Security1 publisher2 min readPublished
DORA's four-hour notification clock begins the moment a bank calls an incident major
Year two of the EU's operational resilience rules moves the test from documented governance to demonstrated detection. The reporting deadline runs from the entity's own classification decision, and the evidence behind that call is the SOC's.
The Watch · Security desk

What happened
- DORA became enforceable across the European Union in January 2025, and the first year of compliance work was an administrative sprint for financial entities.
- That first year went on risk governance, third-party service provider assessments, contract clause updates and documented incident escalation workflows.
- The Hacker News says year two is about demonstrating how well those frameworks work, with EU regulators focused on implementation, ICT incident analysis and the effectiveness of ICT risk supervision.
- Article 9 requires entities to continuously monitor and manage the security and functioning of their ICT ecosystem and to run processes that minimise the impact of ICT risk.
- Article 10 requires swift detection of anomalous activity, including network performance issues, and thresholds for when incident response is triggered.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The gap a supervisor will ask about sits between systems: legacy infrastructure, specialized appliances, unmanaged devices and hosts with thin endpoint telemetry are where an entity has the least to show.
- decision Because the regulation leaves the security stack to the entity, each firm defends its year-two spend on its own evidence, and a supervisor comparing two banks is comparing two different answers.
- contradiction The urgency behind year two rests on one trade publication's reading of where supervision is heading, so a budget case built on it is quoting a vendor-adjacent article.
Classification starts the clock. Article 19's initial notification is due as early as possible and no later than four hours after an incident is classified as a major ICT-related incident [7]. Making that classification requires scope and impact, and the notification then carries the same findings [14]. The scoping work happens before the four hours begin [16].
What a responder has in hand at that point is mostly a description of the institution. An asset inventory lists the systems it owns or operates. Configuration records set out how those systems are meant to interact. Where hosts are monitored, logs and endpoint telemetry show activity [9].
The example the Hacker News piece gives is a payment routing application that normally communicates with an external credit assessment service and then starts communicating substantially more with unfamiliar internal hosts outside working hours, where network telemetry exposes the anomaly even though the application's own logs do not [11].
The correlation case is more ordinary. EDR flags a suspicious process, an identity system flags a suspicious login, and network data ties the two together by showing which systems communicated, which protocols they used, and what happened next [12]. Command-and-control traffic, reconnaissance, lateral movement and data transfers all leave traces in network traffic even when other telemetry is incomplete or unavailable [13].
The article's own answer is network detection and response, which it describes as a catalyst for bringing that detail together: baselines of normal behavior, with timing, volume and directionality weighed against them [18]. The regime entered its second year in January 2026, twelve months after it became enforceable [15].
What to watch
- A named EU supervisor publishing year-two DORA findings, or a first enforcement action under Article 9 or 10, would turn the article's reading into evidence.
- Any ESA change to the Article 19 timetable, including the event that triggers the initial-notification clock.
- A major ICT-related incident where a filed notification is challenged as late because the entity classified late.