What Art. 19 DORA requires
Art. 19(1) DORA requires financial entities to report major ICT-related incidents to the competent authority designated under Art. 46. This is not optional good practice but a statutory duty with a fixed structure: an initial report, intermediate reports where necessary, and a final report (Art. 19(4)). Significant credit institutions follow a special reporting route via the national authority designated under Art. 4 of Directive 2013/36/EU, which forwards the report to the ECB without delay.
Important in practice: the reporting duty does not only kick in once the final assessment of the incident is complete. Under Art. 19(1), fourth subparagraph, financial entities submit the reports “after collating and analysing all relevant information” – so the clock starts running as soon as enough information is available to assess significance and possible cross-border effects. Waiting until the incident is fully clarified means reporting too late.
The reporting process: initial, intermediate, final
Art. 19(4) distinguishes three reporting stages:
- Initial report (point (a)): submitted as soon as the incident is classified as major.
- Intermediate report (point (b)): follows when the status of the incident changes significantly or the handling changes based on new information – also at the explicit request of the competent authority.
- Final report (point (c)): submitted once the root cause analysis is complete, regardless of whether mitigation measures have already been implemented, and the actual impact figures are available.
For the specific deadlines, Art. 19(1) refers to the template to be laid down under Art. 20; reports must contain “all information” the authority needs for its assessment. In practice this means you need a form or template you can complete quickly in an emergency – not one you start developing once the incident is already under way.
Whether an incident even qualifies as “major” ties back to the process described in Art. 17: this requires procedures to detect, manage, log, categorise and classify ICT-related incidents according to their priority, severity and the criticality of the services affected (Art. 17(3)(b), referencing the criteria under Art. 18(1)). Without this upstream classification process, you may not even know whether or when the reporting duty under Art. 19 is triggered at all.
Informing clients of financial impact
In addition to notifying the authority, Art. 19(3) requires informing clients without undue delay where a major ICT-related incident has an impact on their financial interests. Clients must be informed of the incident itself and of the measures taken to mitigate the adverse effects. For significant cyber threats – which under Art. 19(2) may only be reported to the authority on a voluntary basis – a lighter duty applies towards potentially affected clients: they must be informed of appropriate protection measures “where applicable”.
This dual track – authority on one side, client on the other – is often organised separately in practice, without the two reporting channels being synchronised in timing or content. As a result, clients are sometimes informed earlier and sometimes later than the supervisor, which can create inconsistencies if questions arise.
Common gaps in practice
Three patterns crop up regularly:
-
Missing template. Art. 19(1), third subparagraph, requires use of the template under Art. 20 for initial and follow-up reports. If it is not prepared in advance, valuable time is lost on substantive work during an actual incident, even though a substitute report “by other means” is provided for where technical submission is not possible.
-
Unclear responsibility. For financial entities supervised by more than one national authority, Art. 19(1), second subparagraph, requires a single competent authority to be designated. Without this internal clarity, duplicate or contradictory reports are a real risk.
-
Outsourcing without transfer of responsibility. Art. 19(5) allows the reporting duties to be outsourced to a third-party provider – but responsibility for meeting the requirements remains fully with the financial entity. Anyone who fully “delegates away” the reporting duty misunderstands this principle.
Where to start
Whether your organisation fully meets the requirements of Art. 19 – from classification through the reporting template to client information – is best checked in a structured way. The free risk check at /einstufung gives you an initial view of where gaps may exist in your reporting process.