Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Feature Business Continuity

DORA's 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks

DORA's ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.

Table of Contents

TL;DR

  • DORA’s initial ICT incident notification must be submitted within 4 hours of classifying an incident as “major” — with an absolute ceiling of 24 hours from first awareness
  • “Major” is defined by a seven-criterion test from the delegated RTS; meeting any one criterion triggers the full three-report sequence
  • The three-stage model (initial → 72-hour intermediate → one-month final) has no equivalent in US banking rules — US banks with EU branches are running two completely different reporting regimes simultaneously
  • The ESAs’ first annual report counted 3,383 major incidents across EU financial entities in 2025; formal penalties are expected to begin H2 2026

The Clock No One in Your US Operations Team Knows Is Running

Yesterday’s piece on the SEC’s four-day clock under Item 1.05 focused on a timeline that starts at materiality determination. Here’s a regime where the timeline starts earlier, moves faster, and requires not one report but three.

If your bank has a licensed branch or subsidiary in Frankfurt, Dublin, Amsterdam, Paris, or any EU member state, DORA’s ICT incident reporting requirements applied to that entity as of January 17, 2025. The rule is Regulation (EU) 2022/2554, published December 27, 2022. Effective compliance date: eighteen months later.

Most US bank operations teams know they have a 36-hour reporting window under the OCC/FDIC/Fed joint rule for “notification incidents.” Many know that NYDFS Part 500 adds a 72-hour clock for cybersecurity events. Almost none have a playbook that accounts for the EU entity’s obligation to report to its national competent authority within 4 hours.

That gap is what national supervisors are examining right now.

What DORA Actually Covers

DORA is structured around five ICT risk management pillars: ICT risk management framework, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. For most US banks with EU operations, incident reporting (Articles 17–22) is where the compliance gap is most acute — because it requires not just a framework but an operational capability running on a very short clock.

The incident reporting obligations live in:

ArticleSubject
Art. 17ICT incident management process — detect, manage, log, classify, notify
Art. 18Classification criteria for major incidents and significant cyber threats
Art. 19Reporting obligation — the three reports and their timelines
Art. 20Harmonisation of content and templates
Art. 21Centralisation concept — single reporting hub (still being built out)
Art. 22NCA feedback obligation — supervisors must respond, not just receive

Three delegated/implementing acts fill in the mechanics: Commission Delegated Regulation (EU) 2024/1772 on classification criteria, Delegated Regulation (EU) 2025/301 on reporting timelines and content, and Implementing Regulation (EU) 2025/302 on templates and procedures.

The Classification Problem: Seven Criteria, Any One Triggers

The most operationally difficult requirement isn’t the reporting itself — it’s the classification decision that starts the clock.

Under Article 18 and the RTS in Commission Delegated Regulation (EU) 2024/1772, every ICT incident must be assessed against seven criteria. Meeting a threshold on any one of them makes the incident “major” and triggers the full three-report sequence:

CriterionThreshold Signal
Clients affected10% of total clients affected, or 50,000 clients (absolute)
Reputational impactMedia coverage, regulatory attention, client complaints above defined level
Duration and service downtimeUpgraded to primary criterion; measured from detection if start-time unknown
Geographical spreadCross-border impact within or beyond EU
Data lossesConfidentiality, integrity, or availability of data affected
Critical services affectedImpact on designated critical functions of the entity
Economic impactDirect and indirect costs and losses, before financial recoveries

The practical difficulty: you have to complete this assessment before the 4-hour clock starts. Or more precisely, the clock starts when you complete the classification. But you cannot delay classification indefinitely to buy time — the 24-hour absolute ceiling from detection means classification must happen within the first day regardless.

The ESAs’ first annual report on major ICT incidents (JC 2026/16, published June 3, 2026) documented 3,383 major incidents in calendar year 2025 — about 282 per month across EU financial entities. Of those, 29% traced to third-party ICT providers, and 1,056 had measurable cross-border impact. The February 2025 TARGET Services outage and the April 2025 Iberian Peninsula blackout were flagged as generating outsized volumes.

If you’re wondering whether incidents are being classified as major at rates that seem high — yes. The geographic spread criterion and the third-party provider criterion are wide nets.

The Three-Report Model: No US Equivalent Exists

Once an incident is classified as major, DORA requires three sequential reports. This structure has no analog in US banking regulation, where a single notification satisfies the obligation.

Initial Notification: Within 4 hours of classification as a major incident, and no later than 24 hours from first awareness. Content requirements are minimal at this stage — the NCA wants to know you know. The detailed templates in Implementing Regulation 2025/302 specify what must be included.

Intermediate Report: Within 72 hours of submitting the initial notification. This one is required even if the status of the incident hasn’t changed — even if you submitted the initial notification at 3am and nothing is different by hour 72. The intermediate report covers updated scope, containment measures taken, whether external assistance was engaged, and whether client interests have been affected.

Final Report: Within one month of either the intermediate report or full resolution of the incident, whichever comes later. The final report is where root cause analysis, lessons learned, and control remediation steps go.

Compare that to the US landscape:

RequirementDORA (EU)OCC/FDIC/Fed Joint RuleNYDFS Part 500
Initial deadline4 hrs from classification; 24 hrs from detection36 hours from determination72 hours from determination
Intermediate reportRequired within 72 hours of initialNoneNone
Final reportRequired within 1 monthNoneNone
Multi-stage modelYes (three sequential)NoNo
Effective dateJanuary 17, 2025May 1, 2022November 1, 2023 (amended)

For a US bank with a New York license and an EU branch, a single significant incident could require three separate filing obligations to three different regulators on three different timelines — the NCA within 4 hours, the OCC/FDIC/Fed within 36 hours, and NYDFS within 72 hours. These clocks run independently, use different triggers, and require different content. None of them pause for the others.

Who Is Actually In Scope: The Branch Question

DORA’s scope is defined by Article 2. The regulated entity — not the parent — is the in-scope “financial entity.” But the EBA confirmed in Q&A 2023_6876 what this means for US parent organizations: “credit institutions that are third-country branches licensed in an EU country are included in scope of the DORA Regulation.”

In plain terms:

  • A US bank’s licensed Frankfurt branch is an in-scope financial entity
  • A US bank’s EU-licensed subsidiary is an in-scope financial entity
  • A US bank that provides technology services to EU financial entities may be an in-scope ICT third-party provider — 19 Critical ICT Third-Party Providers were designated on November 18, 2025, including AWS, Microsoft Azure, Google Cloud, and IBM

The obligation runs with the EU entity, not with the US parent. But the EU entity usually doesn’t have its own incident response team — it runs on the parent’s infrastructure and the parent’s playbooks. That’s where the compliance gap lives: the playbook was written for US regulatory requirements and doesn’t have a DORA classification workflow or a 4-hour NCA notification path.

Where National Supervisors Are Focused in 2026

The Dutch DNB issued the first formal DORA supervisory letters in Q1 2026 — remediation orders, not yet fines. BaFin and the ECB materially expanded dedicated DORA examination teams through 2025 and began on-site reviews in 2026. Nordic NCAs published explicit 2026 supervisory priority lists naming third-party ICT risk and incident classification operationalization as their top DORA focus areas.

Formal financial penalties are expected to begin in the second half of 2026, targeting entities that made no demonstrable compliance effort. The penalty structure under DORA: up to 2% of global annual turnover or €10 million for entities, and up to €1 million for individual senior managers personally.

The supervisory focus areas that are generating the most follow-up in 2026 NCA examinations:

  1. Register of Information completeness — the mandatory ICT third-party contract inventory, which 46% of institutions identified as their hardest DORA requirement
  2. Incident classification process operationalization — do you have a documented seven-criterion classification workflow?
  3. Testing of ICT business continuity plans — DORA requires advanced testing, including threat-led penetration testing for systemically important entities
  4. Third-party ICT risk — subcontractor visibility — what your vendor uses, and whether you’ve mapped it

What to Add to Your Incident Response Plan

Most US bank incident response frameworks are designed around a single notification obligation with a 24-72 hour window. A DORA-compliant program needs four additions:

1. A DORA Classification Workflow
A documented seven-criterion assessment process that can run in parallel with your forensic investigation. Who runs it, what evidence is required to satisfy each criterion, and who has final authority to declare “major” or “not major.” The assessment must be documented — an undocumented classification carries the same compliance risk as a missed deadline.

2. An EU NCA Notification Tree
Separate from your US bank regulator path and your NYDFS path. The EU NCA is the competent authority in the member state where your branch or subsidiary is licensed. Contact, escalation path, and portal credentials need to exist before you need them.

3. Three-Stage Report Templates
Initial, intermediate, and final reports have different required content under Implementing Regulation 2025/302. Building templates in advance means you’re filling in facts, not designing a document structure during an incident.

4. A Designated EU Incident Notification Owner
Someone with authority to submit the initial notification at 3am on a Sunday, who understands that the 4-hour clock does not pause for business hours. For most US banks with EU branches, this is not currently a named role.

These four gaps are also exactly what an examiner’s pre-exam questionnaire will surface — they’re documented and specific. The good news is they’re concrete and buildable. The harder problem is the systemic one: the incident response process that runs on US timelines needs a parallel EU track that can move faster.

So What Does This Mean For You?

If you have an EU-licensed branch or subsidiary, DORA has applied since January 2025. The classification workflow, the NCA notification path, and the three-stage report templates should already exist. If they don’t, you have a documented gap that examiners will find.

The place to start is a gap assessment against the seven-criterion classification test and the three-report model. Map your current incident response workflow against the DORA requirements. Find where the US process and the EU process diverge — they will, on timeline, on report structure, and on the role of the NCA versus the primary federal regulator. Document both the gap and the remediation timeline.

For banks running a business continuity program that needs to absorb DORA alongside FFIEC BCM guidance, the operational resilience framing is useful: DORA is asking for demonstrated, tested capability — not just a written plan. That’s a higher bar than most US BCM programs currently hit.

The ESAs’ first annual incident report showed 3,383 major incidents in 2025. That’s 282 organizations per month discovering their incident was DORA-major. If your EU branch is running on a US playbook, that discovery will happen at the worst possible time.


The Business Continuity & Disaster Recovery Kit includes incident response frameworks built for financial services, with tabletop exercise templates and a resilience testing program you can adapt for DORA’s operational resilience testing requirements.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does DORA apply to a US bank that has an EU branch but no EU subsidiary?
Yes. The EBA confirmed in Q&A 2023_6876 that third-country branches licensed in an EU member state are included in DORA's scope. A US bank's Frankfurt branch, Dublin branch, or Amsterdam branch is individually subject to DORA's ICT incident reporting, resilience testing, and third-party risk management requirements. The obligation sits with the EU entity, not the US parent — but practically, the US parent usually needs to run the process.
What exactly triggers the 'major ICT incident' classification under DORA?
Seven criteria, assessed from Commission Delegated Regulation (EU) 2024/1772: (1) clients affected — 10% of total clients or 50,000 absolute; (2) reputational impact; (3) duration and service downtime; (4) geographical spread; (5) data losses affecting confidentiality, integrity, or availability; (6) critical services affected; and (7) economic impact in direct and indirect costs. Meeting threshold on any one criterion triggers 'major' status. You assess all seven for every incident.
How does DORA's 4-hour initial report compare to the US banking regulators' 36-hour rule?
DORA: 4 hours from classification as a major incident, with an absolute cap of 24 hours from first awareness. The US OCC/FDIC/Fed joint rule: 36 hours from determining a 'notification incident' has occurred. NYDFS Part 500: 72 hours. These clocks run on different triggers and different timelines — which means a single incident can require you to report to an EU supervisor before you're required to tell your US regulator.
What is DORA's three-report model and which institutions does it apply to?
All in-scope EU financial entities must submit three sequential reports for every major ICT incident: an initial notification (within 4 hours of classification, max 24 hours from detection); an intermediate report (within 72 hours of the initial notification, even if nothing has changed); and a final report (within one month of the intermediate report or incident resolution). This three-stage model has no equivalent in US banking regulation — US rules require a single notification with no intermediate or final reports.
What are the DORA penalties for failing to meet the incident reporting deadlines?
For financial entities: up to 2% of global annual turnover or €10 million, whichever is higher. For individual senior managers personally: up to €1 million. The Dutch DNB issued the first formal supervisory letters with remediation orders in Q1 2026. Formal financial penalties — the first in the EU — are expected to begin in the second half of 2026, targeting entities that made no demonstrable compliance effort.
What specifically needs to be added to a US incident response plan to handle DORA obligations?
Four things that most US playbooks are missing: (1) a classification workflow specifically for the DORA seven-criterion test; (2) a separate notification tree for the EU competent authority alongside your US bank regulator and NYDFS paths; (3) templates for the three-stage report structure (initial, intermediate, final) with content requirements from Implementing Regulation 2025/302; and (4) a clear owner for the EU incident notification obligation — usually someone who can reach the national competent authority on a Sunday at 2am.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.