---
title: "Major ICT-related incident (DORA)"
description: "Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident."
canonical: https://aigovernanceengineer.com/glossary/major-ict-related-incident-dora
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# Major ICT-related incident (DORA)

Under the EU Digital Operational Resilience Act, an ICT-related incident at a financial entity that meets the classification criteria for a major incident. It is reported within 4 hours of classification and no later than 24 hours from awareness (within 4 hours of a classification made after those 24 hours), then in intermediate and final reports [1].

- Developed in: [ch. 17, The overlapping clocks](https://aigovernanceengineer.com/bok/incidents#the-overlapping-clocks)
- Chapters: [ch. 17, Incidents](https://aigovernanceengineer.com/bok/incidents)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-major-ict-related-incident-dora

## Sources

[1] Commission Delegated Regulation (EU) 2025/301 (Art. 5, time limits for major ICT-related incident reports under DORA; Art. 5(2) late classification). Publications Office of the EU (EUR-Lex). 2024-10-23. https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng (verified: primary)
