OpenChainGraph Suite · ART-09 · DORA Incident Classifier
v1.0.0

DORA Major-Incident Reporting Classifier

Enter your ICT incident parameters and get an immediate major/non-major determination under DORA Articles 19–23, every qualifying criterion enumerated, and a full reporting clock — 4-hour initial notification, 72-hour intermediate, 1-month final. Deterministic. Client-side. Chains into PTG-01 to generate a regulator-ready submission draft.

AP2 Export Chains: PTG-01 DORA Art. 19–23 Zero PII Client-Side · Deterministic
🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data — use synthetic or anonymised inputs only.
Educational/indicative only. Classification thresholds are based on DORA (Regulation (EU) 2022/2554) Articles 18–23 and the ESA Joint RTS on the classification of major ICT-related incidents (published January 2025). Thresholds vary by entity type, function criticality, and competent authority guidance. This tool is for pre-assessment and training purposes. Verify all determinations with your compliance function and competent authority before submitting formal notifications. All regulatory citations are real and sourced — do not rely on this output as a substitute for legal advice.
Incident parameters
Timing
When was the incident first detected?
When classified as (potentially) major? Leave blank = same as detection.
Leave blank if ongoing. Used to compute final report deadline.
Total minutes of service disruption. Enter 0 if service remained available (e.g. data breach with no outage).
Impact parameters
Number of clients affected or at risk
Your entity's total clients
Total value of transactions impacted. Enter 0 if not applicable.
Number of EU member states where clients or operations are affected (1–27)
Qualitative flags
Data loss — confidentiality, integrity, or availability of data breached?
DORA Art. 23(1)(c) — any confirmed loss of data confidentiality, integrity, or availability triggers major classification
Critical or important function affected?
DORA Art. 23(1)(a) — functions critical or important per your operational resilience framework
Cross-border component — does the incident involve cross-border payments or operations across ≥2 member states?
Relevant to geographic-spread criterion and competent authority coordination
Third-party ICT provider involved?
Determines whether Oversight Framework provisions under DORA Chap. V apply to a critical third-party ICT provider
Classification criteria (DORA Art. 23 + ESA Joint RTS)
Reporting clock (DORA Art. 19–20)
Competent authority & notification
Chain to PTG-01 — Generate regulatory submission draft
→ Open in PTG-01 Export the artifact below, then paste it into PTG-01 to generate a DORA Art. 19/20 submission draft