DORA compliance requires an incident management process that can detect, manage, classify, escalate, and report ICT-related incidents. A usable compliance record should show all ICT-related incidents and significant cyber threats, the classification analysis, impacted services, senior-management escalation, client communications where required, and the report or notification submitted to the relevant competent authority.
Incident evidence should separate three questions: whether an event is an ICT-related incident, whether it is major, and what reporting package is required. The classification RTS covers criteria such as affected clients or counterparts, transactions, duration, geographical spread, data losses, criticality of services, reputational impact, and economic impact. The reporting ITS then standardises the initial notification, intermediate report, final report, reclassification, outsourced reporting notice, aggregated provider report, and voluntary significant cyber-threat notification templates.