Use Case Use Cases / DORA

DORA · Incidents & Reporting Deadlines

Three deadlines, one clock: 4 h / 72 h / 30 days – with digitally signed incident report.

Why this matters

When a Major ICT Incident occurs, the first hour counts, not the first day.

"For me it's DORA, not NIS2 – that's what most vendors mix up instantly." This is how ICT risk managers at banks describe the difference that hits hardest during incident reporting: DORA Art. 19 requires classifying a serious ICT-related incident within 4 hours of discovery, followed by an interim report and a final report to FMA or BaFin. Without dedicated tooling, this runs on phone calls and improvised Word documents — exactly where things go wrong under time pressure.

The three-tier reporting cascade — initial report, interim report, final report — has different content requirements at each tier. A formatting error or a forgotten interim report is avoidable, but easily overlooked under time pressure when no system systematically counts down which tier is due when.

Threat-Led Penetration Testing (TLPT, Art. 26/27) additionally requires documented planning and tracking — one more piece of evidence that must be ready on audit day, not reconstructed from scratch.

What you get

Four building blocks for deadline-safe incident reporting.

Incident register, three-tier protocol

Every incident flows through initial report, interim report, and final report as a guided process with the required fields at each tier — instead of a loose collection of emails and phone notes.

Incident register with reporting deadline clocks in ReportAct

Classification countdown from discovery

From the moment discovery is recorded, the 4-hour classification countdown runs visibly, followed by the deadlines for interim and final reports — no need to reconstruct them from memory.

Reporting deadline countdown for NIS2, DORA and GDPR in ReportAct

Incident report as digitally signed PDF

The incident report to regulators is generated as a digitally signed PDF with pre-submission validation — so nothing incomplete or malformed gets sent.

Reporting workflow with a draft report per reporting stage in ReportAct

TLPT planning & tracking

Threat-Led Penetration Testing cycles under Art. 26/27 are planned and tracked with status — as a standalone, always-ready proof instead of a separate project file.

TLPT planning under DORA Art. 24–27 in ReportAct
Learn more

More about DORA and the infrastructure behind it.

DORA — the regulation

Reporting deadlines, TLPT requirements, and primary sources in detail.

Regulation details →
Incident Management — the function

How the three-tier reporting protocol and classification countdown work together in workspace.reportact.com.

Function details →
Next step

Your first digitally signed DORA incident report — today.

In 30 minutes we show you what ReportAct delivers for this use case – no obligation.