2026-01-12
Added
Financial entities supervised by the FSMA must report major ICT-related incidents using the FiMiS platform surveys DORA_INCIDENT and DORA_CYBERTHREAT. Major incidents require a three-phase submission: an initial notification within 4 hours, an intermediate report within 72 hours, and a final report within 1 month. Entities may voluntarily notify important cyber threats via the DORA_CYBERTHREAT survey, while exceptions for system outages allow reporting via a specific Excel template sent to dora@fsma.be.
Get FSMA alerts — same-day email on every new publication.
rue du Congrès 12-14 1000 Brussels / www.fsma.be Guide pratique du 12-01-26 DORA - Declaration of Major Incidents and Important Cyber Threats
Scope
Entities subject to the European DORA Regulation 1 that fall under the supervision of the FSMA, with the exception of those also subject to the supervision of the National Bank of Belgium (the latter reporting major incidents and important cyber threats to the NBB only).
Summary/Objectives
The DORA Regulation requires financial entities to report major ICT-related incidents to the FSMA. Furthermore, it allows financial entities to voluntarily notify the FSMA of important cyber threats when they consider the threat relevant to the financial system, service users, or clients. This practical guide explains how to provide this information to the FSMA.
1 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, hereinafter the 'DORA Regulation'.
Practical Guide
2/10 / Practical Guide of 12/01/2026
/ FSMA
Table of Contents
1 The declaration of major incidents and important cyber threats must be made via the FiMiS platform.................................................................................................................................... 3
1.1 Ensure you have access to these surveys.............................................................................................. 3
1.2 Exception procedure: how to declare a major incident or notify an important cyber threat to the FSMA without using FiMiS? ......................................................................................................... 3
1.3 In case of problems filling out these surveys, contact the FSMA ...................................... 3
2 How to fill out a 'DORA_INCIDENT' survey?.................................................................... 4
2.1 How does a 'DORA_INCIDENT' survey work?..................................................... 4
2.2 Create a 'DORA_INCIDENT' survey................................................................................. 4
2.3 Fill out the 'General Information regarding the Financial Entity' page..................... 5
2.4 Fill out the 'Notification' page...................................................................................... 5
2.4.1 You wish to fill out an initial notification or an intermediate report................ 6
2.4.2 You wish to adapt an initial notification or an intermediate report............... 6
2.4.3 You wish to reclassify a major incident as non-major.......................................... 6
2.4.4 Fill out each field of the page.............................................................................. 7
2.5 Submit your DORA_INCIDENT survey............................................................................ 8
3 How to fill out a 'DORA_CYBERTHREAT' survey? ............................................................ 9
3.1 Create a 'DORA_CYBERTHREAT' survey ......................................................................... 9
3.2 Submit your 'DORA_CYBERTHREAT' survey .............................................................. 9
4 FiMiS Glossary ............................................................................................................................. 10
3/10 / Practical Guide of 12/01/2026
/ FSMA
1 The declaration of major incidents and important cyber threats must be made via the FiMiS platform The DORA Regulation provides for the obligation for financial entities to declare to the FSMA major ICT-related incidents they are victims of. You also have the possibility to inform the FSMA of important cyber threats that you consider relevant to the financial system, service users, or clients. 2 The FSMA has set up two FiMiS surveys for this: “DORA_INCIDENT” and “DORA_CYBERTHREAT”. This guide explains how to fill out these surveys.
1.1 Ensure you have access to these surveys
Ensure that at least one member of your staff has the necessary access to FiMiS to fill out these surveys. Furthermore, ensure that these accesses remain up to date, particularly in the event of the departure or change of function of said member of your staff. To obtain access to the FiMiS platform, we invite you to consult the 'User guide for strong authentication'. To have access removed from FiMiS, contact dora@fsma.be.
1.2 Exception procedure: how to declare a major incident or
notify an important cyber threat to the FSMA without using FiMiS?
As an exception, if you are unable to fill out the survey, for example following an incident preventing you from accessing FiMiS, please fill out this Excel template and send it to the address dora@fsma.be. The use of this exceptional channel does not exempt you from filling out the relevant survey in FiMiS as soon as you have access again.
1.3 In case of problems filling out these surveys, contact the
FSMA
Two email addresses are available to you depending on the type of problem you encounter:
2 Article 19 of Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, hereinafter 'the DORA Regulation'. To determine whether an incident should be considered 'major', see Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing the DORA Regulation by regulatory technical standards specifying the criteria for classifying ICT-related incidents and cyber threats, setting thresholds for significant importance and specifying the details of major incident reports.
4/10 / Practical Guide of 12/01/2026
/ FSMA
2 How to fill out a 'DORA_INCIDENT' survey?
2.1 How does a 'DORA_INCIDENT' survey work?
The declaration of a major incident is done in three phases: the initial notification, the intermediate report, and the final report. You must create a new survey for each phase, as well as to modify the information you have submitted in a previous survey. If applicable, the reclassification of a major incident as non-major is possible. ⚠ The DORA Regulation sets out the timeframes within which the initial notification, the intermediate report, and the final report must be transmitted to the FSMA 3:
You classify an incident as
"major"
Once a DORA_INCIDENT survey (whether an initial notification, intermediate report, or final report) is submitted, the FSMA immediately transmits it to the European supervisory authorities and, for the relevant statuses, to the Centre for Cybersecurity Belgium (CCB). It is therefore strongly recommended to fill out each survey in the most correct and complete manner possible.
2.2 Create a 'DORA_INCIDENT' survey
After logging in to the FiMiS platform, you arrive at the FiMiS home page.
Click on 'New Survey' at the top left of the page.
You arrive at the 'New Survey' page:
3 Article 5 of Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing the DORA Regulation by regulatory technical standards specifying the content and timeframes for the initial notification of major ICT-related incidents, and for the intermediate and final reports relating thereto, and the content of the voluntary notification regarding important cyber threats.
5/10 / Practical Guide of 12/01/2026
/ FSMA
2.3 Fill out the 'General Information regarding the Financial Entity' page
The 'DORA_INCIDENT' survey consists of two pages:
2.4 Fill out the 'Notification' page
The Notification page allows you to fill out the data related to all phases of an incident. You can navigate between the phases of the same incident using this menu at the top of the page:
4 The fields to be filled out for each phase of the declaration are those set by the DORA Regulation, which they also follow in terms of numbering. See Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 defining implementing technical standards for the application of the DORA Regulation concerning forms, templates and standard procedures enabling financial entities to notify a major ICT-related incident and to notify an important cyber threat.
6/10 / Practical Guide of 12/01/2026
/ FSMA
Please note, however, that validation tests only run on the phase you have selected in field 1.1 on the previous page (General Information regarding the Financial Entity) and on any previous phases. Therefore:
a) If you have selected 'initial notification' in field 1.1 of the previous section, any data you enter in the 'Intermediate' and 'Final' phases of this survey will be saved but will not be verified by FiMiS. This data does not constitute a valid declaration of the data related to these phases, and it is not transmitted to the European supervisory authorities. b) If you have selected 'intermediate report' in field 1.1 of the previous section, any data you enter in the 'Final' phase will be saved but will not be verified by FiMiS. This data does not constitute a valid declaration of the data related to this phase, and it is not transmitted to the European supervisory authorities.
2.4.1 You wish to fill out an initial notification or an intermediate report
Start by clicking in the following menu on the declaration phase you wish to fill out:
2.4.2 You wish to adapt an initial notification or an intermediate report
As indicated above, it is not possible to modify a survey after it has been submitted. To communicate corrected information to the FSMA, you must create a new survey. By having selected the corresponding survey in the 'Previous Survey' field on the 'New Survey' page (cf. 2.2 Create a 'DORA_INCIDENT' survey supra), you will see that the data from the survey you wish to 'modify' is automatically carried over into the corresponding phase of this new survey. You can then correct the necessary information.
2.4.3 You wish to reclassify a major incident as non-major 5
You have then selected 'major incident reclassified as non-major incident' in field 1.1 on the previous page. On the Notification page, you must then justify this reclassification in field 2.10 'Other relevant information'. The FSMA will be able to assess the relevance and completeness of the reasons for the reclassification after you have submitted the survey.
5 See art. 5 of the aforementioned Commission Implementing Regulation (EU) 2025/302.
7/10 / Practical Guide of 12/01/2026
/ FSMA
2.4.4 Fill out each field of the page
If necessary, a tooltip (i) informs you of the expected response format. 6 We draw your attention to two particular formats to be used in certain fields:
a) The format to be used to enter dates and times (e.g. field 3.2 of an intermediate report) is ISO8601, namely YYYY-MM-DDThh:mm:ssZ, where:
8/10 / Practical Guide of 12/01/2026
/ FSMA
concerned. The validation report mentions the field concerned, the error detected, and how to correct it.
2.5 Submit your DORA_INCIDENT survey
When all the data entered on this page is valid, the ' Submit the Survey' button in the left-hand menu becomes accessible. Click on it to submit your survey.
It is then finalized.
9/10 / Practical Guide of 12/01/2026
/ FSMA
3 How to fill out a 'DORA_CYBERTHREAT' survey?
3.1 Create a 'DORA_CYBERTHREAT' survey
After logging in to the FiMiS platform, you arrive at the FiMiS home page.
Click on 'New Survey' at the top left of the page.
You arrive at the 'New Survey' page:
3.2 Submit your 'DORA_CYBERTHREAT' survey
When all the data entered on this page is valid, the ' Submit the Survey' button in the left-hand menu becomes accessible. Click on it to submit your survey.
It is then finalized.
10 The fields to be filled out for the notification are those set by the DORA Regulation, which they also follow in terms of numbering. See Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 defining implementing technical standards for the application of the DORA Regulation concerning forms, templates and standard procedures enabling financial entities to notify a major ICT-related incident and to notify an important cyber threat.
10/10 / Practical Guide of 12/01/2026
/ FSMA
4 FiMiS Glossary
Concept Definition
Survey Reporting form in FiMiS.
Validation Report List of any problems detected in the survey fields (missing values, poorly formatted values, etc.). This list appears at the top of the page after clicking the ' Validate & Save' button of a page of the survey. Some problems are blocking: these are 'errors'; you cannot submit the survey until they are corrected. Other problems are not blocking: these are 'warnings'; we invite you to check them before submitting the survey. File The entity or entities for which you can fill out a survey in FiMiS. Period This is the date of creation of the survey. Lifecycle Accessibility of the survey. Two values are possible:
Read the rest free
Source: Financial Services and Markets Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from FSMA
We email you every new FSMA publication the day it's published.