Skip to main content
Free DORA Toolkit

DORA Compliance:
Incident Classification Matrix

A practical toolkit for classifying ICT incidents, assessing severity, and documenting reporting decisions under DORA.

  • Incident classification methodology
  • Severity assessment framework
  • Classification matrix and decision worksheet
  • Audit evidence and documentation record
The Challenge

Most plans explain how to respond. Few explain how to classify.

DORA requires organizations to assess ICT incidents, determine severity, and document reporting decisions — consistently, and in a way that stands up to an audit.

Classification challenges
  • Different severity decisions across teams
  • Unclear reporting obligations
  • Missing classification rationale
  • Scattered evidence
  • Manual audit preparation
Structured classification approach
  • Consistent assessment criteria
  • Defined evaluation process
  • Documented decision record
  • Audit-ready documentation
  • Centralised classification records
Toolkit contents

What's inside the DORA Incident Classification Toolkit

Move beyond individual judgment and apply the same assessment process across teams — with templates your team can actually use and documentation that is easier to defend.

Methodology

A practical way to classify ICT incidents

Move beyond individual judgment and apply the same assessment process across security, IT, risk, and compliance teams.

Framework

A framework for severity decisions

Understand what should be considered — customer, service, operational, data, financial, and third-party impact — before assigning a severity level.

Templates

Templates your team can actually use

Record classification decisions, reporting obligations, and supporting rationale in a consistent, repeatable format.

Evidence

Documentation that is easier to defend

Keep evidence and records organized so classification and reporting decisions hold up during audits and regulatory reviews.

Download the DORA Incident Classification Matrix

A practical toolkit for assessing ICT incidents, documenting severity decisions, and maintaining audit-ready records.

Download the toolkit
Why it matters under DORA

What DORA expects from financial entities

Incident classification affects reporting decisions, audit readiness, and how consistently incidents are handled across the organization — not just because DORA says so.

1
Identify
ICT-related incidents as they occur across the environment.
2
Classify
Their severity and impact using consistent, documented criteria.
3
Report
Major ICT incidents to regulators when reporting thresholds apply.
4
Document
Decisions and supporting evidence for audits and reviews.

Need a second opinion on your incident classification process?

Q-Sec helps financial institutions review incident classification procedures, reporting workflows, and audit readiness under DORA.

Talk to a Q-Sec expert
FAQ

DORA compliance questions, answered

DORA compliance means meeting the requirements of the Digital Operational Resilience Act, including ICT risk management, incident reporting, operational resilience, and third-party risk management for financial entities operating in the EU.
Yes. DORA requires organizations to assess ICT-related incidents, determine their severity and impact, and maintain documentation supporting classification and reporting decisions.
A major ICT incident is an event that significantly affects customers, critical services, business operations, or financial stability and may trigger regulatory reporting obligations.
A DORA incident classification matrix should help teams assess impact, assign severity levels, evaluate reporting obligations, document ownership, and record the rationale behind classification decisions.
Teams should document the assessment criteria used, severity assigned, supporting evidence reviewed, reporting decisions made, and the individuals responsible for approving the classification.
The toolkit is designed for CISOs, security managers, risk teams, compliance professionals, operational resilience leaders, and IT teams responsible for DORA compliance and ICT incident management.