Calculator · DORA / 2025/301

DEADLINES FOR REPORTING AN INCIDENT UNDER DORA

The tool calculates deadlines for the initial notification, the intermediate and final report under Regulation 2025/301 — including who gets no weekend deferral.

First we check whether the incident is major at all against the materiality thresholds in Regulation (EU) 2024/1772 — if it is not, there is nothing to report and the tool stops. If it is major, we establish the type of entity (the weekend deferral depends on it) and calculate all three deadlines from the moment you became aware.

The deadlines are calculated in Europe/Prague time, including the switch to summer time and Czech public holidays under Act No. 245/2000 Coll. The full result is shown free of charge and nobody asks you for an email address.

An orientation aid, not a legal assessment This tool is an orientation aid, not a legal assessment or a position of the supervisory authority. Both the classification of the incident and the running of the deadlines depend on facts the calculator cannot know — when exactly you became aware of the incident and what that means in your documentation, which services were really affected, and whether the competent authority has decided anything about you individually. Borderline cases have to be assessed one by one. Every output states the provision it is based on, so you can verify it against the original text — the links are in the section of official sources.
1Severity
2Type of entity
3Times
4Deadlines

Is the incident major at all?

Only a major incident is reported. The criteria are not in DORA itself but in Delegated Regulation (EU) 2024/1772 — its Article 8(1) combines the condition of critical services affected with a further test, and Article 9(1) to (6) sets out six materiality thresholds, one for each criterion.

A — criticality of the services affected

Unless at least one of these conditions is met, the incident is not major, even if the thresholds below are. Tick everything that applies.

B — malicious access with data losses

This condition is enough on its own — it is the materiality threshold in Article 9(5), point (b), which Article 8(1), point (a) refers to separately. Where it is met together with point A, the incident is major and the thresholds below are not counted.

C — materiality thresholds

Tick the conditions that are met in your case. Mind that Article 8(1), point (b) counts the thresholds referred to in Article 9(1) to (6), and one paragraph is one threshold even if several conditions inside it are met — which is why they are grouped, and the groups match the paragraphs of Article 9 in the order 1 to 6. An incident is major where two or more thresholds are met.

Clients, financial counterparts and transactions

Reputational impact

Duration and service downtime

Geographical spread

Data losses

Economic impact

If none of the above applies

Tick this only if you really have gone through points A to C and none of them applies — the tool will then take you to the result. Ticking it clears every choice above; conversely, any choice above clears this box.

What kind of financial entity are you?

One single but decisive thing depends on the type of entity: whether a deadline falling on a weekend or a public holiday is deferred for you. For some entities it is not, and both the four-hour and the twenty-four-hour limit run through Saturday night.

Type of entity

Choose what you are under Article 2(1) of DORA. This is not about size, nor about whether you are under the simplified framework of Article 16 — that has no effect on reporting deadlines.

Are you at the same time a regulated entity under Act No. 264/2025 Coll. — that is, entered in the NÚKIB register under the regime of higher or lower obligations?

Article 5(5) of Regulation 2025/301 also excludes the deferral for financial entities that are essential or important entities under Article 3 of the NIS2 Directive. In the Czech Republic that is Act No. 264/2025 Coll.; what decides is the entry in the NÚKIB register, not your impression. If you are not sure, choose "Not sure" — you will get the stricter variant.

Has the competent authority — in the Czech Republic the Czech National Bank — told you that the weekend deferral does not apply to you?

Article 5(6) allows the competent authority to switch the deferral off for other entities as well, where it considers them significant or systemic. Such a decision applies only to incidents reported after the authority has told you about it.

When did you become aware of the incident?

Enter the times in local time (Europe/Prague). The tool handles the switch to summer and winter time itself and counts the hourly limits as hours actually elapsed.

The outer limit of 24 hours for the initial notification runs from this moment.

The four-hour limit runs from the classification and it is usually the stricter one. If you leave it out, the tool shows only the outer limit of 24 hours — which may be too optimistic.

Have you already submitted anything? It sharpens the other two deadlines

The intermediate report runs from the submission of the initial notification, the final report from the submission of the intermediate one. Submit them earlier than at the last minute and the later deadlines move too — earlier, not later.

An indicative output. It does not replace a legal assessment or a position of the supervisory authority — in borderline cases ask for an individual assessment.

I have more questions

Common questions on DORA — from when it applies, when an incident is major, how and to whom it is reported in the Czech Republic, what an addendum under Article 30 means and how DORA meets the Czech Cybersecurity Act.

Open the FAQ

Guide to the regulation

The system of the regulation from the top: who falls within the scope, how the obligations of a financial entity differ from those of an ICT provider, resilience testing and the register of information.

Open the guide

Everything on DORA

The hub of the category. Where the paths to scope, incident reporting, the register of information and the accompanying technical standards start.

Open the overview

Official sources

Every deadline and every statement about an obligation above comes from one of these sources. For the authoritative wording, always go to them — this page is indicative and does not reproduce the text of the legislation.

Delegated Regulation (EU) 2025/301 ↗ The source of all three deadlines. Article 5(1) the time limits, (2) later classification, (3) notice that a limit will not be met, (4) the deferral to noon of the next working day, (5) the exclusion of the deferral for credit institutions, central counterparties, operators of trading venues and entities under NIS2, (6) the extension of that exclusion by a decision of the competent authority. Delegated Regulation (EU) 2024/1772 ↗ The severity test in the first step. Articles 1 to 5 and 7 define the individual criteria, Article 6 the criticality of the services affected, Article 8(1) the conditions under which an incident is major — referring to the threshold in Article 9(5), point (b) and to two or more of the other thresholds referred to in Article 9(1) to (6). Article 9 sets the materiality thresholds, one paragraph per criterion; paragraph 1 carries clients, financial counterparts and transactions together. Regulation (EU) 2022/2554 (DORA) ↗ The base text. Article 19 the reporting of major incidents, paragraph 3 informing clients, paragraph 5 outsourcing the reporting. The scope and the list of financial entities are in Article 2. Implementing Regulation (EU) 2025/302 ↗ The content of the reports. Standard forms, templates and procedures for reporting a major incident and for notifying a significant cyber threat. Directive (EU) 2022/2555 (NIS2) ↗ Article 3 is the reference used in the exclusion from the weekend deferral — it distinguishes essential and important entities. Act No. 264/2025 Coll. in the e-Sbírka (in Czech) ↗ The Czech transposition of NIS2. It decides whether you are a regulated entity under the regime of higher or lower obligations — and with it the answer to the second question in the step about the type of entity. Act No. 31/2025 Coll. in the e-Sbírka (in Czech) ↗ The Act on the digitalisation of the financial market. The Czech National Bank as the competent authority under DORA is in Section 9; the offences for breaching the duty to report major incidents start at Section 18. Czech National Bank — DORA reporting in the SDAT system (in Czech) ↗ How reports are filed in the Czech Republic. The return for reporting a major incident, registration in SDAT and the requirement for an LEI code. Act No. 245/2000 Coll. in the e-Sbírka (in Czech) ↗ The source of the list of non-working days the tool works with: public holidays, other holidays and the movable Easter holidays. Regulation 2025/301 speaks of a bank holiday in the Member State — for the Czech Republic we take it from here. Regulation (EEC, Euratom) No 1182/71 on time limits ↗ The general rules for calculating periods in acts of the Union. We use them for two things only: hourly limits run continuously, and a monthly limit ends on the same date of the following month, or on its last day. The weekend rule of that regulation does not apply here — Article 5(4) and (5) of Regulation 2025/301 has its own, different arrangement.
Content valid as of 8 August 2026

Where we can help

A document will not meet the deadline,
an on-call rota will.

The four-hour limit from classification cannot be met by a policy in a binder. We will set up the classification and reporting process so that on Saturday night there is a person with the authority to decide, a pre-filled return and a clear escalation path — and we will test it before it goes live.