A cyber threat that could plausibly result in a major ICT-related incident based on technical capabilities, intent of malicious actors, or system vulnerabilities.
Defined in / by
Last updated: 22 August 2026.
What does "Significant cyber threat" mean under DORA?
A cyber threat that could plausibly result in a major ICT-related incident based on technical capabilities, intent of malicious actors, or system vulnerabilities.
Last updated: 22 August 2026.
DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.
Checked