The European Supervisory Authorities (EBA, EIOPA, and ESMA) have finalized the binding Regulatory Technical Standards (RTS) governing major ICT incident reporting and third-party risk management under the Digital Operational Resilience Act (Regulation EU 2022/2554 - DORA). Under the operationalized standards, financial entities across all 27 EU member states must adhere to a strict 4-hour notification SLA for major cybersecurity intrusions.

Regulatory Scope: Beyond Traditional Banking

DORA establishes a single, harmonized operational resilience rulebook applying not only to credit institutions and investment firms, but also to payment gateways, crypto-asset service providers (CASPs), alternative investment fund managers, and critical third-party ICT service providers (CTPPs) such as cloud hyperscalers and SaaS providers.

Articles 17 through 23 mandate a three-stage reporting architecture for major ICT incidents:

  1. Initial Notification: Submitted within 4 hours of the incident being classified as major, and no later than 24 hours from initial detection.
  2. Intermediate Report: Submitted within 72 hours providing updated forensic indicators, root cause hypotheses, and remediation actions.
  3. Final Report: Submitted within 1 month detailing root cause validation, definitive financial loss figures, and long-term architectural fixes.

Materiality Classification Criteria

Classification ParameterDORA Materiality Threshold (RTS Article 9)
Clients Affected> 10% of total active clients or > 100,000 retail customers
Transaction ImpactTransactions exceeding €15,000,000 or systemic payment rail disruption
Data Loss & IntegrityCompromise of cryptographic keys or confidential customer record sets
Geographic ContagionSimultaneous impact spanning two or more European Union member states

Action Plan for Financial Chief Information Security Officers

  • Automate 4-Hour Incident Triage: Integrate SIEM/SOAR automated materiality scoring to alert legal, risk, and regulatory reporting desks within minutes of alert confirmation.
  • Third-Party Cloud Contracting: Review all cloud and vendor service level agreements (SLAs) to ensure mandatory 2-hour upstream notification clauses from vendors to the financial entity.
  • TIBER-EU Penetration Testing: Schedule red-team exercises simulating advanced persistent threat (APT) attacks against payment transaction settlement cores.