What Commission Delegated Regulation (EU) 2024/1772 - Regulatory Technical Standards Specifying the Criteria for the Classification of ICT-Related Incidents and Cyber Threats, Setting Out Materiality Thresholds and Specifying the Details of Reports of Major Incidents (DORA Level 2 RTS, Article 18(4)) requires
Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, the materiality thresholds for determining major incidents, the high materiality thresholds for determining significant cyber threats, and the details of reports of major incidents. Adopted under DORA Article 18(4) third subparagraph and published in the Official Journal on 25 June 2024. Chapter I (Articles 1-7) defines the seven classification criteria: (1) clients, financial counterparts and transactions; (2) reputational impact; (3) duration and service downtime; (4) geographical spread; (5) data losses; (6) criticality of services affected; (7) economic impact. Chapter II (Articles 8-9) defines major incidents and their materiality thresholds. Per Article 8(1), an incident is a major incident where it has affected critical services per Article 6 AND either (a) the data losses threshold in Article 9(5)(b) is met, OR (b) two or more of the other materiality thresholds in Articles 9(1)-(6) are met. Article 8(2) treats recurring incidents (≥2 occurrences in 6 months with the same apparent root cause per DORA Art 20(b)(i)) collectively as one major incident; this rule does not apply to microenterprises or Article 16(1) entities. Article 9 sets the specific numeric thresholds: clients/counterparts/transactions threshold (Art 9(1)) - >10% of clients OR >100,000 affected clients OR >30% of financial counterparts OR >10% of daily transaction count OR >10% of daily transaction value OR affected clients/counterparts identified as relevant per Article 1(3); reputational impact threshold (Art 9(2)) - any condition in Article 2(a)-(d); duration and downtime (Art 9(3)) - incident duration >24 hours OR service downtime >2 hours for ICT services supporting critical or important functions; geographical spread (Art 9(4)) - impact in 2+ Member States; data losses (Art 9(5)) - adverse impact on business objectives/regulatory compliance OR successful unauthorised access; economic impact (Art 9(6)) - costs and losses exceed or likely to exceed €100,000. Chapter III (Article 10) defines a significant cyber threat as one where (a) it could affect critical/important functions of the entity or others, AND (b) it has a high probability of materialisation considering applicable vulnerabilities, threat actor capabilities and intent, and similar incidents at financial or non-financial entities. Chapter IV (Articles 11-12) covers cross-border relevance and details to be shared with competent authorities in other Member States.
Pillar: Banking & Global Finance · Authority: European Commission (delegated regulation under DORA Article 18(4) third subparagraph, based on draft RTS by the Joint Committee of the European Supervisory Authorities - EBA, EIOPA, ESMA) · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1772
SHA-256 integrity: 1f906a7d7015b1fbeb10c11091c09a2edae49c317c901409a2c8b1666c316867
Primary Citations — 12 traced to source
- Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024, Articles 1-7: Seven classification criteria - (1) clients/financial counterparts/transactions, (2) reputational impact, (3) duration and service downtime, (4) geographical spread, (5) data losses, (6) criticality of services affected, (7) economic impact
- Commission Delegated Regulation (EU) 2024/1772, Article 8(1): Major incident test - affects critical services per Article 6 AND either (a) Article 9(5)(b) data-losses threshold met OR (b) two or more of the Article 9(1)-(6) thresholds met
+ 10 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-dora-rts-incident-classification-2024-1772.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-dora-rts-incident-classification-2024-1772.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-dora-rts-incident-classification-2024-1772
- Back to registry: Browse all 10,090 compliance nodes