These Guidelines, mandated by Article 11(11) of the Digital Operational Resilience Act (DORA), aim to harmonise how financial entities estimate and report aggregated annual costs and losses from major ICT‑related incidents. They apply to non‑micro‑entities and require use of a common template, alignment with incident classification/reporting RTS, inclusion of only 'major' incidents with final reports in the reference year, and submission of gross costs and recoveries via a standard template.
Author: European Supervisory Authorities
Status: Adopted / Published
Adoption date: 2024-06‑05
Last updated: 16 Aug 2025
Category: Guidance
Subcategory: Official guidance