DORA RTS on Incident Classification
Specifies criteria for classifying ICT-related incidents and significant cyber threats, including materiality thresholds and reporting timelines under DORA Articles 18–20.
Source: EU Official Journal · OJ L 2024/1772 · published 25 Jun 2024 · effective 17 Jan 2025
- 1Detect
- 2Analyze
- 3Map
- 4Assess
- 5Remediate
Obligation coverage
38%
Open exposures
3
Partial or missing control coverage against this change.
Why relevant
Northbridge operates cross-border payment rails and cloud-hosted core systems. Incident classification thresholds directly shape major ICT incident reporting and board escalation.
Instrument
Commission Delegated Regulation (EU) 2024/1772
Domains
Defensibility note
Every obligation below is grounded in the source instrument. Agent output is a draft for SME review — not an autonomous ruling. Maker-checker remains required before any control or policy change is accepted.
Coverage map
- Art. 18(1) DORA · RTS Art. 1–3Partial
- Art. 19(2) DORA · RTS Art. 7Gap
- Art. 20 DORA · RTS Art. 9Partial