Home › DORA › Incident Reporting

DORA Compliance

DORA Incident Reporting & Classification

Key takeaway

DORA requires firms to detect, manage and classify ICT-related incidents, and to report major ones to their competent authority within set timeframes. In Ireland, major incidents are reported via the Central Bank of Ireland Portal. The Central Bank has said it expects incident identification and reporting in place without delay.

Incident reporting is one of the areas the Central Bank has flagged for early, strict compliance — so it is worth getting the process right now.

Incident vs major incident

DORA distinguishes an ICT-related incident from a major one. Only major incidents trigger mandatory reporting. Classification is based on criteria in the technical standards.

Classification criteria

Flowchart showing how an ICT incident is classified as major under DORA thresholds and the three-stage reporting deadlines to the Central Bank of Ireland
From incident to major incident: the classification criteria and CBI reporting deadlines.

An incident is assessed against factors such as:

  • The number of clients or counterparties affected

  • The duration and service downtime

  • Geographic spread

  • Data losses (availability, integrity, confidentiality)

  • Economic impact

Reporting major incidents

Once an incident is classified as major, it must be reported to the competent authority within defined timeframes — typically an initial notification, an intermediate report and a final report. In Ireland, this is done through the Central Bank of Ireland Portal.

Voluntary reporting of significant cyber threats

Firms may also voluntarily report significant cyber threats, supporting sector-wide awareness.

Next step

Want your incident-management process assessed against DORA? Book a readiness assessment.