M ManySignal

Compliance — DORA

DORA major incident notification — 4 hours, 24 hours, one month

DORA requires financial entities to notify competent authorities (EBA, ESMA, EIOPA, ECB) within 4 hours of classifying an ICT incident as major. ManySignal automates incident classification against DORA's RTS criteria and generates the notification package before the 4-hour deadline — in EU-resident infrastructure.

Jan 2025

DORA applies from 17 January 2025

4 hours

Major ICT incident initial notification to competent authority

24 hours

Intermediate incident report deadline

1 month

Final incident report deadline

Control mapping — DORA to ManySignal

DORA ArticleRequirementManySignal Capability
Art. 9(1) ICT Risk — Protection and Prevention Continuous monitoring of ICT infrastructure — network anomalies, access control violations, and configuration changes
Art. 10(1) Detection Automated anomaly detection across ICT systems — machine-verifiable evidence of continuous detection capability
Art. 10(2) Anomalous ICT Activities Alerts Real-time alerts on anomalous activity with automated triage and evidence packaging
Art. 17(1) ICT-Related Incident Classification Automated incident classification against DORA significance criteria — major/non-major classification with rationale
Art. 19(1)(a) 4-hour Intermediate Report (Major Incidents) Intermediate report generation — incident type, classification rationale, affected functions, and preliminary financial impact
Art. 19(1)(b) 24-hour Final Report Final incident report for major ICT incidents — root cause, duration, cross-border impact, and remediation evidence
Art. 25(1) Digital Operational Resilience Testing Threat-Led Penetration Testing (TLPT) evidence support — detection capability demonstrated during TLPT exercises
Art. 28(4) Third-Party ICT Provider Monitoring Critical third-party ICT provider access monitoring and incident correlation

DORA compliance — auditor questions

Which financial entities are subject to DORA?

DORA (Regulation 2022/2554, applying from 17 January 2025) covers: credit institutions, payment institutions, electronic money institutions, investment firms, crypto-asset service providers (CASPs), central securities depositories, CCPs, trading venues, trade repositories, insurance and reinsurance undertakings, IORPs, credit rating agencies, statutory auditors, and critical ICT third-party service providers. The scope is the broadest yet for EU financial sector cybersecurity.

What is DORA's major incident notification timeline?

DORA Article 19 requires: (1) an initial notification to the competent authority within 4 hours of classifying an incident as 'major'; (2) an intermediate report within 24 hours; and (3) a final report within 1 month. The initial 4-hour notification is the most operationally challenging — ManySignal's automated incident classification and notification draft generation enables this timeline even without 24/7 security staff.

How does ManySignal help with DORA's Threat-Led Penetration Testing (TLPT)?

DORA Article 25 requires 'advanced' financial entities to conduct TLPT every 3 years. TLPT involves red team exercises against live production systems. ManySignal contributes to TLPT by: (1) demonstrating detection capability during the exercise — ManySignal should detect red team activity and the detection record becomes part of the TLPT evidence; (2) providing the pre-exercise threat intelligence profile that guides the red team's TTPs.

Does DORA require financial entities to assess their critical ICT third-party providers?

Yes. DORA Articles 28-44 establish requirements for ICT third-party risk management, including: due diligence on critical ICT third-party providers (CTPPs), contractual arrangements with specific security requirements, and ongoing monitoring. ManySignal's third-party access monitoring — tracking what CTPP system credentials access, when, and what they do — provides evidence of the ongoing monitoring requirement.

How does ManySignal classify ICT incidents as 'major' under DORA's classification criteria?

DORA's Regulatory Technical Standards (RTS) on ICT incident classification specify major incident criteria including: number of clients affected, duration of service disruption, geographic spread, data losses, and reputational impact. ManySignal's incident classification engine applies these RTS criteria — flagging incidents likely to meet 'major' thresholds for analyst confirmation, and generating the classification rationale required in the 4-hour notification.

Get DORA-compliant before the next examination

Deploy in EU infrastructure, configure DORA major incident thresholds, and generate your first DORA-formatted incident notification package — in one session.