Major ICT-related incident (DORA)

Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident. It is reported within 4 hours of classification and no later than 24 hours from awareness (within 4 hours of a classification made after those 24 hours), then in intermediate and final reports 1.

Developed in
ch. 17, The overlapping clocks
Chapters
ch. 17, Incidents
Source
1 numbered reference, listed below

Where it is used

3 chapters of the Body of Knowledge use the term. Each link opens the first section that does.

Sources

  1. [1] Commission Delegated Regulation (EU) 2025/301 (Art. 5, time limits for major ICT-related incident reports under DORA; Art. 5(2) late classification). Publications Office of the EU (EUR-Lex). 2024-10-23. https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Major ICT-related incident (DORA). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/major-ict-related-incident-dora. CC BY 4.0

BibTeX

@misc{aige2026majorictrelatedincidentdora,
  author  = {Jorge García Aibar},
  title   = {{Major ICT-related incident (DORA)}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/major-ict-related-incident-dora}
}