DORA · Incidents & Reporting Deadlines
Three deadlines, one clock: 4 h / 72 h / 30 days – with digitally signed incident report.
When a Major ICT Incident occurs, the first hour counts, not the first day.
"For me it's DORA, not NIS2 – that's what most vendors mix up instantly." This is how ICT risk managers at banks describe the difference that hits hardest during incident reporting: DORA Art. 19 requires classifying a serious ICT-related incident within 4 hours of discovery, followed by an interim report and a final report to FMA or BaFin. Without dedicated tooling, this runs on phone calls and improvised Word documents — exactly where things go wrong under time pressure.
The three-tier reporting cascade — initial report, interim report, final report — has different content requirements at each tier. A formatting error or a forgotten interim report is avoidable, but easily overlooked under time pressure when no system systematically counts down which tier is due when.
Threat-Led Penetration Testing (TLPT, Art. 26/27) additionally requires documented planning and tracking — one more piece of evidence that must be ready on audit day, not reconstructed from scratch.
Four building blocks for deadline-safe incident reporting.
Incident register, three-tier protocol
Every incident flows through initial report, interim report, and final report as a guided process with the required fields at each tier — instead of a loose collection of emails and phone notes.

Classification countdown from discovery
From the moment discovery is recorded, the 4-hour classification countdown runs visibly, followed by the deadlines for interim and final reports — no need to reconstruct them from memory.

Incident report as digitally signed PDF
The incident report to regulators is generated as a digitally signed PDF with pre-submission validation — so nothing incomplete or malformed gets sent.

TLPT planning & tracking
Threat-Led Penetration Testing cycles under Art. 26/27 are planned and tracked with status — as a standalone, always-ready proof instead of a separate project file.

More about DORA and the infrastructure behind it.
Reporting deadlines, TLPT requirements, and primary sources in detail.
Regulation details →How the three-tier reporting protocol and classification countdown work together in workspace.reportact.com.
Function details →Your first digitally signed DORA incident report — today.
In 30 minutes we show you what ReportAct delivers for this use case – no obligation.