ESAs — DORA Incident Reporting Operational Instructions (Sep 2026)

Tag: S-2026-09-16-eba-dora-incident-reporting-operational-instructions Type: report (ESAs-staff operational-guidance document) Author(s): European Supervisory Authorities staff — EBA, EIOPA, ESMA (agreed with competent authorities) Date of source: 2026-09-16 (publication date on the EBA publications listing) Date ingested: 2026-09-17 Authority weight: medium — a primary document published by the EBA, but explicitly “best efforts” ESAs-staff guidance that “do[es] not represent any legal interpretation, nor… official stance of the ESAs”, to be updated regularly. Raw file: S-2026-09-16-eba-dora-incident-reporting-operational-instructions.md. Source PDF: https://www.eba.europa.eu/sites/default/files/2026-09/3039fc09-0b6e-4468-99bb-e27ae88bcf85/DORA%20IR%20-%20Operational%20Instructions_for%20publication%20%281%29.pdf ; listing: https://www.eba.europa.eu/publications-and-media/publications

What it claims

On 16 September 2026 the EBA published (on behalf of the ESAs — EBA, EIOPA and ESMA) a document of operational instructions to support competent authorities’ supervisory engagement with financial entities on the reporting of major ICT-related incidents under DORA (Regulation (EU) 2022/2554), with the stated aim “to enhance data quality and promote greater consistency across jurisdictions” [S-2026-09-16-eba-dora-incident-reporting-operational-instructions]. The document is expressly best-efforts ESAs-staff material that does not represent legal interpretation or the official ESA stance, has been agreed with the relevant competent authorities, and will be updated regularly based on experience with DORA incident reporting [S-2026-09-16-eba-dora-incident-reporting-operational-instructions].

It sits under the DORA incident-reporting instruments — ITS 2025/302 (standard forms/procedures to report a major ICT-related incident and notify a significant cyber threat), RTS 2025/301 (content and time limits for initial notification, intermediate and final reports), and RTS 2024/1772 (classification criteria and materiality thresholds) — and describes the reporting chain: a firm reports a major incident to its competent authority using national channels/templates, and the competent authority then notifies the ESAs using pre-defined ESA templates in English [S-2026-09-16-eba-dora-incident-reporting-operational-instructions].

The substance is a table of 14 field-level operating topics, including: use of the English templates for CA→ESA notifications (free-text may stay national); reporting monetary fields (3.11, 4.13, 4.14) in thousands of units in a single currency; leaving non-applicable free-text fields blank rather than entering “N/A”; the one-month final-report deadline with an expected monthly cadence of intermediate reports; submitting corrections as a new version of the latest report type carrying all prior information; keeping the unique incident identifiers (Fields 1.3a/1.3b, 2.1) unchanged across the incident life-cycle to prevent double counting; always identifying “critical services affected” in Field 2.5 (per Art. 8(1) RTS 2024/1772); excluding the home country from geographical spread (Field 2.6); a standardised semicolon-separated TPP/other-entity origin format with LEI or EUID in Field 2.8; completing the duration/downtime actual-vs-estimate flag (Field 3.17) for both intermediate and final reports; a wording correction for Field 3.25 threat techniques; conditional completion of the resolution-authority fields (4.10, 4.11); and reporting the economic-impact threshold (Field 4.12) in final reports where economic impact is a classification criterion [S-2026-09-16-eba-dora-incident-reporting-operational-instructions].

Notable quotes

“This document provides operational instructions intended to support competent authorities in their supervisory engagement with financial entities regarding the reporting of information on the major ICT-related incidents under Regulation (EU) 2022/2554 (DORA), to enhance data quality and promote greater consistency across jurisdictions.” — DORA Incident Reporting – Operational Instructions, p.1 (16 September 2026)

“The instructions are provided on ‘best efforts’ basis by the ESAs staff and therefore they do not represent any legal interpretation, nor do they represent official stance of the ESAs.” — DORA Incident Reporting – Operational Instructions, p.1 (16 September 2026)

What’s speculative vs. asserted

  • Asserted (primary PDF, fetched in full): the 16 Sep 2026 publication; the purpose (data quality + cross-jurisdiction consistency); the best-efforts / non-binding status; the reference to ITS 2025/302, RTS 2025/301 and RTS 2024/1772; the 14 field-level topics and their guidance as summarised.
  • Explicitly non-authoritative (the source’s own framing): the instructions are staff best-efforts guidance, not legal interpretation or the ESAs’ official stance, and are subject to regular revision — so the specific field practices are recommended conventions, not new legal obligations.
  • Not independently verified this run: the field numbering and thresholds are reproduced from this document and not cross-checked against the underlying ITS 2025/302 / RTS texts.

Topics this feeds

Open questions raised

  • Whether firms (not just competent authorities, the document’s direct addressees) will be expected to align their internal incident-reporting templates and controls to these conventions, and how supervisors will treat divergences.
  • How the “regularly updated” cadence will work in practice — i.e. whether later versions will materially change field expectations.
  • Whether the standardised TPP-origin field (2.8) will, over time, feed CTPP oversight and third-party-concentration analysis under DORA.