Law / European Union

DORA, Article 19 (reporting of major ICT-related incidents), with the time limits of Delegated Regulation (EU) 2025/301

Regulation (EU) 2022/2554, Article 19

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 17 January 2025.

A vulnerability and incident reporting rule binding private bodies.

As of 20 September 2026.

What it requires

  • This duty reaches you where you are a financial entity under Article 2(1), points (a) to (t), of Regulation (EU) 2022/2554: a credit institution, payment institution, electronic money institution, investment firm, crypto-asset service provider, central securities depository, central counterparty, trading venue, insurance or reinsurance undertaking, institution for occupational retirement provision, credit rating agency, crowdfunding service provider, or one of the Article's other listed categories. It does not reach you as an ICT third-party service provider merely because you serve one of those entities: Article 2(2) confines the term 'financial entities' to points (a) to (t), so you carry this duty only where a financial entity has outsourced its own Article 19 reporting task to you, or where your own contract for a critical or important ICT service separately obliges you to assist that financial entity when an ICT incident occurs.
  • Report a major ICT-related incident to the competent authority your sector's Union law designates under Article 46, the European Central Bank through your national supervisor if you are a credit institution classified as significant, using the templates referred to in Article 20, and submit an initial notification as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it.
  • Where classification as major comes later than that, submit the initial notification within four hours of the classification instead.
  • Submit an intermediate report within 72 hours of the initial notification, and update it without undue delay whenever the incident's status changes significantly or you recover normal activity.
  • Submit a final report no later than one month after the intermediate report, or your latest updated one, once you know the root cause and the actual impact figures.
  • If you cannot meet one of those deadlines, tell the competent authority without undue delay and before the deadline lapses, explaining why. A deadline falling on a weekend or bank holiday moves to noon of the next working day, unless you are a credit institution, a central counterparty, a trading venue operator, or an entity your Member State has designated essential or important under the NIS2 Directive, none of which get that extension for an initial notification or intermediate report.
  • Notifying a significant cyber threat under Article 19(2) is voluntary, only where you judge it relevant to the financial system, service users, or your clients. Where a major ICT-related incident affects your clients' financial interests, tell them without undue delay as soon as you become aware of it, describing the incident and the mitigation measures you took, and, for a significant cyber threat, tell a potentially affected client of protection measures it could take, where applicable.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46 (for example the entity's banking, payments, investment-firm, or insurance supervisor), or the ECB for a credit institution classified as significant under Regulation (EU) No 1024/2013, exercising the administrative penalty and remedial powers of Articles 50 and 51. A critical ICT third-party service provider is overseen separately, by the Lead Overseer under Chapter V, Section II.

Settledness

No court has construed Article 19 or Commission Delegated Regulation (EU) 2025/301, and none of it is under challenge, as of the date shown; both instruments are recent (Regulation applying from 17 January 2025, Delegated Regulation in force from 12 March 2025).

As of
20 September 2026
Guidance link
https://finance.ec.europa.eu/regulation-and-supervision/financial-services-legislation/implementing-and-delegated-acts/digital-operational-resilience-regulation_en
Guidance body
European Commission, on the basis of regulatory technical standards the European Supervisory Authorities (EBA, ESMA and EIOPA) developed through their Joint Committee under Article 20
Open questions
Where Article 5(2) of Commission Delegated Regulation (EU) 2025/301 anchors the four-hour initial notification to a classification that comes more than 24 hours after awareness, and states no outer limit on how long classification itself may take, does delaying classification itself breach the reporting duty?

What it reaches

Obligation class

Reporting, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Regulation (EU) 2022/2554 (DORA) is the financial sector's own digital operational resilience regime, and Article 19 sets its major ICT-related incident reporting duty, read here together with Commission Delegated Regulation (EU) 2025/301, which Article 20 required to specify the report content and time limits Article 19 itself leaves open.

Article 19 requires a financial entity listed in Article 2(1), points (a) to (t), such as a credit institution, payment institution, investment firm, insurance or reinsurance undertaking, or crypto-asset service provider, to report a major ICT-related incident to the competent authority designated for it under Article 46.

Article 2(1) also names ICT third-party service providers as point (u), but Article 2(2) confines the defined term financial entities to points (a) to (t), so Article 19's own reporting duty does not bind an ICT third-party service provider directly. A financial entity may instead outsource the Article 19 reporting task to a third-party service provider while remaining fully responsible for fulfilling it.

Separately, every contract for the use of ICT services must oblige the provider to assist the financial entity, at no additional cost or at a pre-agreed cost, when an ICT incident related to that service occurs, and a contract covering a critical or important function carries further terms on top of that baseline.

The duty runs through three stages under Article 19(4): an initial notification, an intermediate report once the incident's status or handling changes significantly or new information becomes available, and a final report once the root cause analysis is complete and the actual impact figures are known.

Commission Delegated Regulation (EU) 2025/301 supplies the clock Article 20 left to be specified: the initial notification is due as early as possible and in any case within four hours of classifying the incident as major, and no later than 24 hours from becoming aware of it. Where classification of an incident as major happens more than 24 hours after the financial entity became aware of it, the initial notification is instead due within four hours of that later classification.

The intermediate report is due at the latest within 72 hours of the initial notification, updated without undue delay whenever the incident's status changes or normal activity is recovered. The final report is due no later than one month after the intermediate report, or, where the entity filed an updated one, after the latest updated intermediate report.

A financial entity unable to meet one of these deadlines must tell the competent authority without undue delay and before the deadline itself lapses, explaining the reason for the delay. A deadline that falls on a weekend or a bank holiday moves to noon of the next working day.

That extension does not apply to an initial notification or an intermediate report from a credit institution, a central counterparty, a trading venue operator, or an entity identified as essential or important under the NIS2 Directive. Notifying a significant cyber threat under Article 19(2) is voluntary, made only where the financial entity itself judges the threat relevant to the financial system, service users, or clients.

Where a major ICT-related incident has an impact on the financial interests of clients, Article 19(3) requires the financial entity to inform those clients without undue delay as soon as it becomes aware of the incident, describing the incident and the mitigation measures taken. For a significant cyber threat, Article 19(3) requires the financial entity to inform a potentially affected client of protection measures it could take, where applicable.

Unlike the Cyber Resilience Act's and the NIS2 Directive's own fine tiers, DORA leaves the amount of an administrative penalty for a breach of Article 19 to each Member State's own law, requiring only that the penalty be effective, proportionate, and dissuasive. DORA applies from 17 January 2025.

Commission Delegated Regulation (EU) 2025/301, which supplies the four-hour, 24-hour, 72-hour, and one-month figures above, entered into force on 12 March 2025, 54 days after DORA's own application date, closing the gap during which Article 19's reporting duty applied without a specified clock.

When LexLint raises it

  • provides_financial_services

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2022/2554, supplemented by Commission Delegated Regulation (EU) 2025/301

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app