What are DORA's deadlines for the initial notification and intermediate report of a major ICT incident?
Question as asked: Under DORA, what are the deadlines for the initial notification and intermediate report of a major ICT-related incident?
Under DORA, the initial-notification and intermediate-report deadlines for a major ICT-related incident are set not in Article 19 itself but in the Level 2 act adopted under it:
-
Legal basis: Article 19(4)(a)–(b) requires the financial entity to submit an initial notification and an intermediate report "within the time limits to be laid down in accordance with Article 20, first paragraph, point (a)(ii)." The actual figures are fixed in Commission Delegated Regulation (EU) 2025/301, Article 5(1)(a)–(b).
-
Initial notification (Art. 5(1)(a)): within 4 hours of classifying the incident as major, and in any event no later than 24 hours after the entity became aware of the incident.
- Late-classification rule (Art. 5(2)): if the incident is not classified as major within 24 hours of awareness but is classified as major at a later point, the initial notification is instead due within 4 hours of that later classification.
-
Intermediate report (Art. 5(1)(b)): within 72 hours of submitting the initial notification, even if there is no material change to report; it must also be updated once regular activities have been recovered.
Other points relevant to these two clocks:
- If the entity cannot meet a deadline, it must inform the competent authority without undue delay and no later than the deadline itself, explaining why (CDR 2025/301 Art. 5(3)).
- A deadline falling on a weekend day or bank holiday in the entity's home Member State may be deferred to noon of the next working day — but this deferral does not apply to credit institutions, CCPs, trading-venue operators, or entities identified as NIS2 essential/important entities (CDR 2025/301 Art. 5(4)–(5)); competent authorities may also disapply the deferral for significant or systemically important entities (Art. 5(6)).
Note: the final report deadline is one month after the latest (updated) intermediate report (CDR 2025/301 Art. 5(1)(c)), included here for completeness since the three stages are normally read together, though only the first two were asked about.
Research aid, not legal or audit advice. This answer reflects the standard as of the date above; verify it against the official text before relying on it.
More answers
- Can we use SAQ A with a payment processor's iframe, and do we still need ASV scans? (PCI DSS v4.0.1)
- How many Annex A controls are in ISO 27001:2022, and how are they grouped? (ISO/IEC 27001:2022)
- How long do we have to answer a GDPR subject access request, and can we extend it? (GDPR)
- When do the EU AI Act's high-risk obligations apply to Annex III and Annex I systems? (EU AI Act)