Skip to main content
Glossary termPublished inDORA

Major ICT-related incident

What does "Major ICT-related incident" mean under DORA?

An ICT-related incident with a potential or actual high impact on the operational capability, financial services, or systems of the entity, evaluated against statutory impact criteria (e.g., clients affected, financial impact, geographical spread, duration).

Defined in / by

Last updated: 22 August 2026.

Regulations

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    Next
    Next register of information cycle, reference date expected 31 December 2026

    Checked