DORA Tells You to Classify the Incident. It Stops Before Telling You What It Cost.
The Digital Operational Resilience Act produces some of the most structured incident data a risk analyst could ask for, then declines to quantify any of it.
The Digital Operational Resilience Act, EU Regulation 2022/2554, has applied to in-scope financial entities since 17 January 2025. It was adopted in December 2022, and because it is a Regulation rather than a Directive it took effect in every member state with no national transposition step. For a compliance function it is a substantial programme: five chapters covering ICT risk management, incident classification and reporting, resilience testing, third-party risk, and information sharing.
The part that deserves a risk analyst’s attention is Article 18, the incident classification criteria. A financial entity must assess every ICT-related incident against six factors: the number of clients and counterparts affected, the duration, the geographic spread, the extent of data loss, whether critical or important functions were hit, and the economic impact, both direct and indirect. It is the closest thing DORA has to a loss taxonomy, and as a data schema it is genuinely good. Those six fields are close to what a quantitative risk practitioner would design if asked to structure incident records for later calibration of Loss Event Frequency and Loss Magnitude.
Where it stops
DORA specifies what must be assessed and disclosed. It does not specify how to quantify it. The Article 18 impact assessment is structural and largely qualitative. Even the numeric materiality thresholds, the lines that decide whether an incident counts as “major” and triggers mandatory regulator reporting, were not fixed in the Regulation text. They were delegated to joint regulatory technical standards from the European Supervisory Authorities, due to the Commission in early 2024.
The one place DORA comes close to a costing method is the Joint Guidelines JC 2024/34, issued in June 2024 and applying from 19 May 2025, which tell entities how to estimate the aggregated annual costs and losses of major incidents. The method is a three-step sequence: estimate gross costs and losses per incident, separately estimate recoveries such as insurance payouts per incident, then aggregate the two separately across all qualifying incidents so recoveries appear as an explicit offset rather than being netted away silently. Entities are told to base the figures on their actual accounting records first and fall back to estimation only where audited numbers are not available.
Compliance output as analytic input
That is a reporting procedure, not a risk model. It tells a regulator what last year cost. It does not tell the entity how much risk it carries going forward, or how much a given control investment would reduce that risk. Those are quantitative questions, and DORA is a compliance framework, not a quantitative one.
The practical move is to stop treating the Article 18 assessment as the end of the process. The six criteria, collected consistently over time and linked to each incident’s final-report reference code as the Guidelines require, are exactly the structured incident-to-loss mapping that voluntary industry surveys never provide. Feed them into a quantitative risk analysis: use the observed frequency of major incidents to calibrate Loss Event Frequency for a specific scenario, and the economic-impact and data-loss fields to calibrate Loss Magnitude distributions. The regulation has already compelled the organization to collect the raw material. Leaving it in the compliance file is the waste.
One caveat on scope. DORA covers the EU financial sector, so its incident data calibrates frequency and magnitude for financial entities specifically, not as a general cross-sector benchmark. The pattern generalises, though: wherever a regulator forces structured incident disclosure, that disclosure is a calibration dataset, and most organizations subject to one are not using it as such.