DORA Technical Standards on the Classification of ICT-Related Incidents and Cyber Threats and the Materiality Thresholds for Major Incidents
Commission Delegated Regulation (EU) 2024/1772
In force since .
A vulnerability and incident reporting rule binding private bodies.
- Private right of action
- No
- Obligation class
- Reporting
As of .
What it requires
- This Regulation details the classification of incidents under Article 18 of Regulation (EU) 2022/2554, so it reaches you if you are a financial entity under Article 2(1), points (a) to (t), of that Regulation, unless Article 2(3) takes you out of the Regulation or your Member State has excluded you under Article 2(4). Use these criteria to decide whether an ICT-related incident is a major incident that you must report under Article 19(1) of that Regulation.
- Classify an ICT-related incident as major where it has affected critical services, meaning it affects ICT services or network and information systems that support your critical or important functions, affects financial services that require authorization, registration or supervision, or is a successful, malicious and unauthorized access to your network and information systems, and either the data losses threshold of Article 9(5), point (b), is met or two or more of the other materiality thresholds of Article 9(1) to (6) are met (Articles 6 and 8(1)).
- Apply these materiality thresholds: for clients, financial counterparts and transactions, more than 10 % of all clients using the affected service, more than 100,000 affected clients, more than 30 % of the financial counterparts carrying out activities related to the affected service, more than 10 % of the daily average number of transactions or of their daily average value, or the affecting of clients or financial counterparts identified as relevant; for reputational impact, any condition of Article 2(1); for duration and service downtime, a duration longer than 24 hours or a service downtime longer than 2 hours for ICT services that support critical or important functions; for geographical spread, an impact in two or more Member States; for data losses, an adverse impact on your business objectives or your ability to meet regulatory requirements, or a successful, malicious and unauthorized access that may result in data losses; and for economic impact, costs and losses that have exceeded or are likely to exceed 100,000 euro (Article 9(1) to (6)).
- Count the affected clients, financial counterparts and transactions as Article 1 requires and estimate the numbers from comparable reference periods where the actual figures cannot be determined, measure the duration and the service downtime of the incident as Article 3 requires, assess data losses against the availability, authenticity, integrity and confidentiality of data as Article 5 requires, and add up the direct and indirect costs and losses listed in Article 7(1), without accounting for financial recoveries (Articles 1, 3, 5 and 7).
- Treat recurring incidents that individually are not major as one major incident where they have occurred at least twice within 6 months, have the same apparent root cause and together fulfill Article 8(1), and assess whether recurring incidents exist on a monthly basis. This does not apply if you are a microenterprise or an entity listed in Article 16(1) of Regulation (EU) 2022/2554 (Article 8(2)).
Who enforces it
Enforcement body
The competent authority designated for each category of financial entity under Article 46 of Regulation (EU) 2022/2554, which ensures compliance with that Regulation in accordance with the powers granted by the respective legal acts.
What this law does
Commission Delegated Regulation (EU) 2024/1772 supplements Regulation (EU) 2022/2554 with regulatory technical standards that specify the criteria for the classification of ICT-related incidents and cyber threats, set out materiality thresholds and specify the details of reports of major incidents.
Article 8(1) makes an incident a major incident for the purposes of Article 19(1) of Regulation (EU) 2022/2554 where it has affected critical services as referred to in Article 6 and either the materiality threshold of Article 9(5), point (b), is met or two or more of the other materiality thresholds of Article 9(1) to (6) are met.
Article 6 treats services as critical where the incident affects ICT services or network and information systems that support critical or important functions, affects financial services that require authorization, registration or supervision, or constitutes a successful, malicious and unauthorized access to the network and information systems of the financial entity.
Article 9(1) sets the threshold for clients, financial counterparts and transactions at more than 10 % of all clients using the affected service, more than 100,000 affected clients, more than 30 % of the financial counterparts carrying out activities related to the affected service, more than 10 % of the daily average number or value of transactions of the affected service, or the affecting of clients or financial counterparts identified as relevant.
Article 9(2) treats the threshold for reputational impact as met where any of the conditions set out in Article 2, points (a) to (d), is fulfilled.
Article 2(1) treats a reputational impact as having occurred where the incident has been reflected in the media, has resulted in repetitive complaints from different clients or financial counterparts, will or is likely to leave the entity unable to meet regulatory requirements, or will or is likely to lose it clients or financial counterparts with a material impact on its business.
Article 9(3) treats the threshold for duration and service downtime as met where the duration of the incident is longer than 24 hours or the service downtime is longer than 2 hours for ICT services that support critical or important functions. Article 9(4) treats the threshold for geographical spread as met where the incident has an impact in two or more Member States.
Article 9(5) treats the threshold for data losses as met where any impact on the availability, authenticity, integrity or confidentiality of data has or will have an adverse impact on the entity's business objectives or ability to meet regulatory requirements, or where a successful, malicious and unauthorized access to network and information systems that may result in data losses occurs.
Article 9(6) treats the threshold for economic impact as met where the costs and losses incurred have exceeded or are likely to exceed 100,000 euro. Article 8(2) treats recurring incidents that individually are not major as one major incident where they have occurred at least twice within 6 months, have the same apparent root cause and collectively fulfill Article 8(1), and requires the entity to assess recurrence on a monthly basis.
Article 8(2) does not apply to microenterprises or to the financial entities listed in Article 16(1) of Regulation (EU) 2022/2554. Article 3(1) requires the duration of an incident to be measured from the moment the incident occurs until the moment when it is resolved, or from the moment it was detected where the entity cannot determine when it occurred.
Article 7(1) requires the entity, without accounting for financial recoveries, to take into account the direct and indirect costs and losses it has incurred, including expropriated funds, replacement costs, staff costs, fees for non-compliance with contractual obligations, redress and compensation to customers, forgone revenues, communication costs and advisory costs.
Article 10 treats a cyber threat as significant where it could affect critical or important functions or other financial entities, has a high probability of materialisation, and could if materialised meet the criticality criterion of Article 6 or the thresholds of Article 9(1) or Article 9(4). Article 13 provides that the Regulation enters into force on the twentieth day following that of its publication in the Official Journal of the European Union.
The penalties for a breach are those of the parent Regulation, whose Article 50(3) requires Member States to lay down effective, proportionate and dissuasive administrative penalties and remedial measures.
When LexLint raises it
When your app profile says your app provides financial services.