Menu

DORA Incident Reporting for Insurance Companies: Requirements & Key Criteria

DORA Incident Reporting for Insurance Companies: Requirements & Key Criteria

An insurance company can have strong cybersecurity controls and still face a difficult regulatory question when an ICT incident occurs: Is this incident major enough to report, and how quickly does the clock start? For insurers operating across Europe, this question has become more important since the Digital Operational Resilience Act (DORA) became applicable on 17 January 2025. DORA establishes harmonized requirements for managing, classifying, and reporting ICT-related incidents across the financial sector, including insurance and reinsurance undertakings.

The challenge is that incident reporting cannot wait until every detail is known. Insurance companies may need to classify an incident while its impact is still developing, determine whether it meets DORA's thresholds, and submit an initial notification within a defined timeframe. Understanding DORA Incident Reporting for Insurance Companies therefore requires looking beyond cybersecurity itself and considering classification, reporting timelines, regulatory communication, and third-party ICT dependencies.

What Is DORA Incident Reporting?

DORA requires financial entities to report major ICT-related incidents to the relevant competent authority. The regulation also establishes a framework for voluntarily notifying significant cyber threats. The objective is to create a more consistent approach to ICT incident reporting across Europe's financial sector and give supervisory authorities the information needed to understand the significance and potential cross-border effects of major incidents.

This means ICT-related incident reporting under DORA is not simply another version of an internal incident ticket. It is a regulatory process that requires an organization to determine whether an ICT incident qualifies as major, collect relevant information, and communicate that information through the prescribed reporting process.

For insurers, this can include incidents affecting systems that support important insurance activities, customer-facing services, data, or other technology dependencies. The focus is therefore not only on whether a cyberattack occurred, but on what the incident means for the insurer's operations, customers, services, and resilience.

Does DORA Apply to Insurance Companies?

Yes, DORA specifically includes insurance and reinsurance undertakings within its scope, subject to the exemptions set out in the regulation. Insurance intermediaries and certain other insurance-related entities are also addressed within the framework, with specific exclusions applying to certain smaller entities.  DORA became applicable across the EU on 17 January 2025 and is designed to ensure that financial entities can withstand, respond to, and recover from ICT disruptions such as cyberattacks and system failures.  For an insurance company, this matters because modern insurance operations depend on interconnected technology. Policy administration, claims processing, customer portals, payment systems, cloud platforms, data environments, communication systems, and outsourced ICT services can all play a role in delivering critical services. As a result, DORA incident reporting obligations for insurance companies need to be considered as part of the broader operational resilience framework rather than as an isolated compliance activity.

Make your DORA compliance independently verifiable with INTERCERT’s assessment services. Connect with our DORA experts.

What Counts as a Major ICT-Related Incident Under DORA?

One of the most important points for insurers is that not every ICT incident automatically becomes a major ICT-related incident. DORA's regulatory technical standards establish classification criteria and materiality thresholds for determining whether an incident is major. The framework considers factors including affected clients and financial counterparts, transactions, reputational impact, duration and service downtime, geographical spread, data losses, and economic impact.

For example, the classification thresholds include an incident affecting more than 10% of clients using the affected service, certain transaction thresholds, an incident lasting more than 24 hours, or service downtime exceeding two hours for ICT services supporting critical or important functions. An incident affecting two or more Member States can also meet the geographical-spread threshold. The classification process is particularly important for insurers because the impact of an incident may not be immediately clear. A system outage that initially appears limited could later affect customers, claims processing, or services across several European markets.

DORA also addresses recurring incidents. Certain incidents that individually would not qualify as major may need to be assessed collectively when they occur repeatedly, have the same apparent root cause, and together meet the relevant conditions. This makes DORA major incident reporting for insurers a process that requires ongoing assessment rather than a simple yes-or-no decision made at the beginning of an incident.

What Is the DORA Incident Reporting Timeline?

Once an ICT incident is classified as major, the reporting process moves quickly. Under Commission Delegated Regulation (EU) 2025/301, insurers and other financial entities must submit an initial notification as early as possible, within four hours of classifying the incident as major, and no later than 24 hours after becoming aware of the incident.

The process then continues with an intermediate report, which must be submitted within 72 hours of the initial notification. This report may need to be updated as the situation develops and when regular activities are recovered. The final report must be submitted within one month after the intermediate report or the latest updated intermediate report.

If an insurer cannot meet a reporting deadline, it must inform the competent authority without undue delay and explain the reason for the delay. This timeline highlights an important operational reality: the regulatory clock can run while the incident is still unfolding. Insurance companies therefore need established processes for classification, escalation, information gathering, and regulatory communication before a major incident occurs.

What Information Must Insurers Include in a DORA Incident Report?

A DORA incident report is not necessarily completed with every known detail at the moment an incident is first reported. Instead, the reporting process develops as the insurer investigates the incident and more information becomes available. Each stage provides the competent authority with a more complete understanding of what happened, its impact, and how the organization is responding.

Initial Notification

The initial notification gives the competent authority the information needed to understand the nature and significance of the major ICT-related incident. This can include details such as when the incident was detected and classified, the affected services, the impact on the organization, the geographical scope, and other relevant information available at the time. The initial report is therefore focused on providing timely and useful information rather than waiting for the investigation to be fully completed. This makes accurate incident records particularly important. Detection time, classification time, affected systems and services, initial impact, and other key events should be recorded consistently. When these details are already captured through established incident management processes, insurers can prepare the initial notification without having to reconstruct the timeline while the incident is still unfolding.

Intermediate Report

The intermediate report provides a more developed view of the incident as the investigation progresses. By this stage, the insurer may have more information about affected business processes and infrastructure, customer or financial impact, the nature of the threat, recovery activities, and other relevant factors. Instead of treating the intermediate report as a completely separate submission, insurers should view it as an updated picture of the same incident. As new information becomes available, the report gives the competent authority greater visibility into the incident's development and the measures being taken to manage its effects.

Final Report

The final report provides the most complete account of the incident after the situation has progressed further. It can capture information that was unavailable during the initial and intermediate reporting stages, including the final impact, resolution, recovery, and other relevant details. For insurers, this means DORA incident reporting should be treated as an evolving information process rather than a single form completed once. The ability to move from an initial notification to progressively more detailed reporting depends on having reliable incident records, clear responsibilities, and processes that allow relevant information to be gathered and updated as the situation develops.

How Do Third-Party ICT Providers Affect DORA Reporting?

Insurance companies increasingly depend on cloud platforms, software providers, managed services, data providers, and other ICT third parties. This creates another layer of complexity when an incident occurs. An outage or security incident originating with a technology provider may still have consequences for the insurer's own critical services. The insurer therefore needs to understand how third-party incidents affect its systems, customers, business processes, and regulatory obligations.

This is relevant to DORA cyber incident reporting insurance sector requirements because the source of an incident and its impact are not necessarily the same thing. An incident may originate outside the insurer but still disrupt an insurance service or affect customers within the insurer's environment. The DORA incident-reporting framework also requires reporting information concerning whether a major ICT-related incident originated from a third-party provider or another financial entity. The practical lesson is straightforward: an insurer cannot assume that an incident is solely the technology provider's responsibility simply because the provider's infrastructure was involved.

Common DORA Incident Reporting Challenges for Insurance Companies

Meeting DORA’s incident reporting requirements involves more than submitting reports within the required deadlines. Insurance companies must make classification decisions quickly, bring together information from different teams, and maintain a consistent view of the incident as new facts emerge.

Determining Whether an Incident Is Major

Classification is often one of the first challenges an insurer faces. The organization must evaluate the incident against DORA’s classification criteria, even when the full scope and impact may not yet be clear. This can make early decisions difficult, particularly when an incident is still developing. Clearly defined classification criteria, escalation procedures, and decision-making responsibilities can make the process more consistent.

Gathering Information Under Pressure

During a major ICT incident, important information may be spread across technical teams, business functions, legal and compliance teams, and senior management. Each group may have visibility into a different part of the incident, making it difficult to build a complete picture quickly. Established processes for recording, validating, and sharing incident information can reduce delays and provide a clearer basis for regulatory reporting.

Managing Cross-Border Impact

Insurance groups operating across Europe may have systems, customers, business services, and ICT dependencies spanning multiple Member States. Since DORA’s classification framework considers geographical spread when determining the significance of an incident, insurers need to understand where an incident has affected their operations and services.

Coordinating With ICT Providers

An insurer may rely on an ICT third party to investigate the cause of an incident, determine its scope, or provide information about recovery. However, dependence on a third party does not remove the need for the insurer to meet its own reporting obligations. Clear communication channels, defined responsibilities, and appropriate contractual arrangements can make it easier to obtain critical information within the required reporting timeframe.

Keeping Reports Consistent

The initial, intermediate, and final reports are prepared at different stages of the same incident. As the investigation develops, some information may change, while other details may become more precise. Insurers therefore need a controlled process for updating incident information so that subsequent reports remain consistent with earlier submissions while accurately reflecting what is now known.

How Can Insurance Companies Prepare for DORA Incident Reporting?

Preparation should begin well before a major ICT incident occurs. A reporting process that works under pressure depends on clear responsibilities, reliable information, and an accurate understanding of the systems and services involved.

Establish Clear Classification and Escalation Procedures

Insurance companies should define how ICT incidents are identified, assessed, escalated, and classified. Teams should know who is responsible for evaluating an incident, who determines whether it may meet the criteria for a major incident, and who is responsible for regulatory communication. Clearly defined roles can reduce delays when decisions need to be made quickly.

Map Critical Services and ICT Dependencies

Insurers should maintain a clear view of the applications, infrastructure, data, and ICT third parties that support their critical services and important business activities. This visibility can make it easier to determine the scope of an incident and understand how disruption to one system may affect connected services or operations.

Establish a Process for Gathering Reporting Information

Reporting depends on having timely and reliable information. Insurers should establish processes for capturing details such as detection and classification times, affected services, customer impact, geographical spread, service downtime, data impact, and potential economic consequences. Having these records readily available reduces the need to reconstruct key facts while an incident is still unfolding.

Test the Reporting Process Through Exercises

A documented process should also be tested in practice. Tabletop exercises and incident simulations can help insurers determine whether teams can classify incidents, gather relevant information, coordinate with ICT providers, escalate decisions, and prepare regulatory communications within the required timeframes. These exercises can also expose gaps in responsibilities or information flows before a real incident puts the process under pressure.

What Should Insurance Companies Remember About DORA Incident Reporting?

The key point is that DORA incident reporting is closely connected to digital operational resilience. The regulation does not simply ask whether an insurer experienced a cyber incident. It establishes a structured approach for determining which incidents are major, what impact they have, and how that information should reach the relevant competent authority. The importance of this framework is becoming clearer across Europe. In June 2026, the European Supervisory Authorities published their first annual overview of major ICT-related incidents reported under DORA. The report highlighted that ICT risks are increasingly borderless and interconnected, reinforcing the importance of coordinated incident reporting across the financial sector. For insurance companies, effective reporting therefore depends on more than knowing the deadlines. It requires visibility into critical services, clear classification criteria, reliable incident information, defined responsibilities, and coordination across internal teams and ICT providers.

From DORA Requirements to Operational Resilience

DORA has changed the way insurance companies must approach ICT incidents. A major incident is no longer only a cybersecurity or operational issue; it can trigger a defined regulatory reporting process with specific classification criteria, reporting timelines, and information requirements. For insurers operating across Europe, having the right processes in place to identify, classify, document, and report ICT-related incidents is now an important part of digital operational resilience.

This is where INTERCERT’s DORA services can provide an independent perspective on an organization’s approach to the regulation. As an independent third-party certification body, INTERCERT brings an impartial assessment approach to DORA-related requirements, with experienced auditors and a focus on internationally recognized certification and assessment practices.

For insurance companies, DORA readiness is ultimately about more than responding quickly after an incident occurs. It is about having the governance, processes, responsibilities, and reporting mechanisms in place before the reporting clock starts.

 

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved