DORA Art. 19: major ICT-related incident reporting

Report major ICT-related incidents: initial notification within 4 hours of classification as major and no later than 24 hours from awareness (within 4 hours of a classification made after those 24 hours), intermediate report within 72 hours of the initial notification, final report within one month of the latest intermediate report

From clause to evidenceThe chain from DORA Art. 19 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseDORAArt. 19Duty holderFinancialentitiesApplies from2025-01-17In forceArtefactClassificationrecord…LayerLayer 05Assurance &ContinuousComplianceEvidence recordEvidence recordv1Same topic elsewhere: no crosswalk topic files this clause yetAs of 2026-09-24 · illustrative, not a claim of conformity From clause to evidenceThe chain from DORA Art. 19 to its evidence record, in 6 steps; the text alternative lists them and the facts under the figure state each in full.ClauseDORA · Art. 19Duty holderFinancial entitiesApplies from2025-01-17 · In forceArtefactClassification record…LayerLayer 05Assurance & Continuous ComplianceEvidence recordEvidence record v1Same topic elsewhere: no crosswalk topicfiles this clause yetAs of 2026-09-24illustrative, not a claim of conformity
From clause to evidence Build the artefact, then file every output it produces as a record that names AIGE-OBL-DORA-ART19. Drawn from chapter 08.
Text alternative
  • Clause: DORA, Art. 19.
  • Duty holder: Financial entities.
  • Applies from: 2025-01-17, In force.
  • Artefact: Classification record….
  • Layer: Layer 05 Assurance & Continuous Compliance.
  • Evidence record: Evidence record v1.
  • Record schema: Evidence record.
  • No crosswalk topic files this clause yet.
Id
AIGE-OBL-DORA-ART19
Instrument
Digital Operational Resilience Act (EU) 2022/2554 law
Clause
Art. 19
In scope
Financial entities
Authority
Financial competent authority
Applies from
In force · time limits in Delegated Regulation (EU) 2025/301

The artefact that evidences it

Classification record with a timestamp; per-regime clock; consistent cause coding for recurring-incident aggregation.

Patterns that build it

No pattern in the catalogue names this clause on its "Maps to" line yet; the artefact above is the engineering answer.

Source

Chapter 08, section Cyber-security and incident-reporting law, checked against its sources on the review date above.

Machine-readable

Cite this obligation

García Aibar, J. (2026). DORA Art. 19: major ICT-related incident reporting (AIGE-OBL-DORA-ART19). In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0). https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/obligations/aige-obl-dora-art19. CC BY 4.0

BibTeX

@misc{aige2026obligation,
  author       = {Jorge García Aibar},
  title        = {{DORA Art. 19: major ICT-related incident reporting (AIGE-OBL-DORA-ART19)}},
  howpublished = {In AI Governance Engineering: The Thesis \& Body of Knowledge},
  year         = {2026},
  version      = {0.5.0},
  doi          = {10.5281/zenodo.22956197},
  url          = {https://aigovernanceengineer.com/obligations/aige-obl-dora-art19},
  note         = {Version 0.5.0}
}