DORA major incident reports: what the ESAs' staff instructions expect
European Securities and Markets Authority (ESMA)AnnouncementIssued
By the ExamPass CY editorial teamPublished
- DORA and ICT risk
- Reporting
Short answer
On 16 September 2026 staff of the European Supervisory Authorities (ESAs) issued operational instructions on reporting major ICT-related incidents under DORA. The 14 points aim to improve data quality and consistency: for example, monetary fields are reported in thousands of units, the incident identifiers should not change between the initial notification and the final report, and optional fields that do not apply are left blank. The instructions are provided on a best-efforts basis and do not represent a legal interpretation.
At a glance
- What changes
- The law does not change; ESAs staff set out how fields in the DORA major incident reporting templates are expected to be completed.
- Who is affected
- Financial entities in DORA's scope that report major ICT-related incidents to their competent authority, including investment firms, credit institutions, payment and e-money institutions, crypto-asset service providers authorised under MiCA, UCITS management companies and AIFMs (sub-threshold AIFMs are excluded).
- Financial entities in the scope of DORA that report major ICT-related incidents
- Staff who prepare and submit incident notifications and reports
- Competent authorities that forward incident information to the ESAs
- What to do
- Check your incident reporting procedure and templates against the 14 instructions, especially monetary fields, identifiers, final reports and corrections.
- By when
- Now — review without delay
What are the operational instructions?
A five-page document of operational instructions on DORA incident reporting, dated 16 September 2026, has been published on ESMA's website. Its aim is to help competent authorities when they engage with financial entities about major ICT-related incident reports under the Digital Operational Resilience Act, Regulation (EU) 2022/2554, so that the data reported are of better quality and reporting is more consistent from one jurisdiction to another.
Financial entities report a major incident to their competent authority through the channels, templates and format set at national level; competent authorities then notify the ESAs using pre-defined templates in English. The instructions refer to the reporting templates in Implementing Regulation (EU) 2025/302, the content and time limits in Delegated Regulation (EU) 2025/301 and the classification criteria in Delegated Regulation (EU) 2024/1772. They are provided by ESAs staff on a best-efforts basis, are not a legal interpretation or an official stance of the ESAs, were agreed with the relevant competent authorities and will be updated regularly.
What do the instructions say about amounts, blanks and report versions?
Monetary fields 3.11, 4.13 and 4.14 are reported in thousands of units, in the currency given in field 1.15: an amount of EUR 2,500 is reported as 3 (or 2.5 with further precision). Free-text fields should contain only information relevant to the field, and a field that is neither mandatory nor applicable is best left blank rather than filled with words such as 'not applicable'. The national language can still be used in free-text fields.
The final report is due no later than one month after the intermediate report or the latest updated intermediate report, so at least one intermediate report a month is expected until the final report. A correction is submitted as a new version of the latest report (for example, a corrected intermediate report) and should contain all the information from the latest update. The values in fields 1.3a, 1.3b and 2.1, which identify the incident, should remain unchanged from the initial notification to the final report, to avoid double counting.
What about classification and third-party details?
Every report should list 'critical services affected' explicitly among the classification criteria in field 2.5, for consistency. Under Delegated Regulation (EU) 2024/1772 an incident is major only where critical services are affected and at least one other condition is met, so this criterion is always fulfilled. The country of the affected financial entity should not be included in the geographical spread in field 2.6.
Where an incident originates from a third-party provider or another financial entity, field 2.8 should give, separated by semicolons and in this order, the full legal name, the LEI or EUID, the type of code and any other relevant information. Field 3.17 (whether duration and downtime are actual or estimated) is expected in both intermediate and final reports, the fields for resolution authorities are completed only where they apply (field 4.10 where the incident poses a risk to critical functions, field 4.11 where it has affected resolvability), and field 4.12 on the economic-impact threshold is always reported in final reports where economic impact is a classification criterion. For field 3.25, the wording 'data exfiltration and manipulation, excluding identity theft' is taken as the reference.
In the official wording
“The instructions are provided on ‘best efforts’ basis by the ESAs staff and therefore they do not represent any legal interpretation, nor do they represent official stance of the ESAs.”
When does it apply?
Applies now
- DORA's major ICT-related incident reporting duties, with the templates of Implementing Regulation (EU) 2025/302 and the content and time limits of Delegated Regulation (EU) 2025/301.
- The ESAs staff operational instructions of 16 September 2026, which are not a legal interpretation but were agreed with the relevant competent authorities.
Applies later
No later dates announced.
What to do
- Check that your incident reports give monetary fields 3.11, 4.13 and 4.14 in thousands of units and in the currency of field 1.15.No fixed deadline
- Keep the incident identifiers in fields 1.3a, 1.3b and 2.1 unchanged for the whole reporting life cycle.No fixed deadline
- Plan at least one intermediate report a month until the final report, and submit corrections as a complete new version of the latest report.No fixed deadline
- List 'critical services affected' in field 2.5 of every major incident report and leave non-applicable optional fields blank.No fixed deadline
Sources
- DORA Incident Reporting – Operational Instructions (opens in a new tab)
ESAs staff (published by ESMA)Official text
- DORA incident reporting - operational instructions (ESMA library entry) (opens in a new tab)
ESMAOfficial text
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) (opens in a new tab)
EUR-LexOfficial text
Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.
This document has been drafted using material downloaded from ESMA's website. ESMA does not endorse this publication and in no way is liable for copyright or other intellectual property rights infringements nor for any damages caused to third parties through this publication.
© European Union, https://eur-lex.europa.eu. EU material is reused with credit and has been summarised; only the Official Journal of the European Union is authentic.