Feature Business Continuity
DORA's 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks
DORA's ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.
Table of Contents
TL;DR
- DORA’s initial ICT incident notification must be submitted within 4 hours of classifying an incident as “major” — with an absolute ceiling of 24 hours from first awareness
- “Major” is defined by a seven-criterion test from the delegated RTS; meeting any one criterion triggers the full three-report sequence
- The three-stage model (initial → 72-hour intermediate → one-month final) has no equivalent in US banking rules — US banks with EU branches are running two completely different reporting regimes simultaneously
- The ESAs’ first annual report counted 3,383 major incidents across EU financial entities in 2025; formal penalties are expected to begin H2 2026
The Clock No One in Your US Operations Team Knows Is Running
Yesterday’s piece on the SEC’s four-day clock under Item 1.05 focused on a timeline that starts at materiality determination. Here’s a regime where the timeline starts earlier, moves faster, and requires not one report but three.
If your bank has a licensed branch or subsidiary in Frankfurt, Dublin, Amsterdam, Paris, or any EU member state, DORA’s ICT incident reporting requirements applied to that entity as of January 17, 2025. The rule is Regulation (EU) 2022/2554, published December 27, 2022. Effective compliance date: eighteen months later.
Most US bank operations teams know they have a 36-hour reporting window under the OCC/FDIC/Fed joint rule for “notification incidents.” Many know that NYDFS Part 500 adds a 72-hour clock for cybersecurity events. Almost none have a playbook that accounts for the EU entity’s obligation to report to its national competent authority within 4 hours.
That gap is what national supervisors are examining right now.
What DORA Actually Covers
DORA is structured around five ICT risk management pillars: ICT risk management framework, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. For most US banks with EU operations, incident reporting (Articles 17–22) is where the compliance gap is most acute — because it requires not just a framework but an operational capability running on a very short clock.
The incident reporting obligations live in:
| Article | Subject |
|---|---|
| Art. 17 | ICT incident management process — detect, manage, log, classify, notify |
| Art. 18 | Classification criteria for major incidents and significant cyber threats |
| Art. 19 | Reporting obligation — the three reports and their timelines |
| Art. 20 | Harmonisation of content and templates |
| Art. 21 | Centralisation concept — single reporting hub (still being built out) |
| Art. 22 | NCA feedback obligation — supervisors must respond, not just receive |
Three delegated/implementing acts fill in the mechanics: Commission Delegated Regulation (EU) 2024/1772 on classification criteria, Delegated Regulation (EU) 2025/301 on reporting timelines and content, and Implementing Regulation (EU) 2025/302 on templates and procedures.
The Classification Problem: Seven Criteria, Any One Triggers
The most operationally difficult requirement isn’t the reporting itself — it’s the classification decision that starts the clock.
Under Article 18 and the RTS in Commission Delegated Regulation (EU) 2024/1772, every ICT incident must be assessed against seven criteria. Meeting a threshold on any one of them makes the incident “major” and triggers the full three-report sequence:
| Criterion | Threshold Signal |
|---|---|
| Clients affected | 10% of total clients affected, or 50,000 clients (absolute) |
| Reputational impact | Media coverage, regulatory attention, client complaints above defined level |
| Duration and service downtime | Upgraded to primary criterion; measured from detection if start-time unknown |
| Geographical spread | Cross-border impact within or beyond EU |
| Data losses | Confidentiality, integrity, or availability of data affected |
| Critical services affected | Impact on designated critical functions of the entity |
| Economic impact | Direct and indirect costs and losses, before financial recoveries |
The practical difficulty: you have to complete this assessment before the 4-hour clock starts. Or more precisely, the clock starts when you complete the classification. But you cannot delay classification indefinitely to buy time — the 24-hour absolute ceiling from detection means classification must happen within the first day regardless.
The ESAs’ first annual report on major ICT incidents (JC 2026/16, published June 3, 2026) documented 3,383 major incidents in calendar year 2025 — about 282 per month across EU financial entities. Of those, 29% traced to third-party ICT providers, and 1,056 had measurable cross-border impact. The February 2025 TARGET Services outage and the April 2025 Iberian Peninsula blackout were flagged as generating outsized volumes.
If you’re wondering whether incidents are being classified as major at rates that seem high — yes. The geographic spread criterion and the third-party provider criterion are wide nets.
The Three-Report Model: No US Equivalent Exists
Once an incident is classified as major, DORA requires three sequential reports. This structure has no analog in US banking regulation, where a single notification satisfies the obligation.
Initial Notification: Within 4 hours of classification as a major incident, and no later than 24 hours from first awareness. Content requirements are minimal at this stage — the NCA wants to know you know. The detailed templates in Implementing Regulation 2025/302 specify what must be included.
Intermediate Report: Within 72 hours of submitting the initial notification. This one is required even if the status of the incident hasn’t changed — even if you submitted the initial notification at 3am and nothing is different by hour 72. The intermediate report covers updated scope, containment measures taken, whether external assistance was engaged, and whether client interests have been affected.
Final Report: Within one month of either the intermediate report or full resolution of the incident, whichever comes later. The final report is where root cause analysis, lessons learned, and control remediation steps go.
Compare that to the US landscape:
| Requirement | DORA (EU) | OCC/FDIC/Fed Joint Rule | NYDFS Part 500 |
|---|---|---|---|
| Initial deadline | 4 hrs from classification; 24 hrs from detection | 36 hours from determination | 72 hours from determination |
| Intermediate report | Required within 72 hours of initial | None | None |
| Final report | Required within 1 month | None | None |
| Multi-stage model | Yes (three sequential) | No | No |
| Effective date | January 17, 2025 | May 1, 2022 | November 1, 2023 (amended) |
For a US bank with a New York license and an EU branch, a single significant incident could require three separate filing obligations to three different regulators on three different timelines — the NCA within 4 hours, the OCC/FDIC/Fed within 36 hours, and NYDFS within 72 hours. These clocks run independently, use different triggers, and require different content. None of them pause for the others.
Who Is Actually In Scope: The Branch Question
DORA’s scope is defined by Article 2. The regulated entity — not the parent — is the in-scope “financial entity.” But the EBA confirmed in Q&A 2023_6876 what this means for US parent organizations: “credit institutions that are third-country branches licensed in an EU country are included in scope of the DORA Regulation.”
In plain terms:
- A US bank’s licensed Frankfurt branch is an in-scope financial entity
- A US bank’s EU-licensed subsidiary is an in-scope financial entity
- A US bank that provides technology services to EU financial entities may be an in-scope ICT third-party provider — 19 Critical ICT Third-Party Providers were designated on November 18, 2025, including AWS, Microsoft Azure, Google Cloud, and IBM
The obligation runs with the EU entity, not with the US parent. But the EU entity usually doesn’t have its own incident response team — it runs on the parent’s infrastructure and the parent’s playbooks. That’s where the compliance gap lives: the playbook was written for US regulatory requirements and doesn’t have a DORA classification workflow or a 4-hour NCA notification path.
Where National Supervisors Are Focused in 2026
The Dutch DNB issued the first formal DORA supervisory letters in Q1 2026 — remediation orders, not yet fines. BaFin and the ECB materially expanded dedicated DORA examination teams through 2025 and began on-site reviews in 2026. Nordic NCAs published explicit 2026 supervisory priority lists naming third-party ICT risk and incident classification operationalization as their top DORA focus areas.
Formal financial penalties are expected to begin in the second half of 2026, targeting entities that made no demonstrable compliance effort. The penalty structure under DORA: up to 2% of global annual turnover or €10 million for entities, and up to €1 million for individual senior managers personally.
The supervisory focus areas that are generating the most follow-up in 2026 NCA examinations:
- Register of Information completeness — the mandatory ICT third-party contract inventory, which 46% of institutions identified as their hardest DORA requirement
- Incident classification process operationalization — do you have a documented seven-criterion classification workflow?
- Testing of ICT business continuity plans — DORA requires advanced testing, including threat-led penetration testing for systemically important entities
- Third-party ICT risk — subcontractor visibility — what your vendor uses, and whether you’ve mapped it
What to Add to Your Incident Response Plan
Most US bank incident response frameworks are designed around a single notification obligation with a 24-72 hour window. A DORA-compliant program needs four additions:
1. A DORA Classification Workflow
A documented seven-criterion assessment process that can run in parallel with your forensic investigation. Who runs it, what evidence is required to satisfy each criterion, and who has final authority to declare “major” or “not major.” The assessment must be documented — an undocumented classification carries the same compliance risk as a missed deadline.
2. An EU NCA Notification Tree
Separate from your US bank regulator path and your NYDFS path. The EU NCA is the competent authority in the member state where your branch or subsidiary is licensed. Contact, escalation path, and portal credentials need to exist before you need them.
3. Three-Stage Report Templates
Initial, intermediate, and final reports have different required content under Implementing Regulation 2025/302. Building templates in advance means you’re filling in facts, not designing a document structure during an incident.
4. A Designated EU Incident Notification Owner
Someone with authority to submit the initial notification at 3am on a Sunday, who understands that the 4-hour clock does not pause for business hours. For most US banks with EU branches, this is not currently a named role.
These four gaps are also exactly what an examiner’s pre-exam questionnaire will surface — they’re documented and specific. The good news is they’re concrete and buildable. The harder problem is the systemic one: the incident response process that runs on US timelines needs a parallel EU track that can move faster.
So What Does This Mean For You?
If you have an EU-licensed branch or subsidiary, DORA has applied since January 2025. The classification workflow, the NCA notification path, and the three-stage report templates should already exist. If they don’t, you have a documented gap that examiners will find.
The place to start is a gap assessment against the seven-criterion classification test and the three-report model. Map your current incident response workflow against the DORA requirements. Find where the US process and the EU process diverge — they will, on timeline, on report structure, and on the role of the NCA versus the primary federal regulator. Document both the gap and the remediation timeline.
For banks running a business continuity program that needs to absorb DORA alongside FFIEC BCM guidance, the operational resilience framing is useful: DORA is asking for demonstrated, tested capability — not just a written plan. That’s a higher bar than most US BCM programs currently hit.
The ESAs’ first annual incident report showed 3,383 major incidents in 2025. That’s 282 organizations per month discovering their incident was DORA-major. If your EU branch is running on a US playbook, that discovery will happen at the worst possible time.
The Business Continuity & Disaster Recovery Kit includes incident response frameworks built for financial services, with tabletop exercise templates and a resilience testing program you can adapt for DORA’s operational resilience testing requirements.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does DORA apply to a US bank that has an EU branch but no EU subsidiary?
What exactly triggers the 'major ICT incident' classification under DORA?
How does DORA's 4-hour initial report compare to the US banking regulators' 36-hour rule?
What is DORA's three-report model and which institutions does it apply to?
What are the DORA penalties for failing to meet the incident reporting deadlines?
What specifically needs to be added to a US incident response plan to handle DORA obligations?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
Personnel Continuity Under FFIEC BCM: Succession Is Not a List of Phone Numbers
Build FFIEC business continuity management personnel coverage with tested backups, delegated authority, usable procedures, and recovery evidence.
Jul 26, 2026
Business Continuity
Business Continuity Workaround Strategies: Document the Manual Process Before the System Goes Down
A BCP without documented manual workaround procedures isn't a continuity plan — it's a recovery plan. Here's the workaround template fields and critical-function structure FFIEC examiners expect to see.
Jul 25, 2026
Business Continuity
FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies
Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.
Jul 24, 2026