This implementing regulation specifies the templates and procedures that financial entities must use to report major ICT-related incidents and notify significant cyber threats under DORA. It outlines a standardized approach for incident data collection, reporting requirements for third-party providers, and aggregated reporting options. Additionally, it addresses secure submission methods and conditions for reclassifying incidents.
Author: European Commission
Status: Adopted / Published
Adoption date: 2024-10-23
Last updated: 08 Aug 2025
Category: Relevant legislation
Subcategory: Delegated Regulation