Major ICT incident reporting for payment firms — from PSD2 to DORA
If your major-incident reporting playbook still points at PSD2 Article 96, it points at a repealed obligation. Since 17 January 2025, payment institutions, e-money institutions and account-information service providers no longer report major operational or security incidents under PSD2 — they report major ICT-related incidents under the Digital Operational Resilience Act (DORA). The reporting hub, the classification test, the deadlines and the templates all changed. This is the operational walkthrough of what replaced what, and how a payments firm rewires its incident desk.
1. What changed, and when
Under PSD2 (Directive (EU) 2015/2366), Article 96 required PSPs to notify their home-state competent authority of major operational or security incidents, on the process and templates set by the European Banking Authority’s revised Guidelines (EBA/GL/2021/03, applicable from 1 January 2022). Those Guidelines were repealed with effect from 17 January 2025.
The replacement is DORA (Regulation (EU) 2022/2554), which applies from 17 January 2025. The accompanying “DORA Amending Directive” (Directive (EU) 2022/2556) removed the PSD2 incident-reporting obligation for entities that fall within DORA’s scope, so those entities now report under a single regime. The point of the change was to stop firms reporting the same technology outage twice, under two different frameworks, on two different clocks.
2. Who is in scope
DORA’s incident-reporting regime covers the payments universe directly:
- Credit institutions;
- Payment institutions, including exempted payment institutions;
- Electronic-money institutions, including exempted e-money institutions;
- Account-information service providers;
- Investment firms, crypto-asset service providers and other financial entities named in Article 2.
If you held an incident-reporting obligation under PSD2, you almost certainly hold one under DORA now. The scope test is the entity type, not the individual service.
3. Legal basis
- Regulation (EU) 2022/2554 (DORA) — Article 17 (ICT-related incident management process), Article 18 (classification of incidents and cyber threats), and Article 19 (reporting of major ICT-related incidents and voluntary notification of significant cyber threats).
- Commission Delegated Regulation (EU) 2024/1772 — the regulatory technical standard setting the criteria and materiality thresholds for classifying an incident as “major” and a cyber threat as “significant”.
- Commission Delegated Regulation (EU) 2025/301 — the RTS on the content and time limits of the initial, intermediate and final reports.
- Commission Implementing Regulation (EU) 2025/302 — the ITS setting the standard forms and templates for the reports.
- Directive (EU) 2015/2366 (PSD2), Article 96 — the predecessor obligation, and Directive (EU) 2022/2556 — the amending directive that switched it off for DORA-scope entities.
4. Classification — is the incident “major”?
DORA does not ask you to report every glitch. Under the classification RTS an incident is major when it meets a combination of criteria above their materiality thresholds. The criteria are: the number of clients or financial counterparties affected and the transactions involved; the reputational impact; the duration and the service downtime; the geographical spread across member states; data losses (integrity, confidentiality or availability); the criticality of the services affected; and the economic impact. The RTS sets primary and secondary criteria and the thresholds that turn a combination of them into a “major” classification. Build the classification logic to score an incident against those criteria automatically, and record the score — the supervisor can ask how you reached the decision.
5. The three-stage reporting timeline
Reporting runs to your home-state national competent authority, which forwards to the relevant European Supervisory Authority (and, where relevant, the ECB and other authorities). It is a three-stage process:
| Stage | Trigger | Deadline |
|---|---|---|
| Initial notification | Incident classified as major | As early as possible, within 4 hours of classification, and no later than 24 hours from becoming aware of the incident |
| Intermediate report | Initial notification submitted | Within 72 hours of the initial notification, or sooner when normal activities are recovered |
| Final report | Root-cause analysis complete | No later than one month after the major-incident classification |
Where a deadline falls on a weekend or public holiday, a limited extension to noon of the next working day is available for certain financial entities. Significant cyber threats may be notified voluntarily where the firm judges the threat relevant to the financial system — that notification is not mandatory, unlike the major-incident report.
6. The parallel-obligations trap
A single event can trigger more than one regulator clock, and a DORA report does not discharge the others:
- DORA — the major ICT-related incident report to the competent authority, on the timeline above.
- GDPR — where the incident is also a personal-data breach, notification to the data-protection authority without undue delay and within 72 hours of becoming aware (Regulation (EU) 2016/679, Article 33). This is a different authority, a different threshold and a different clock.
- Sectoral and national duties may add further notifications depending on the entity and the nature of the incident.
The operational consequence: the incident desk needs a routing matrix that fires the right notifications in parallel from a single triage, not a single “report it” button.
7. Worked examples
Facts: A payment institution suffers a six-hour degradation of its card-authorisation service during business hours, declining a material share of transactions for tens of thousands of clients across three member states.
What the rule says: Clients affected, transactions affected, service downtime, and geographical spread all point above the classification thresholds; the criticality of an authorisation service is high. The incident classifies as major.
What the practitioner does: Timestamps the major classification, files the DORA initial notification within 4 hours of that classification, follows with the intermediate report inside 72 hours once service is restored, and closes with the final report within one month once root cause is confirmed.
Facts: An e-money institution discovers that a phishing campaign harvested staff credentials and exposed a set of customer records before it was contained.
What the rule says: This is an ICT-related incident under DORA and, because customer personal data was exposed, also a personal-data breach under the GDPR. Two regimes apply at once.
What the practitioner does: Runs the DORA classification and, if major, the three-stage report to the competent authority; separately assesses the GDPR breach and, if the risk test is met, notifies the data-protection authority within 72 hours. The firm may also consider a voluntary DORA notification of the underlying cyber threat. It does not treat the DORA filing as covering the GDPR duty.
Facts: A brief database failover causes a 25-minute interruption to an internal reporting tool with no client-facing impact and no data loss.
What the rule says: The criteria stay below the materiality thresholds; the incident is not major.
What the practitioner does: Logs the incident in the DORA incident register — record-keeping applies regardless of classification — but files no report. If a pattern of similar minor incidents accumulates, that recurrence itself can push a later assessment over a threshold.
8. FAQ
Do I still report payment incidents under PSD2 Article 96?
No. For entities within DORA’s scope the PSD2 Article 96 incident-reporting obligation and the EBA Guidelines EBA/GL/2021/03 were switched off from 17 January 2025. You report major ICT-related incidents under DORA Article 19 instead.
Who do I report the incident to?
Your home-state national competent authority. It forwards the report to the relevant European Supervisory Authority and, where relevant, to the ECB and other authorities — you file once, to your own supervisor.
What makes an incident “major”?
A combination of criteria above the materiality thresholds set in the classification RTS (Commission Delegated Regulation (EU) 2024/1772): clients and transactions affected, reputational impact, duration and downtime, geographical spread, data losses, criticality of services and economic impact.
What are the deadlines?
Initial notification within 4 hours of classifying the incident as major and no later than 24 hours from awareness; intermediate report within 72 hours of the initial notification; final report within one month of the major classification.
Do I have to report cyber threats too?
Reporting a major ICT-related incident is mandatory. Notifying a significant cyber threat is voluntary — you may do it where you judge the threat relevant, but DORA does not compel it.
Does a DORA report satisfy my GDPR breach obligation?
No. Where the incident is also a personal-data breach, the GDPR 72-hour notification to the data-protection authority is a separate duty, to a different authority, on a different test. Run both in parallel.
9. What to do, today
- Retire the PSD2 Article 96 references in your incident procedure and repoint them to DORA Articles 17–19.
- Encode the classification RTS criteria into an automated scoring step, and timestamp the moment an incident is classified as major — that is when the 4-hour clock starts.
- Build the three-stage template pipeline (initial, intermediate, final) to the ITS forms, filing to your home competent authority.
- Wire a parallel routing matrix so a DORA-reportable incident that is also a data breach fires the GDPR 72-hour clock at the same time.
- Keep the incident register for every ICT incident, not only the major ones — recurrence can turn minor incidents into a reportable pattern.
Related: DORA register of information · DORA Article 30 — ICT contracts · PSD3 and the Payment Services Regulation tracker


