Does Digital Operational Resilience Act (DORA) require Incident Reporting?

European Union • enforcing

Yes — 1 provision

Requirements at a glance

This regulation imposes 4 specific requirements for Incident Reporting across 1 provision:

ICT Incident Reporting #

Obligation:
Incident Reporting
enforcing
Effective:
Jan 17, 2025
Risk tier:
all
Scope:
providers, deployers

Requirements

RequirementDetails
Classify incidentsClassify ICT-related incidents using ESA criteria
Major incident reportingNotify competent authorities of major ICT incidents
Reporting thresholds>24 hours duration, >2 hours critical service disruption, ≥2 EU states affected, or >EUR 100,000 economic impact
Voluntary threat reportingEncouraged to report significant cyber threats

Penalties

ViolationFine
Non-complianceDetermined by national competent authorities per member state law
View full regulation View obligation Obligation matrix