Live Updates

ESAs publish the first report on DORA major ICT-related incidents

AI Analysis

Executive Summary

The ESAs (EBA, EIOPA and ESMA) have published their first annual report under Article 22(2) DORA, aggregating 3,383 **major ICT‑related incidents** reported by EU financial entities and highlighting that roughly one third had a cross‑border impact. This is an early supervisory “heat map” of DORA incident reporting and sends a clear signal that competent authorities will focus on cross‑border ICT risk, third‑party/outsourcing failures and the adequacy of firms’ incident classification and reporting frameworks.

What Changed

  • - The ESAs have operationalised Article 22(2) DORA by issuing the first annual overview of major ICT‑related incidents, confirming that yearly ESA‑level aggregation and analysis of incident data is now part of the standard supervisory cycle.
  • Incident reporting under DORA is now demonstrably harmonised and centralised, with major ICT‑related incidents being notified to all competent authorities involved and then aggregated by the ESAs for EU‑wide analysis.
  • The report confirms that cross‑border incidents are prevalent (around one third of major incidents), reinforcing that the “borderless and interconnected” nature of ICT risk is a key supervisory concern, especially where shared infrastructures and ser
  • System failures and external events, rather than pure cyber‑attacks, are identified as the main drivers of major incidents, placing regulatory emphasis on ICT change management, resilience of core infrastructure, and non‑cyber operational risk.
  • The ESAs highlight third‑party and outsourcing risk as a core theme, stressing the need for robust oversight of ICT service providers and close coordination with them during incident response and remediation.
  • The report notes that only about 10% of major incidents are cybersecurity‑related, but calls out the need to maintain “highest cybersecurity standards” in light of highly capable AI‑driven tools, signalling heightened expectations on AI‑related cyber

Suggested Considerations

  • Review and, where necessary, recalibrate internal incident classification criteria against the DORA definition of “ICT‑related incident” and “major ICT‑related incident”, ensuring consistency with applicable RTS on classification and materiality thresholds.
  • Validate that your firm’s incident management and escalation processes can identify, assess and classify incidents “without undue delay” and trigger major‑incident reporting within the prescribed timelines (initial, intermediate and final reports).
  • Conduct a gap analysis of cross‑border incident handling, ensuring that governance, communication and coordination arrangements adequately address incidents affecting multiple Member States or shared cross‑border infrastructures.
  • Strengthen third‑party and outsourcing risk management by mapping critical and important functions to their supporting ICT service providers, and ensuring contracts, SLAs and incident‑response clauses support DORA reporting and cooperation obligations.
  • Test and, if needed, enhance incident response runbooks to ensure close coordination with ICT service providers during incident containment, remediation and recovery, including clear roles for data provision required for regulatory reporting.
  • Implement or refine metrics and logging to capture the data points highlighted by the ESAs (e.g. number of incidents, cross‑border impact, client and transaction impact, remedial actions, and costs), so you can evidence accurate and complete reporting and answer supervisory follow‑up questions.

Key Dates

17 January 2025
– DORA (Regulation (EU) 2022/2554) applies, and financial entities become obliged to report major ICT‑related incidents to their competent authority once classification thresholds are met
Annual (from 2026 onwards) DEADLINE
– Under Article 22(2) DORA, the ESAs must issue a yearly report covering number, nature, impact, remedial actions and costs of major ICT‑related incidents; the publication in early June 2026 is the first such report and sets the expectation for future annual cycles

Compliance Impact

Non‑compliance with DORA incident management and reporting obligations can lead to supervisory findings, administrative sanctions, and heightened intrusive supervision, especially where cross‑border incidents or third‑party failures are not properly reported or managed. Given the ESAs are now publicly benchmarking the sector, firms whose reporting patterns appear inconsistent with peers face incre

Who is Affected

EU‑authorised credit institutions and investment firms within scope of Regulation (EU) 2022/2554 (DORA).EU insurance and reinsurance undertakings and intermediaries subject to DORA.EU payment service providers and electronic money institutions subject to DORA.EU central counterparties (CCPs), central securities depositories (CSDs), trading venues, trade repositories and other market infrastructures within DORA scope.EU‑authorised asset managers and investment fund managers (including AIFMs and UCITS management companies) in scope of DORA.EU‑authorised credit rating agencies, benchmark administrators and data reporting service providers subject to DORA.ICT third‑party service providers supporting critical or important functions of in‑scope financial entities, insofar as their failures drive reportable major incidents and are subject to oversight under the DORA critical‑ICT‑third‑party regime.National competent authorities (NCAs) and the ESAs themselves, which must operate the incident reporting, aggregation and supervisory follow‑up processes mandated by DORA.

AI-generated analysis. May contain errors or omissions — verify with the original ESMA source before acting. Full disclaimer.

Summary

ESAs publish the first report on DORA major ICT-related incidents 03 June 2026 Digital Finance and Innovation Joint Committee The European Supervisory Authorities (EBA, EIOPA and ESMA) today published their first annual overview of major ICT-related incidents in the EU financial sector based on a reporting mechanism established by the Digital Operational Resilience Act (DORA). It shows that ICT risks are increasingly borderless and interconnected. The authorities also note that the recent evo...

Relevant Firm Types

BankAsset ManagerInsurancePayment Provider
View Original on ESMA Back to Feed

Share this update