Skip to content

RTS (EU) 2024/1772 – Incident Classification

PropertyValue
NumberDelegated Regulation (EU) 2024/1772
DORA ArticleArt. 18(3)
PillarP2 – Incident Reporting
Publication25.06.2024
Applicable since17.01.2025
EUR-LexLink

Content

Specifies the 7 classification criteria for ICT-related incidents and cyber threats:

  1. Affected clients/financial counterparties
  2. Reputational impact
  3. Downtime of critical services
  4. Geographic spread
  5. Data loss (CIA triad)
  6. Criticality of affected services
  7. Economic impact

Defines materiality thresholds and provides practical examples for applying the criteria.

→ Details: P2: Incident Reporting

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT