Calculator · DORA / 2025/301
The tool calculates deadlines for the initial notification, the intermediate and final report under Regulation 2025/301 — including who gets no weekend deferral.
First we check whether the incident is major at all against the materiality thresholds in Regulation (EU) 2024/1772 — if it is not, there is nothing to report and the tool stops. If it is major, we establish the type of entity (the weekend deferral depends on it) and calculate all three deadlines from the moment you became aware.
The deadlines are calculated in Europe/Prague time, including the switch to summer time and Czech public holidays under Act No. 245/2000 Coll. The full result is shown free of charge and nobody asks you for an email address.
Only a major incident is reported. The criteria are not in DORA itself but in Delegated Regulation (EU) 2024/1772 — its Article 8(1) combines the condition of critical services affected with a further test, and Article 9(1) to (6) sets out six materiality thresholds, one for each criterion.
Unless at least one of these conditions is met, the incident is not major, even if the thresholds below are. Tick everything that applies.
This condition is enough on its own — it is the materiality threshold in Article 9(5), point (b), which Article 8(1), point (a) refers to separately. Where it is met together with point A, the incident is major and the thresholds below are not counted.
Tick the conditions that are met in your case. Mind that Article 8(1), point (b) counts the thresholds referred to in Article 9(1) to (6), and one paragraph is one threshold even if several conditions inside it are met — which is why they are grouped, and the groups match the paragraphs of Article 9 in the order 1 to 6. An incident is major where two or more thresholds are met.
Clients, financial counterparts and transactions
Reputational impact
Duration and service downtime
Geographical spread
Data losses
Economic impact
Tick this only if you really have gone through points A to C and none of them applies — the tool will then take you to the result. Ticking it clears every choice above; conversely, any choice above clears this box.
One single but decisive thing depends on the type of entity: whether a deadline falling on a weekend or a public holiday is deferred for you. For some entities it is not, and both the four-hour and the twenty-four-hour limit run through Saturday night.
Choose what you are under Article 2(1) of DORA. This is not about size, nor about whether you are under the simplified framework of Article 16 — that has no effect on reporting deadlines.
Article 5(5) of Regulation 2025/301 also excludes the deferral for financial entities that are essential or important entities under Article 3 of the NIS2 Directive. In the Czech Republic that is Act No. 264/2025 Coll.; what decides is the entry in the NÚKIB register, not your impression. If you are not sure, choose "Not sure" — you will get the stricter variant.
Article 5(6) allows the competent authority to switch the deferral off for other entities as well, where it considers them significant or systemic. Such a decision applies only to incidents reported after the authority has told you about it.
Enter the times in local time (Europe/Prague). The tool handles the switch to summer and winter time itself and counts the hourly limits as hours actually elapsed.
The outer limit of 24 hours for the initial notification runs from this moment.
The four-hour limit runs from the classification and it is usually the stricter one. If you leave it out, the tool shows only the outer limit of 24 hours — which may be too optimistic.
The intermediate report runs from the submission of the initial notification, the final report from the submission of the intermediate one. Submit them earlier than at the last minute and the later deadlines move too — earlier, not later.
CypherOn provides cybersecurity consulting services and is not a law firm. For legal opinions, turn to an attorney registered with the Czech Bar Association.
Common questions on DORA — from when it applies, when an incident is major, how and to whom it is reported in the Czech Republic, what an addendum under Article 30 means and how DORA meets the Czech Cybersecurity Act.
Open the FAQThe system of the regulation from the top: who falls within the scope, how the obligations of a financial entity differ from those of an ICT provider, resilience testing and the register of information.
Open the guideThe hub of the category. Where the paths to scope, incident reporting, the register of information and the accompanying technical standards start.
Open the overviewEvery deadline and every statement about an obligation above comes from one of these sources. For the authoritative wording, always go to them — this page is indicative and does not reproduce the text of the legislation.
Where we can help
The four-hour limit from classification cannot be met by a policy in a binder. We will set up the classification and reporting process so that on Saturday night there is a person with the authority to decide, a pre-filled return and a clear escalation path — and we will test it before it goes live.