A

AITAS Intelligence

Horizon Scan → Gap Analysis

At RiskEU · L2

DORA RTS on Incident Classification

Specifies criteria for classifying ICT-related incidents and significant cyber threats, including materiality thresholds and reporting timelines under DORA Articles 18–20.

Source: EU Official Journal · OJ L 2024/1772 · published 25 Jun 2024 · effective 17 Jan 2025

  1. 1Detect
  2. 2Analyze
  3. 3Map
  4. 4Assess
  5. 5Remediate

Obligation coverage

38%

Open exposures

3

Partial or missing control coverage against this change.

Why relevant

Northbridge operates cross-border payment rails and cloud-hosted core systems. Incident classification thresholds directly shape major ICT incident reporting and board escalation.

Instrument

Commission Delegated Regulation (EU) 2024/1772

Domains

DORAICT riskIncident response

Defensibility note

Every obligation below is grounded in the source instrument. Agent output is a draft for SME review — not an autonomous ruling. Maker-checker remains required before any control or policy change is accepted.

Coverage map

  • Art. 18(1) DORA · RTS Art. 1–3Partial
  • Art. 19(2) DORA · RTS Art. 7Gap
  • Art. 20 DORA · RTS Art. 9Partial