Incident Management
Logging and reporting ICT-related incidents
Logging an Incident & Creating Reports
Per DORA's technical standards, three reports must be submitted for major ICT-related incidents.
Adding an Incident
This will log the Incident in DORAedge so that the reports can start to be created.
Whether the Incident is classified as major or non-major is determined by answering the questions in the Criticality step.
After saving the Incident, the classification can be updated with a reason on the Incident's page by clicking on the classification.
Reporting Time Limits
DORA requires financial entities to submit Incident reports for ICT-related incidents that are categorized as major.
Major incidents: the time limits for reporting are automatically set to mirror the technical standards for reporting major ICT-related incidents to Competent Authorities.
Please note that Incident reports created in DORAedge must be exported and submitted to Competent Authorities per their specific submission guidelines within the time limit requirement.
Non-major incidents: As of April 2026, DORAedge has not yet implemented suggested discretionary time limits, as non-major reports are not required to be reported to Competent Authorities/EBA.
Activity Timeline
DORAedge captures both system-generated and user-logged information related to the Incident.
System generated: triggered upon logging incidents as well as creating and updating reports
User-logged: internal, freeform comments can be left in the Status Updates field
This can be used for tracking offline incident activity, e.g., sending reports outside of DORAedge and submitting them to Competent Authorities
Exporting Reports
After a report is created, click Open to see the report details in a slide out. Click Export Report, and select the desired file format for the exported report per your Competent Authority's requirements.
Last updated