DORA
DORA Chapter III: ICT-Related Incident Management

DORA DORA-Art.19: Reporting of major ICT-related incidents

Financial entities report major ICT-related incidents to their single designated competent authority (significant credit institutions report to the national authority, which passes the report to the ECB), using the Article 20 templates, with an alternative channel where a technical problem blocks the initial notification; Member States may also require copies to NIS2 authorities or CSIRTs. Under Commission Delegated Regulation (EU) 2025/301, Article 5, the clocks are: initial notification as early as possible and within 4 hours of classifying the incident as major, but no later than 24 hours after becoming aware of it (Art. 5(1)(a)); where the incident is classified as major only after that 24-hour point, within 4 hours of classification (Art. 5(2)); intermediate report within 72 hours of submitting the initial notification even if nothing has changed, plus a further updated intermediate report promptly, and at the latest once regular activities are recovered (Art. 5(1)(b)); final report at the latest one month after the intermediate report or, where updates were filed, the latest updated intermediate report (Art. 5(1)(c)). An entity that cannot meet a deadline must tell the authority and give reasons before it expires (Art. 5(3)). A deadline falling on a weekend or bank holiday may move to noon of the next working day (Art. 5(4)), except for initial and intermediate submissions by credit institutions, central counterparties, trading venue operators and NIS2 essential or important entities (Art. 5(5)), and competent authorities may withdraw that relief from other significant or systemic entities (Art. 5(6)). Where a major incident affects the financial interests of clients, they are told without undue delay about it and the mitigation taken (Art. 19(3)). Significant cyber threats may be notified voluntarily. Reporting may be outsourced, but the entity stays responsible (Art. 19(5)).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 34 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-P33 APRA Notification of Operational Risk Incidents within 72 Hours
  • CPS230-P42 APRA Notification of Disruption Outside Tolerance within 24 Hours
  • 32 Para 32 Notify APRA within 72 hours of a material operational risk incident
  • 41 Para 41 Notify APRA within 24 hours of a disruption outside tolerance

NIS2 Directive · 4 controls

  • Art.23.1 Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients
  • Art.23.4.a Submit an early warning within 24 hours of becoming aware of a significant incident
  • Art.23.4.b Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise
  • Art.23.4.d Submit a final report within one month, and a progress report where the incident is still running
  • CFTC-SS-19 Prompt Notification to the Commission
  • CFTC-SS-32 Timely Advance Notice of Material Planned Changes

CIS Controls v8 · 2 controls

  • CIS-17.2 Establish and Maintain Contact Information for Reporting Security Incidents
  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

FedRAMP High · 2 controls

FedRAMP Moderate · 2 controls

ISO 27001:2022 · 2 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.5 Contact with authorities

ISO 27002:2022 · 2 controls

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 5.5 Contact with authorities
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-RS.CO-02 Internal and external stakeholders are notified of incidents

NIST SP 800-53 Rev 5 · 2 controls

SOC 2 · 2 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P6.6 P6.6 Notifying breaches and incidents

C5 (Germany) · 1 control

  • C5-SIM-03 Documentation and reporting of security incidents

EU AI Act · 1 control

  • PSD2-Art.96 Incident reporting to competent authority (PSD2 Article 96)

GDPR · 1 control

  • GDPR-Art.33 Notification of a personal data breach to the supervisory authority

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in DORA Chapter III: ICT-Related Incident Management

You are reading one control. How much of DORA have you already done?

DORA DORA-Art.19 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.

Query this from an agent

The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.