Skip to Primary Navigation

EU DORA RTS – ICT-related incident classification

Sets out the criteria and materiality thresholds for the classification of ICT-related, security payment-related and operational incidents at financial institutions. Ensures that the size and overall risk profile and the nature, scale and complexity of the financial entity is reflected in both threshold and criteria.

Rule Overview

Jurisdiction: European Union

Regulator: ESMA

Topic: Resilience

Overview
Notable
Latest News

Includes provisions for information sharing arrangements between competent authorities and EU level regulators.

Article 1
Clients, financial counterparts and transactions
Article 2
Reputational impact
Article 3
Duration and service downtime
Article 4
Geographical spread
Article 5
Data losses
Article 6
Criticality of services affected
Article 7
Economic impact
Article 8
Major incidents
Article 9
Major incident materiality threshold
Article 10
High materiality threshold for significant cyber threats
Article 11
Relevance of major incidents to competent authorities
Article 12
Details of major incidents to be shared with other competent authorities
Notable

Latest News

View More News