The European Supervisory Authorities (EBA, EIOPA, and ESMA) have finalized the binding Regulatory Technical Standards (RTS) governing major ICT incident reporting and third-party risk management under the Digital Operational Resilience Act (Regulation EU 2022/2554 - DORA). Under the operationalized standards, financial entities across all 27 EU member states must adhere to a strict 4-hour notification SLA for major cybersecurity intrusions.
Regulatory Scope: Beyond Traditional Banking
DORA establishes a single, harmonized operational resilience rulebook applying not only to credit institutions and investment firms, but also to payment gateways, crypto-asset service providers (CASPs), alternative investment fund managers, and critical third-party ICT service providers (CTPPs) such as cloud hyperscalers and SaaS providers.
Articles 17 through 23 mandate a three-stage reporting architecture for major ICT incidents:
- Initial Notification: Submitted within 4 hours of the incident being classified as major, and no later than 24 hours from initial detection.
- Intermediate Report: Submitted within 72 hours providing updated forensic indicators, root cause hypotheses, and remediation actions.
- Final Report: Submitted within 1 month detailing root cause validation, definitive financial loss figures, and long-term architectural fixes.
Materiality Classification Criteria
| Classification Parameter | DORA Materiality Threshold (RTS Article 9) |
|---|---|
| Clients Affected | > 10% of total active clients or > 100,000 retail customers |
| Transaction Impact | Transactions exceeding €15,000,000 or systemic payment rail disruption |
| Data Loss & Integrity | Compromise of cryptographic keys or confidential customer record sets |
| Geographic Contagion | Simultaneous impact spanning two or more European Union member states |
Action Plan for Financial Chief Information Security Officers
- Automate 4-Hour Incident Triage: Integrate SIEM/SOAR automated materiality scoring to alert legal, risk, and regulatory reporting desks within minutes of alert confirmation.
- Third-Party Cloud Contracting: Review all cloud and vendor service level agreements (SLAs) to ensure mandatory 2-hour upstream notification clauses from vendors to the financial entity.
- TIBER-EU Penetration Testing: Schedule red-team exercises simulating advanced persistent threat (APT) attacks against payment transaction settlement cores.



