Critical ICT incident reporting
What this control requires
All major ICT incidents impacting payment services, customer data or availability must be classified within 4 hours and reported under DORA timelines including initial, intermediate and final reports.
Other EU Instant Payments Regulation 2024 controls
EU_INSTANT_PAYMENTS_REG_2024-CTRL-001 - Daily safeguarding reconciliationEU_INSTANT_PAYMENTS_REG_2024-CTRL-003 - GDPR breach notification workflowEU_INSTANT_PAYMENTS_REG_2024-CTRL-004 - AML suspicious transaction monitoringEU_INSTANT_PAYMENTS_REG_2024-CTRL-005 - Quarterly PCI vulnerability assessmentEU_INSTANT_PAYMENTS_REG_2024-CTRL-006 - Outsourcing provider oversightEU_INSTANT_PAYMENTS_REG_2024-CTRL-007 - DORA Register of Information maintenanceEU_INSTANT_PAYMENTS_REG_2024-CTRL-008 - CTIF suspicious activity escalationEU_INSTANT_PAYMENTS_REG_2024-CTRL-009 - NIS2 cyber resilience testingEU_INSTANT_PAYMENTS_REG_2024-CTRL-010 - Instant payment availability monitoringIPR-001-001 - Instant Payments Capability ImplementationIPR-005-001 - Payee Verification (VOP) ControlsIPR-008-001 - Instant Payments Pricing Compliance