Documentation Index
Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
Use this file to discover all available pages before exploring further.
Overview
Matproof’s Incidents module manages the full lifecycle of ICT incidents under DORA — from initial detection through NCA notification, resolution, and post-incident review. Every incident you log generates linked evidence automatically.DORA incident reporting requirements
DORA mandates that financial entities report major ICT incidents to their competent authority (NCA) within strict deadlines:| Report type | Deadline | Trigger |
|---|---|---|
| Initial notification | 4 hours | Incident classified as major |
| Intermediate report | 72 hours | After initial notification |
| Final report | 1 month | After incident resolution |
What makes an incident “major”
DORA defines a major ICT incident by the following criteria. Matproof guides you through each one during classification:- Number of clients affected — threshold varies by entity type
- Duration — incidents exceeding defined downtime thresholds
- Geographic spread — impact across multiple member states
- Data loss — availability, integrity, or confidentiality impact
- Criticality of services — payment, trading, custody, or other critical functions affected
- Economic impact — financial loss to the entity or clients
Incident lifecycle
Every incident moves through five stages:Creating an incident
- Go to Incidents → New incident
- Fill in the detection details:
- Title — short description of the incident
- Detection date and time — when your team first became aware
- ICT systems affected — select from your registered assets
- Initial description — what is known at time of logging
- Save as draft — the incident is now in Detection stage
Classifying severity
After detection, classify the incident:- Open the incident → Classify
- Step through each DORA major incident criterion
- Matproof calculates a severity recommendation:
- Minor — below all major thresholds, internal handling only
- Significant — approaching thresholds, monitor closely
- Major — meets one or more DORA major criteria, NCA notification required
- Confirm the classification
Generating the NCA notification
For major incidents, generate the initial notification report directly from Matproof:- Open the incident → Generate report → Initial notification
- Review the pre-filled report — Matproof pulls in incident details, affected services, and classification rationale
- Add any additional context required by your NCA
- Export as PDF or submit via the NCA’s reporting portal
Report templates follow the DORA regulatory technical standards (RTS) format. You can customize the template under Settings → Incident reporting.
Logging resolution steps
As the incident progresses, document your response in the timeline:- Go to the incident → Timeline tab → Add entry
- Choose entry type: action taken, status update, escalation, or external communication
- Attach supporting files (runbooks, screenshots, logs)
Post-incident review
After resolution, DORA requires a post-incident analysis to identify root cause and prevent recurrence.- Open the incident → Post-incident review
- Complete the review fields:
- Root cause — what caused the incident
- Detection gap — why it was not caught earlier
- Response effectiveness — what worked, what did not
- Corrective actions — tasks to prevent recurrence (linked to your task tracker)
- Mark the review as complete
Evidence integration
Every incident automatically generates evidence records that attach to relevant DORA controls:- Incident log → evidence for DORA Art. 17 (ICT-related incident management)
- NCA notification report → evidence for DORA Art. 19 (reporting obligations)
- Post-incident review → evidence for DORA Art. 17 (lessons learned)
Risk Management
Link incident root causes to risks in your risk register
Evidence Collection
Understand how incident evidence maps to your controls