Efficient Capture, Analysis, and Reporting of ICT Incidents According to DORA Requirements

DORA Incident Reporting: Meet Notification Deadlines

DORA mandates reporting of major ICT-related incidents within strict timelines: initial notification within 4 hours of classification, intermediate report within 72 hours, and a final report within one month.

  • 01Timely fulfillment of DORA reporting obligations
  • 02Systematic capture and classification of ICT incidents
  • 03Clear responsibilities and workflows for efficient incident management
  • 04Continuous improvement through structured analysis and lessons learned
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA Incident Reporting: Deadlines, Thresholds and Processes

Since January 2025, DORA incident reporting obligations apply to all financial entities. Major ICT-related incidents must be classified against defined thresholds and reported to competent authorities within strict deadlines: initial notification within 4 hours of classification, an intermediate report within 72 hours, and a final report within one month. Our automated reporting system monitors deadlines, generates authority-compliant reports, and maintains a complete audit trail.

Our DORA Incident Reporting System includes all necessary components for effective capture, analysis, and reporting of ICT incidents according to DORA requirements. We support you in implementing a customized solution that considers your specific business requirements.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DORA Incident Classification Framework

Development of a structured framework for classifying and assessing ICT incidents according to DORA requirements.

  • Definition of thresholds and criteria for reportable incidents
  • Development of assessment matrices for evaluating incident severity
  • Implementation of a multi-level classification system
  • Integration with enterprise-wide risk management
02

Incident Reporting Workflow Design

Design of efficient workflows for timely detection, escalation, and reporting of ICT incidents.

  • Development of clear escalation paths and responsibilities
  • Definition of service level agreements for response times
  • Creation of standardized reporting forms and templates
  • Integration with existing IT service management processes

5 phases

Our Approach

We support you in developing and implementing a customized incident reporting system that meets DORA requirements while being optimally integrated into your existing processes.

  1. Analysis of existing incident management processes and gap analysis to DORA requirements

  2. Definition of reporting criteria, thresholds, and classification schemes

  3. Development of a structured incident reporting process with clear responsibilities

  4. Implementation of technical solutions to support the reporting process

  5. Training of relevant employees and conducting exercises for validation

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Implementing a DORA-compliant incident reporting system is a complex undertaking that requires both technical and organizational expertise. Our team supports financial institutions in designing this process efficiently while creating value for overall risk management.

Our Strengths

  • 01Deep expertise in regulatory requirements and reporting obligations
  • 02Proven methodology for implementing efficient incident management processes
  • 03Comprehensive experience in integrating reporting solutions into existing IT landscapes
  • 04Comprehensive approach considering technical, procedural, and organizational aspects

Expert Tip

An effective incident reporting system goes beyond pure compliance. It enables valuable insights into operational risks and promotes continuous improvement of your organization's digital resilience.

6 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA Incident Reporting System

What deadlines apply for reporting ICT incidents under DORA?

Incidents classified as major are subject to a staged reporting obligation: an initial notification within a few hours of detection, an intermediate report with an updated assessment, and a final report after the analysis is complete. Exact deadlines are set out in the regulatory technical standards and should be checked there in detail, since they can differ from other reporting obligations.

How is a "major" ICT incident defined under DORA?

Classification follows defined thresholds, such as number of customers affected, duration of disruption, economic impact, or geographic spread. These criteria are detailed in the regulatory technical standards; an incident below those thresholds isn't subject to DORA's reporting obligation but should still be documented internally.

What content must an initial incident notification include?

The initial notification typically includes the time of detection, an early assessment of affected systems and customers, and immediate measures already taken. Since it's prepared under time pressure, it's normal for it not to include every detail yet; that's what the subsequent intermediate and final reports are for.

How do initial, intermediate, and final reports differ?

The initial notification informs the supervisor as quickly as possible that an incident has occurred, the intermediate report provides an updated picture as the situation becomes clearer, and the final report documents the complete root cause analysis and measures taken. Each stage has its own content requirements and deadline.

What systems support timely incident reporting?

Useful systems automatically convert incident data from monitoring tools into a reportable format and track the status of each reporting stage, rather than requiring every report to be assembled manually from scratch. When selecting one, it's worth checking whether it directly supports the specific reporting formats of the relevant supervisory authority.

Who exactly is an ICT incident reported to?

Reports go to the relevant national supervisory authority, in Germany typically BaFin, potentially supplemented by sector-specific reporting channels. For companies operating across borders, reporting obligations can apply in several member states simultaneously; this should be clarified in advance with the respective national authorities rather than discovered during an actual incident.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance