DORA Major ICT Incident Reporting

The DORA incident-reporting surface prepares major ICT-related incident classification output and signed handoff artifacts for customer/operator use. Stella provides deterministic classification, reporting timeline milestones, local report encoders, and filesystem handoff support; the financial-entity operator remains the reporting party.

This is a surface of the DORA Operational Resilience Pack.

Claim boundary: operator-support.

Source Docs

Runtime Boundary

Telemetry Core owns the deterministic seven-criteria classifier over frozen incident facts, tenant compliance profile values, and telemetry snapshots. Notify owns the shared timeline regime and the major-incident outbound filesystem handoff adapter. CLI owns offline classify, export, and verify commands over local inputs.

The default outcome is a signed, replayable operator handoff. Auto-submit is default-off and requires a tenant/channel authorization snapshot, fresh approval, and a configured delivery path. The connector does not call Authority directly and must fail closed if approval or readiness is missing.

Timeline

Runtime regime id: dora.

Target Assurance timeline profile id: dora.article19.incident.

MilestoneTimeline milestoneDue withinEvidence keys
Initial reportinitial_reportPT4H from opened eventincident_opened_event_ref, dora_major_incident_classification_ref
Intermediate reportintermediate_reportPT72H from opened eventincident_classified_event_ref, intermediate_report_bundle_ref, operator_approval_ref
Final reportfinal_reportP1M from opened eventfinal_report_bundle_ref, initial_report_payload_hash, intermediate_report_payload_hash, operator_approval_ref

The shared Notify runtime route is GET /api/v1/regulatory/reporting-timelines?regime=dora. The generic Assurance timeline profile endpoint must not report this profile as configured until dora.article19.incident is registered with readiness checks.

Handoff Artifacts

stella export dora-incident-report produces a deterministic variant directory containing:

Supported variants are initial, intermediate, and final.

stella verify dora-incident-report replays the manifest, artifact hashes, DSSE payload binding, and local HMAC signature offline. The local HMAC path is an offline tamper check. It is not a production CAdES/KMS signature or proof of regulator receipt.

Schema Status

The local encoder is pinned to dora-major-incident-report.v1 and local validation rule set dora-major-incident-report-local-validation-v1.

Official EBA schema validation is not finished by waiting for the abandoned eba-dora-incident-reporting-framework-4.3 asset. Engineering already re-verified that Framework 4.3 is the wrong asset for DORA major-incident reporting. To finish official taxonomy validation, follow the completion procedure: first decide whether a correct DORA-IR machine-validation package exists, then perform legal and asset intake, then wire Notify/CLI validation against local bytes only. Until that procedure lands, docs and UI must describe the output as a local-contract handoff, not a fileable official XBRL package.

Blocking Conditions

Do not treat a handoff as ready for filing when: