: significant media coverage or regulatory attention resulting from the incident.
- Economic impact: direct financial losses exceeding prescribed thresholds relative to the entity’s total annual operating costs.
Entities must apply the classification criteria at the point of detecting an incident — which requires trained staff and documented classification procedures in place before any incident occurs. This is precisely where many organisations struggle under time pressure.
5-Step DORA Incident Reporting Process
- 1 Detect & log the incident — your ICT team raises a formal incident record with timestamp, affected systems, and initial severity assessment.
- 2 Classify the incident — apply the RTS classification criteria. If “major,” the 4-hour clock starts immediately from this moment of formal classification.
- 3 Submit initial notification (T+4h) — file with your competent authority (Banco de España, CNMV, FCA, etc.) via the prescribed reporting channel. Include incident reference and suspected cause.
- 4 Submit intermediate report (T+72h) — updated analysis including preliminary root cause, IoCs, and revised impact assessment. Containment measures already taken must be documented.
- 5 Submit final report (T+1 month) — comprehensive post-incident review with confirmed root cause, total impact, remediation actions completed and planned, and process improvements to prevent recurrence.
Who Must Comply with DORA Incident Reporting?
DORA Regulation (EU) 2022/2554 applies to a broad set of financial entities defined in Article 2. The following entity types are in scope for the full incident reporting regime, including the 4h/72h/1-month timeline:
- Credit institutions (banks and building societies)
- Investment firms subject to MiFID II
- Payment institutions and e-money institutions
- Insurance and reinsurance undertakings (Solvency II)
- UCITS management companies and AIFMs
- Crypto-asset service providers (CASPs) under MiCA
- Central counterparties (CCPs) and trade repositories
- Data reporting service providers and crowdfunding platforms
Microenterprises (fewer than 10 staff and annual turnover below €2 million) benefit from a simplified regime under Article 16 and are subject to lighter incident reporting requirements. However, the classification obligations still apply in full.
Manual Process vs IgeraRegTech: Incident Reporting Comparison
The operational challenge of DORA incident reporting is not primarily legal — it is operational. Organisations that rely on manual classification and report drafting consistently struggle to meet the 4-hour window. Here is how IgeraRegTech changes that reality.
| Criterion | Manual Process | IgeraRegTech |
|---|---|---|
| Incident classification | 30–120 min (manual RTS cross-reference) | <3 min (automated RTS criteria check) |
| Report drafting (initial) | 60–180 min per report | Pre-filled template in minutes |
| Audit trail | Manual email chains, inconsistent records | Automatic timestamped audit log |
| Deadline tracking | Manual calendar entries, human error risk | Automated deadline alerts at T+3h, T+70h, T+27d |
| Regulatory source citation | Legal team consultation required | Exact DORA article cited in every answer |
Case Study — Northern European bank, 2025
A mid-size Nordic bank with €4.2 billion in assets experienced a core banking outage affecting online payments for 3.5 hours in Q1 2025. Under DORA, the incident was immediately classified as major.
Before deploying IgeraRegTech, the bank’s compliance team spent 94 minutes deciding whether the incident crossed the classification thresholds, then a further 2 hours drafting the initial notification — submitting it 3 hours and 51 minutes after classification, just minutes before the 4-hour deadline.
After deploying IgeraRegTech’s DORA incident module, the same process took 18 minutes total. Classification was confirmed automatically by the system, the pre-filled initial notification template was reviewed and submitted in under 15 minutes. The compliance team described the change as “the difference between structured process and organised panic.”
IgeraRegTech — Live demo
You: What is the deadline to report a major ICT incident to the regulator?
IgeraRegTech: Under Article 19(4) of DORA Regulation (EU) 2022/2554, financial entities must submit an initial notification to their competent authority within 4 hours of classifying an incident as major. This is followed by an intermediate report within 72 hours (Art. 19(4)(b)) and a final report within 1 month (Art. 19(4)(c)).
Source: Art. 19(4), DORA Reg. (EU) 2022/2554 — Commission Delegated Regulation (EU) 2024/1772 (incident classification RTS)
If your compliance team is still relying on manual classification and templated emails to meet DORA’s 4-hour window, the operational risk is significant. IgeraRegTech automates incident classification against the DORA RTS criteria in under three minutes, generates pre-filled notification templates, and maintains a timestamped audit trail — removing the manual bottleneck precisely when time pressure is greatest.
Struggling with DORA incident classification?
IgeraRegTech automates it — classification in <3 minutes, pre-filled reports, automated deadline alerts. Built for financial entities operating under DORA in 2025 and beyond.
Explore IgeraRegTech →Key points
- DORA has been fully applicable since 17 January 2025 — the 4h/72h/1-month timeline is a live obligation, not a future requirement.
- The 4-hour clock starts at formal classification, not at detection — so your classification procedures must be pre-trained and documented.
- IgeraRegTech reduces classification time by 71% and generates pre-filled DORA notification templates, giving compliance teams time to review rather than draft under crisis conditions.
Frequently Asked Questions
When did DORA reporting obligations come into force?
DORA Regulation (EU) 2022/2554 became fully applicable on 17 January 2025. There was no transitional period for in-scope entities. The incident reporting obligations — including the 4-hour initial notification — have been enforceable since that date. The accompanying regulatory technical standards (RTS) from EBA, ESMA and EIOPA were published in January 2025 and are directly applicable.
What happens if a financial entity misses a DORA reporting deadline?
DORA Article 50 requires Member States to empower competent authorities to impose administrative penalties and remedial measures for non-compliance. Penalties vary by jurisdiction, but national regulators such as Banco de España, the CNMV and the FCA all have broad sanctioning powers. Beyond financial penalties, a missed notification deadline can trigger enhanced supervisory scrutiny, mandatory audits, and reputational consequences in regulated markets.
Do I need to report minor ICT incidents under DORA?
No. DORA’s three-stage reporting timeline applies only to incidents classified as “major” under the criteria in Commission Delegated Regulation (EU) 2024/1772. However, financial entities must maintain an internal log of all ICT incidents — including minor ones — as part of their ICT incident management framework under Article 17. Competent authorities may request this internal log at any time.
Which authority do I report DORA incidents to in Spain or the UK?
In Spain, the relevant authority depends on entity type: credit institutions report to Banco de España, investment firms to the CNMV, and insurers to the DGSFP. All use or are implementing a common reporting platform (AGORA). In the United Kingdom, DORA does not apply directly post-Brexit, but the FCA has introduced its own operational resilience rules under PS21/3 and PS21/6 which impose similar incident notification expectations. Financial entities operating across both jurisdictions should maintain separate notification workflows.
What information must be included in the initial 4-hour DORA report?
The initial notification under Article 19(4)(a) of DORA must include: the incident reference number; the date and time of classification; an initial description of the affected systems and functions; whether there is a suspected malicious or illegal cause (such as a cyberattack); and whether the incident has or is likely to have cross-border impact on other Member States or financial entities. The format follows the ITS published by EBA/ESMA/EIOPA in January 2025.
How can IgeraRegTech help with DORA incident reporting?
IgeraRegTech is a RAG-powered compliance assistant trained on DORA Regulation (EU) 2022/2554, all published RTS/ITS, and EBA/ESMA/EIOPA Q&As. It automates incident classification against the RTS criteria, generates pre-filled notification templates for each of the three reporting stages, tracks deadlines with automated alerts, and maintains a full audit trail. Financial entities using IgeraRegTech have reduced classification time by 71% compared to manual processes. You can explore IgeraRegTech at igerasolutions.com/igeraregtech.
What to do now
DORA’s 4-hour reporting window leaves no room for teams that are designing their classification process during a crisis. The practical steps that separate compliant organisations from those facing supervisory action are straightforward:
- Document your classification procedure now — define which team member triggers the formal classification, what system records the timestamp, and who is authorised to submit the initial notification.
- Run a classification drill — simulate a core banking outage or ransomware incident and time how long your team takes to formally classify it and draft the initial notification. Most organisations discover they are already over four hours in this exercise.
- Evaluate automated tools before the next incident — IgeraRegTech’s DORA module classifies incidents against the RTS criteria automatically and generates pre-filled report templates. Deploying it before an incident is straightforward; deploying it during one is not.
The regulator’s expectation is clear: a compliant financial entity should be able to submit a well-structured initial notification within four hours of classification, every time, regardless of which team member is on duty. Operationalise that expectation now, not after the first missed deadline.
Last updated: June 2026 | Author: Gerard Maymó, CEO IgeraSolutions | Sources: DORA Regulation (EU) 2022/2554 · Commission Delegated Regulation (EU) 2024/1772 (incident classification RTS) · EBA/ESMA/EIOPA Joint Guidelines on ICT Incident Classification · ITS on ICT-related incident reporting (EBA/ITS/2023/01)