Commission Delegated Regulation (EU) 2024/1772
Digital Operational Resilience Act (DORA)
Objective: This RTS establishes precise criteria for classifying ICT incidents as "major" and determines the materiality thresholds that trigger the obligation to report to competent authorities.
Critical Importance: Correct incident classification is essential as it determines:
An ICT incident is considered "major" if it meets ONE OR MORE of the following criteria:
Classification thresholds by entity type:
| Financial Entity Type | Impact Threshold | Examples |
|---|---|---|
| Systemic banks (G-SIBs) | ≥ 100,000 clients | BNP Paribas, Deutsche Bank, Santander |
| Other banks | ≥ 50,000 clients | Regional banks, savings banks |
| Insurance companies (large) | ≥ 100,000 policyholders | AXA, Allianz, Generali |
| Insurance companies (SMEs) | ≥ 30,000 policyholders | Regional mutuals |
| Payment service providers | ≥ 50,000 users | PayPal, Stripe, Revolut |
| Investment firms | ≥ 20,000 clients | Brokers, asset managers |
| Crypto-asset providers | ≥ 25,000 users | Exchanges, custodial wallets |
| Microenterprises | ≥ 5,000 clients | Small fintechs, financial advisors |
⚠ IMPORTANT - Calculating affected clients:
Thresholds by function criticality:
| Criticality Level | Minimum Duration | Service Examples |
|---|---|---|
| CRITICAL functions | ≥ 2 hours cumulative over 24h |
• SEPA/SWIFT payments • Real-time trading • Automated teller machines (ATM) • Client account access |
| IMPORTANT functions | ≥ 4 hours cumulative over 24h |
• Reporting services • Banking back-office • Claims management (insurance) • Account management portals |
| Other functions | ≥ 24 hours continuous |
• Marketing services • Newsletters • Non-essential administrative functions |
Calculation method:
Classification by geographic scope:
| Extent | Definition | Classification |
|---|---|---|
| Multi-Member States | Impact in ≥ 2 EU countries | MAJOR |
| Extensive national | Impact in ≥ 3 regions of a country OR ≥ 25% of national territory | MAJOR |
| Major metropolitan area | Capital or city > 1 million inhabitants completely impacted | POTENTIALLY MAJOR |
| Regional | Single administrative region | Minor (unless other criteria) |
Special cases:
Data loss classification criteria:
| Loss Type | Major Threshold | Examples |
|---|---|---|
| Sensitive personal data | ≥ 5,000 individuals | Bank card numbers, health data, biometric data |
| Non-sensitive personal data | ≥ 50,000 individuals | Names, addresses, emails, phone numbers |
| Transactional data | ≥ 10,000 transactions | Payment histories, stock orders, insurance policies |
| Critical financial data | Any irreversible loss | Account balances, trading positions, collateral |
| Data integrity | Corruption affecting >1% of critical records | Customer database, accounting records |
⚠ ATTENTION - Types of losses:
Financial thresholds by entity size:
| Entity Category | Total Balance Sheet | Major Impact Threshold |
|---|---|---|
| Very large institutions | > €100 billion | ≥ €10 million direct losses |
| Large institutions | €30-100 billion | ≥ €5 million direct losses |
| Medium institutions | €5-30 billion | ≥ €2 million direct losses |
| Small institutions | €1-5 billion | ≥ €500,000 direct losses |
| Microenterprises | < €1 billion | ≥ €100,000 direct losses |
Calculation of direct losses:
⏰ Initial vs. final calculation:
Criticality matrix:
| Criticality Level | Criteria | Service Examples | Major Threshold |
|---|---|---|---|
| CRITICAL (Tier 1) |
• Direct customer service • Regulated/mandatory • Revenue >20% of turnover |
• Payments • Trading • Core Banking • Claims processing |
Any interruption ≥ 2h |
| IMPORTANT (Tier 2) |
• Support for critical functions • Compliance • Revenue 5-20% of turnover |
• Regulatory reporting • Risk management • Customer onboarding |
Interruption ≥ 4h |
| STANDARD (Tier 3) |
• Support functions • No direct client impact • Revenue <5% of turnover |
• HR systems • Marketing • Intranet |
Interruption ≥ 24h |
Determining criticality:
STEP 1 - Detection (T+0)
STEP 2 - Rapid Assessment (T+0 to T+2h)
STEP 3 - Preliminary Classification (T+2h to T+4h)
STEP 4 - Notification (Before T+4h)
Scenario: A regional bank suffers a ransomware attack that encrypts its production servers.
Observed impacts:
Classification:
✓ Verdict: MAJOR INCIDENT (notification within 4h mandatory)
Scenario: An insurance company discovers a data leak via a poorly secured API.
Observed impacts:
Classification:
✓ Verdict: MINOR INCIDENT (no DORA notification, but GDPR notification required)
Scenario: A cloud provider suffers a major power failure in its primary datacenter.
Observed impacts:
Classification:
✓ Verdict: MAJOR INCIDENT
⚠ Particularity: EACH client institution must notify individually (15 separate notifications)
| Criterion | Question to Ask | Data Source |
|---|---|---|
| 1. Clients | ☐ How many clients can no longer access the service? | Access logs, CRM system, application monitoring |
| 2. Duration |
☐ How long has the service been interrupted? ☐ What is the criticality of the affected service? |
Monitoring system, ticketing, log timestamps |
| 3. Geography |
☐ How many regions/countries are impacted? ☐ Which offices/datacenters are affected? |
Infrastructure mapping, service geolocation |
| 4. Data |
☐ Has there been unauthorized access to data? ☐ Is data lost or corrupted? ☐ What type of data? How many people? |
SIEM logs, DLP alerts, database audit trails |
| 5. Impact € |
☐ Estimate of incident response costs? ☐ Lost transactional revenue? ☐ Fraud or direct financial losses? |
Invoices, budget tracking, accounting data |
| 6. Criticality |
☐ Is the affected service critical or important? ☐ What is its classification in the BIA? |
Critical functions register, BIA documentation |
Correct: Classify as soon as sufficient information is available (within 4h), even if the incident is not yet resolved.
Correct: Count ALL clients who cannot access the service, whether they attempted to connect or not during the incident.
Correct: The duration starts as soon as the service is unavailable, not from detection or start of remediation.
Correct: The cause of the incident (internal/external/third-party) does NOT affect classification. Only impact matters.
Correct: If an initially minor incident exceeds a threshold in subsequent hours/days, it must be reclassified as major and notified.
Our experts can guide your institution through DORA compliance, from gap analysis to full implementation.
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.