Classifying fast and well
The mechanics
DORA articulates two distinct moments:
- Classification (Article 18) — is the incident major? It relies on harmonised criteria: clients and counterparties affected, reputation, duration and downtime, geographical spread, data losses, criticality of affected services, economic impact.
- Reporting (Article 19) — a three-stage schema: initial notification, intermediate report, final report.
The trap: the clock starts when the incident is classified as major, not when it is detected. Delaying classification does not buy time — it is a breach in itself, and one of the first things a supervisor checks by comparing monitoring timestamps with classification timestamps.
The operational grid
The grid must fit on one page and be usable by one person alone, at 3 a.m.
| Criterion | Threshold to record | Data source |
|---|---|---|
| Clients or counterparties affected | Number and percentage | Monitoring, client services |
| Downtime duration | Hours elapsed | Monitoring |
| Geographical spread | Number of member states | Service mapping |
| Data losses | Confidentiality, integrity, availability | Technical analysis |
| Criticality of affected services | Critical or important function? | Article 8 map |
| Economic impact | Estimated direct and indirect costs | Estimate, range acceptable |
Each criterion is filled with the best available estimate and an explicit note on the level of uncertainty. Waiting for exact data before classifying is the surest way to miss the deadline.
The decision chain
Three roles, named with deputies:
- Who detects and triggers qualification — usually the SOC or on-call;
- Who classifies — a designated role, reachable 24/7, empowered to decide alone;
- Who reports — the compliance function or its deputy, who transmits to the authority.
Role 2 is the most critical. If it requires a meeting or hierarchical sign-off, the deadline will be missed. The delegation must be written, with a threshold beyond which classification follows without debate.
The three reports
| Report | Content |
|---|---|
| Initial notification | Known facts, affected services, immediate measures, preliminary estimate |
| Intermediate report | Evolution, consolidated impact, recovery status, revised classification |
| Final report | Root causes, definitive quantified impact, corrective actions, lessons |
The final report leaves the durable trace. It is read, compared with previous ones, and its corrective actions will be checked at the next supervisory review.
Interaction with other obligations
One incident can trigger several notifications, with different deadlines and recipients: DORA to the competent authority, NIS 2 where applicable, data protection in the event of a breach, and informing affected clients.
These streams are not interchangeable. A single table in the procedure — which event, which obligation, which deadline, which recipient, which template — prevents omissions at the moment nobody has time to look.
Key takeaways
- Late classification is a breach, not time gained
- An on-call person must be able to classify without a meeting
- The criteria are cumulative and combine