DORA requires firms to detect, manage and classify ICT-related incidents, and to report major ones to their competent authority within set timeframes. In Ireland, major incidents are reported via the Central Bank of Ireland Portal. The Central Bank has said it expects incident identification and reporting in place without delay.
Incident reporting is one of the areas the Central Bank has flagged for early, strict compliance — so it is worth getting the process right now.
Incident vs major incident
DORA distinguishes an ICT-related incident from a major one. Only major incidents trigger mandatory reporting. Classification is based on criteria in the technical standards.
Classification criteria
An incident is assessed against factors such as:
The number of clients or counterparties affected
The duration and service downtime
Geographic spread
Data losses (availability, integrity, confidentiality)
Economic impact
Reporting major incidents
Once an incident is classified as major, it must be reported to the competent authority within defined timeframes — typically an initial notification, an intermediate report and a final report. In Ireland, this is done through the Central Bank of Ireland Portal.
Voluntary reporting of significant cyber threats
Firms may also voluntarily report significant cyber threats, supporting sector-wide awareness.
Want your incident-management process assessed against DORA? Book a readiness assessment.