Skip to main content
Glossary termPublished inDORA

Significant cyber threat

What does "Significant cyber threat" mean under DORA?

A cyber threat that could plausibly result in a major ICT-related incident based on technical capabilities, intent of malicious actors, or system vulnerabilities.

Defined in / by

Last updated: 22 August 2026.

Regulations

  • Digital Operational Resilience Act (DORA)

    DORA is Regulation (EU) 2022/2554. It has applied since 17 January 2025 to 20 categories of licensed financial entity, from banks to crypto-asset service providers. It requires an ICT risk management framework, major incident reporting within 4 hours of classification, an annual register of ICT contracts, and threat-led penetration testing every three years.

    Next
    Next register of information cycle, reference date expected 31 December 2026

    Checked