With this tool, financial entities can easily determine if an incident is classified as major and as such
needs to be reported to the competent authorites under the Digital Operational Resilience Act (DORA). This
questionnaire is based upon the technical standard on classification of ICT-related incidents.
The reporting timelines for major incidents in DORA are:
please note that this tool does not cover recurring incidents. Recurring ICT-related incidents shall be reported as major incidents where incidents with the same apparent root cause occur at least twice within a period of six months and, when assessed collectively, meet the criteria for classification as a major incident.
For more information on how to report the incident to the competent authorities and the (mandatory) content of the different reports, refer to the respective technical standard.
|
This DORA incident classification tool has been co-developed by NOREA with RiskNow, provider of the RiskNow GRC SaaS platform that helps companies to comply with DORA. |
