DORA ICT Incident Reporting — Article 19 + classification RTS

DORA ICT Incident Reporting — Article 19 + classification RTS — 100% of in-scope requirements covered.

4 requirements · 3 in scope (3 enforced) · 1 out-of-scope (outside KYE™’s authority layer). The 100% is weighted over the in-scope base.

Source: The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires financial entities to detect, manage, classify, and report major ICT-related incidents to competent authorities (Article 19), on a staged initial / intermediate / final report timeline, with root-cause analysis. KYE Protocol™ governs whether an AI-assisted containment action / incident classification / disclosure-timing decision under DORA may PROCEED to a consequential incident action — under a named accountable officer's authority, with chain-of-custody recorded for incident evidence, with a signed Evidence Pack™, and a contestability record so the decision can be reconstructed and challenged. KYE™ does not detect the threat, run the SIEM/EDR, perform forensics, or determine the technical response. · License: DORA is an EU legislative act published in the Official Journal of the European Union; KYE™ registry paraphrases each requirement's intent and cites the official article identifier for mapping purposes only.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Named-authority on the containment / response action11000100%
Incident-evidence chain-of-custody & report integrity11000100%
Disclosure-timing authority on the staged reporting clock11000100%
Threat detection, forensics & remediation engineering100000%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
dora-ict-incident.containment-action-authorityAn AI-assisted containment / response action proceeds only under a recorded named-authority decisionenforcedaudit_events: kye.purpose.request.v1, kye.purpose.admissibility.v1, kye.evidence.decision_map.v1
engines: internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
dictionaries: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
dora-ict-incident.incident-evidence-integrityIncident evidence proceeds only with a recorded chain-of-custody and integrity recordenforcedaudit_events: kye.evidence.decision_map.v1, kye.evidence.pack.v1
engines: internal
rule_packs: kye:rule-pack:cyber-resilience-incident
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora-ict-incident.staged-report-timing-authorityDisclosure-timing on the staged reporting clock proceeds only under a recorded named-authority decision, contestable in a post-incident inquiryenforcedaudit_events: kye.purpose.admissibility.v1, kye.evidence.pack.v1, kye.replay.context_seal.v1, kye.replay.proof.v1
engines: internal, internal, internal
rule_packs: kye:rule-pack:cyber-resilience-incident
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.md
dora-ict-incident.threat-detection-forensics-remediationThreat detection, forensics, and remediation engineeringout-of-scope(no enforcement cited)

Canonical KYE™ surfaces referenced on this page: Evidence Pack™ · KYE Protocol™.