Cyber Security Blog

EU DORA 2026 Guide: Cyber Incident Response Requirements Explained

Written by Aditi Uberoi | 27 July 2026

DORA is dominating headlines and if you’re in the financial services space in the EU, it’s probably also dominating all boardroom discussions. The Digital Operational Resilience Act (DORA) came into force on 16th January, 2023 and has been fully applicable from 17th January, 2025. 

DORA is a regulatory framework and one of the key components of the European Union Digital Finance Package. The vision behind the Package is to catalyse the digital transformation of the financial services space in the EU and also harmonise the regulatory requirements at all EU member states. The goal is to offer clarity to financial institutions on how they can enter into a new era of digitisation while staying secure from the threats that loom large across all digital frontiers. 

Important 2026 Update: Since DORA became fully applicable in January 2025, organisations are now implementing the accompanying Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). This guide has been updated to reflect current reporting expectations, documentation requirements and operational practices. Organisations should ensure their procedures reflect these standards rather than relying solely on the Regulation text. 

The Act comes in the wake of major cybersecurity incidents with financial organisations the world over. The impact of a cyber-attack on a financial player, sadly, is never limited to the business alone and directly impacts the end-user or the citizen. To mitigate these risks and others arising from Information and Communication Technologies (ICT), the crux of the DORA requirements pertaining to operational resilience can be broken into two parts: 

  • Build operational resilience - By anticipating cybersecurity risks and ensuing disruptions. And preparing for these well ahead of time. 
  • Demonstrate operational resilience - Through regular testing, businesses must be able to prove that they have the necessary resilience to withstand a cyber or ransomware attack and act appropriately in a crisis.     

But how do you achieve these goals laid out by DORA and what does Digital Operational Resilience really mean? As experts in Cyber Incident Resilience Testing and creators of the NCSC Assured Training in Cyber Incident Planning & Response, we feel like we’re well-placed to explain both. 

In this article, though, we are going to focus on the Act’s requirements pertaining to Business Continuity and Cyber Incident Response Plans. In the next article in this educational series on DORA, we take up Digital Operational Resilience Testing. 

What DORA says about ICT Response and Recovery Plans

Chapter II of DORA covers ICT Risk Management in complete detail and emphasises on all aspects of Cyber Incident Response and Recovery, while Chapter IV is focussed on Digital Operational Resilience Testing.  Article 11 (Chapter II) talks in detail about Cyber Incident Response Recovery. The gist is encapsulated in this sentence: “Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms.” Chapter IV is devoted 

In essence, DORA formalises what we have been recommending to our clients for as long as we can remember - plan, plan and plan! If you fail to plan, plan to fail - at least when you’re embroiled in battle with an advanced criminal hacker. 

As per DORA, a solid business continuity plan and cyber security incident response plan are essential to ensure recovery from a cyber incident as seamlessly as possible. The financial entity must be able to respond to and resolve any cybersecurity incident with the end-goal of mitigating damage and minimising disruption to services. 

These plans should also clearly define communication channels and crisis communications management strategies. Communication plans must include all internal and external stakeholders in compliance with Article 14 of the Act. Article 19 (Chapter II) lays out the guidance on updating ‘competent authorities’ when a major ICT-related incident and/or significant cyber threat does emerge.    

Chapter II on ICT Risk Management of the final text of DORA is detailed and exhaustive. It talks of every aspect of Cyber Incident Response - Identification (Article 8), Prevention (Article 9), Detection (Article 10) and Response and Recovery (Article 11), Lessons Learned (Article 13), Communication (Article 14) and so forth. 

It can be daunting and overwhelming to grasp every detail of every Article. So much so, that we’ve actually met potential clients who haven’t even started readying themselves for DORA a year into its official announcement. 

Lucky for you, though, that you’ve stumbled upon this article and we may be able to help in at least unravelling DORA requirements at the onset. Our objective in the next section is to simplify for you how you can get started on building an effective Business Continuity Plan and inch a step closer to becoming DORA compliant before 2025. 

DORA Incident Reporting Timelines Explained

One of the biggest challenges organisations face during a cyber incident is balancing technical response with regulatory reporting. DORA establishes a structured reporting process for major ICT-related incidents, ensuring competent authorities receive timely information as the situation develops.

Rather than producing a single report, organisations should be prepared for a staged reporting process.

Report

Timing

Purpose

Initial Notification

As early as possible after classifying an incident as major, and no later than 24 hours after detection

Alerts the competent authority that a major ICT incident has occurred.

Intermediate Report

Within 72 hours of submitting the initial notification

Provides updated information on the incident, its impact, containment measures and any known root cause.

Final Report

Within one month of submitting the intermediate report

Confirms the full impact, root cause analysis, remediation activities and lessons learned.

Meeting these reporting deadlines requires far more than technical capability. Organisations should already have documented reporting procedures, decision-making authorities, contact lists and evidence collection processes in place before an incident occurs.

Waiting until a cyber incident happens to determine who approves reports, who contacts regulators or what information must be collected is likely to create unnecessary delays during the most critical stages of an incident.

Actions for meeting DORA’s Cyber & Operational Resilience & Response Requirements

#1. Train your staff - In our opinion, the first and foremost step you need to take is to educate your staff in Cyber Incident Response. They need to understand what goes into preparing for and responding to a cyber crisis. 


Many of our clients whose teams have attended the NCSC Assured Training in Cyber Incident Planning and Response shared with us how significantly the course helped their staff to understand the real impact a cyber incident could have on their organisation. High-quality cybersecurity training in Incident Response really opens up the minds of employees about how much still needs to be done to bolster their defences against cyber crime. 

The course also teaches you how to implement a well-defined and managed approach to dealing with a cyber-attack or data breach. Your team can learn how to put in place an effective Cyber Incident Response framework which can ultimately help you fulfil the requirements of the Digital Operational Resilience Act.

#2. Create or Review Your Cyber Incident Response Plan: An effective Business Continuity Plan and a Cyber Incident Response Plan are prerequisites of DORA. You need to make sure that you have a robust and fit-for-purpose cyber incident response plan as a financial entity. 

The plan should actually help in case of an Incident to control the infection and mitigate any damage that it can cause. It must reflect the latest techniques and core principles of effective cyber incident response. It must also be in sync with the current cybersecurity threat landscape. 

If you don’t have a plan, or are uncertain about the effectiveness of your existing plan, our cybersecurity consultants can help. Our Virtual Cyber Assistant Service is unlike anything in the market. You can hire deeply experienced cybersecurity experts for exactly the number of hours you need them. 

You can choose to have them create a new Plan for you or review your existing plan and share their opinion on whether it is aligned with DORA or not. They can also help you refresh your plan to meet the requirements of the Act. But the services aren’t limited to just your Incident Response Plan. 

Our expert cyber consultants can help you achieve significant improvements in your overall cybersecurity maturity. Ensuring Business Continuity within the context of cybersecurity is amongst the chief reasons why our clients enlist the services of our cybersecurity consultants. And this in turn brings you closer to achieving the goals laid out in the Digital Operational Resilience Act.   

#3. Use our FREE Incident Response Plan Template: We understand that it may not be possible or feasible to immediately hire an external expert to advise you on your Cyber Incident Response Plan. This is why we’ve created an invaluable FREE resource - our Cyber Incident Response Plan template. 

Created by the world leader in cybersecurity incident response and the creator of the NCSC Assured Training in Incident Response Planning, this free template is an extremely crisp, insightful and easily customisable resource. You can easily tailor it to your organisational structure, technology infrastructure and business context. 

While it won’t replace the expertise of an external cybersecurity consultant, it’s a great starting point. It will show you what key elements of incident response to cover and what steps to take immediately in the aftermath of a cybersecurity incident. Use it in combination with our free Cyber Incident Response Checklist and you’ll feel more confident about becoming DORA compliant. 

#4. Build Effective Playbooks in Conjunction with Plans: Though the DORA text doesn’t specifically mention Cyber Incident Response Playbooks, we recommend creating and/or refreshing yours in conjunction with your IR plans. Together, they can help you achieve the levels of digital operational resilience that DORA mandates.

Incident Response Playbooks contain immediate remediation steps based on pre-defined triggers. They also contain specific triggers for communication channels in case of a cyber incident - a stringent DORA requirement. 

#5. Test your Response & Recovery Cybersecurity plans: Digital Operational Resilience Testing is a major part of DORA. And it is highly recommended to regularly test your cyber resilience through cyber crisis tabletop exercises. We cover this aspect of DORA requirements in greater detail in our next blog. 

However, any conversation about cyber resilience and cyber incident response plans is incomplete without a mention of cybersecurity drills so we had to include this in the list of action items. In the context of IR plans, it has to be underlined that testing the plans against simulated cyber attack scenarios is critical. 

Without cyber simulation drills, it’s impossible to know whether the plans are any good or not. It’s also the best way to familiarise your staff and key incident responders with what’s in the plans, processes and cybersecurity procedures. 

What Documentation Should Be Prepared Before a DORA Incident?

An effective incident response capability is built long before an incident occurs. DORA expects organisations to maintain documented procedures that enable a rapid, coordinated and well-governed response when major ICT incidents arise. Refer to our DORA Incident Response Document Library for a full list of documents, policies and procedures you must have in order to be fully DORA compliant.  

Typical documentation includes:

  • An Incident Response Plan defining roles, responsibilities and response procedures.
  • Incident response playbooks for common scenarios such as ransomware, data breaches and third-party service failures.
  • An Incident Classification Procedure explaining how incidents are assessed and when they become reportable.
  • A Crisis Communications Plan covering internal, customer, regulator and media communications.
  • Regulatory reporting procedures aligned to DORA reporting obligations.
  • Contact directories for internal teams, regulators, suppliers and external advisers.
  • Evidence collection logs and forensic preservation procedures.
  • Decision logs to record key actions taken during the incident.
  • Incident registers to maintain a complete record of reportable events.
  • Lessons learned procedures for continual improvement following every significant incident.

Many organisations discover during tabletop exercises that these documents either do not exist, are incomplete or have never been tested together. Having a complete and integrated document set significantly improves both operational response and regulatory readiness.

You should also download our DORA Incident Response Master Document Register. It is the operational control centre for your entire DORA incident response documentation estate. Instead of managing dozens of policies, procedures, playbooks, forms and registers individually, you manage everything through one structured register.

Common DORA Incident Response Mistakes

Since DORA became fully applicable, organisations have increasingly shifted their focus from creating policies to demonstrating that those policies work in practice. The same weaknesses continue to appear across many incident response programmes.

Common issues include:

Delaying incident classification

Organisations often spend valuable time debating whether an incident is "major" rather than following a documented classification process.

Undefined reporting responsibilities

If legal, compliance, cyber security and senior management have not agreed reporting responsibilities in advance, regulatory notifications can quickly become delayed.

Missing reporting templates

Preparing reports from scratch during an active cyber incident increases pressure and creates unnecessary risk.

Incomplete documentation

Incident response plans frequently exist without supporting playbooks, communication procedures, evidence logs or decision records.

Limited executive involvement

Cyber incidents rapidly become business issues. Senior leadership should understand their responsibilities before an incident occurs, not during one.

Incident response plans that have never been exercised

Documentation alone is rarely sufficient. Regular tabletop exercises help validate whether procedures, reporting workflows and governance arrangements actually function under pressure.

What DORA Incident Response Looks Like in Practice

Achieving DORA compliance is about much more than having an Incident Response Plan stored on a shared drive. Regulators increasingly expect organisations to demonstrate that their incident response arrangements are operational, documented and regularly exercised.

In practice, a mature DORA incident response capability typically includes:

  • Clearly defined incident classification criteria.
  • Scenario-specific response playbooks for the organisation's most significant cyber risks.
  • A documented escalation process linking technical teams, executive leadership and compliance functions.
  • Pre-approved regulatory reporting workflows and notification templates.
  • Crisis communication procedures for employees, customers, suppliers and regulators.
  • Evidence collection and decision logs that support post-incident investigations.
  • Regular tabletop exercises that validate both technical response and governance arrangements.
  • A structured lessons learned process that drives continual improvement after every significant incident.

Organisations that establish these capabilities before an incident occurs are generally able to respond more effectively, meet regulatory reporting obligations with greater confidence and demonstrate stronger operational resilience during supervisory reviews.

How CM-Alliance Helps Organisations Meet DORA Incident Response Requirements

Meeting DORA's incident response requirements requires more than understanding the regulation. Organisations need documented processes, clearly defined governance, tested response procedures and evidence that these arrangements work in practice.

CM-Alliance has worked with organisations across regulated sectors to strengthen cyber incident response capabilities through a combination of practical documentation, independent assurance and realistic exercising.

Our support includes:

  • Developing and reviewing Incident Response Plans, playbooks and supporting documentation.
  • Creating complete incident response document libraries and registers aligned to DORA requirements.
  • Delivering cyber tabletop exercises that test technical teams, executive leadership and crisis management processes.
  • Providing executive cyber crisis training that prepares senior leaders to make informed decisions during high-pressure incidents.
  • Conducting independent incident response and security policy assurance reviews to identify documentation gaps, governance weaknesses and opportunities for improvement.

Rather than producing documentation simply to satisfy compliance requirements, our focus is on helping organisations build incident response capabilities that are practical, repeatable and capable of standing up to both real cyber incidents and regulatory scrutiny.

Whether an organisation is preparing for DORA implementation, reviewing existing incident response arrangements or strengthening operational resilience, combining robust documentation with regular exercising and independent assurance provides a far stronger foundation than relying on policies alone.

Last Word

Cyber incident response planning is critical to the Digital Operational Resilience Act (DORA). It ensures that financial entities and service providers can effectively prepare for, respond to, and recover from cyber incidents. 

Incident Response planning is essential for minimising the impact of cyber incidents on the financial markets, protecting consumers, and preserving the stability and resilience of the financial system. 

By mandating robust incident response mechanisms and a robust Incident Response Plan, DORA aims to enhance the overall digital operational resilience of the financial sector. While complying with DORA is mandatory for financial entities in the EU, it is important to remember that by taking the actions mentioned above, you can also ensure that your business can withstand, respond to, and recover from adverse cyber events without significant disruption to financial services or loss of sensitive data.

FAQs on DORA Incident Response Requirements

1. What are DORA incident response requirements?

The Digital Operational Resilience Act (DORA) requires financial entities to establish and maintain documented incident response procedures for detecting, managing, classifying, responding to and recovering from ICT-related incidents. Organisations must be able to identify major ICT incidents, notify competent authorities within prescribed timelines, maintain appropriate records and continuously improve their incident response capability through testing and lessons learned.

2. What qualifies as a major ICT incident under DORA?

A major ICT incident is an ICT-related event that significantly disrupts or has the potential to disrupt a financial entity's operations, services or customers. DORA requires organisations to assess incidents against criteria such as the number of clients affected, service downtime, geographical spread, data loss, financial impact and reputational consequences. Incidents meeting the regulatory thresholds must be reported to the relevant competent authority.

3. What are the DORA incident reporting timelines?

DORA requires major ICT incidents to be reported through a staged reporting process. Organisations must submit an initial notification as soon as possible after classifying an incident as major, and no later than 24 hours after detection. An intermediate report follows within 72 hours of the initial notification, with a final report submitted within one month of the intermediate report. These reports provide progressively more detailed information as the incident investigation develops.

4. Who must report major ICT incidents under DORA?

Financial entities that fall within the scope of DORA are responsible for reporting major ICT incidents to their competent authority. This includes banks, investment firms, insurance and reinsurance companies, payment institutions, electronic money institutions, crypto-asset service providers and many other regulated financial organisations operating within the European Union. 

5. What documentation is required for DORA incident response?

While DORA does not prescribe a fixed list of documents, organisations are expected to maintain comprehensive incident response documentation. This typically includes an Incident Response Plan, incident classification procedures, response playbooks, crisis communication plans, regulatory reporting procedures, escalation matrices, contact lists, evidence logs, incident registers, decision records and lessons learned documentation. Together, these documents help demonstrate that incident response arrangements are structured, repeatable and effective.

6. Does DORA require organisations to test their incident response plans?

Yes. DORA requires financial entities to regularly test their digital operational resilience, including their incident response capabilities. Organisations should conduct exercises such as cyber tabletop simulations, technical response testing and scenario-based exercises to validate that their procedures, governance arrangements and communication processes work effectively during real ICT incidents. Testing also helps identify gaps before they become regulatory or operational issues.

7. What is the difference between DORA incident response and NIS2 incident reporting?

Although both frameworks require organisations to manage and report significant cyber incidents, they apply to different sectors and have different objectives. DORA focuses specifically on the operational resilience of financial entities and establishes detailed requirements for ICT risk management, incident reporting, resilience testing and third-party ICT risk. NIS2 applies across a broader range of essential and important entities, with an emphasis on improving cybersecurity and resilience across critical sectors. Organisations that fall within the scope of both regulations should ensure their incident response procedures satisfy the requirements of each framework.

8. How can organisations prepare for DORA incident reporting before an incident occurs?

Preparation should begin long before a cyber incident takes place. Organisations should establish documented incident response procedures, define incident classification criteria, prepare reporting templates, maintain up-to-date contact lists, assign reporting responsibilities, develop incident response playbooks and regularly test these arrangements through cyber tabletop exercises. Maintaining a complete set of incident response documentation and reviewing it periodically helps organisations respond more effectively while meeting DORA's reporting obligations with confidence.