2024-06-27

Added · Updated

DORA Update 4: Managing, Classifying, and Reporting ICT-Related Incidents

This document, part of a series on the Digital Operational Resilience Act (DORA), guides undertakings on managing, classifying, and reporting ICT-related incidents to comply with the regulation by January 17, 2025. It details requirements for establishing ICT incident management processes (DORA Article 17) and consistent classification procedures based on criteria like customer impact, data loss, and service criticality (DORA Article 18). Financial entities must report major ICT incidents to the supervisor, with specific deadlines: an initial notification within 4 hours of classification (max 24 hours after detection), an interim report within 72 hours, and a final report within one month of classification or one day after resolution. The AFM is developing an online portal for these mandatory reports and optional reports of significant cyber threats, available from January 17, 2025.

Autoriteit Financiele Markten logo

Netherlands

Autoriteit Financiele Markten

Click to view full text

More like this from AFM

We email you every new AFM publication the day it's published.

Share