2025-03-03

Added · Updated

Commission Delegated and Implementing Regulations under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector Published in the EU Official Journal (Update 3)

The Malta Financial Services Authority published an update regarding Commission Delegated and Implementing Regulations under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector. This document serves as a notification that these specific regulations have been published in the EU Official Journal. It provides a reference point for financial entities to access the latest regulatory requirements concerning digital operational resilience.

Source: Malta Financial Services Authority — original document

Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

Malta Financial Services Authority logo

Malta

Malta Financial Services Authority

Click to view full text

Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Commission Delegated and Implementing Regulations under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector Published in the EU Official Journal (Update 3) This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. As detailed by the latter circular, Regulation (EU) 2022/2554 (“the Regulation”) is to be supplemented by, inter alia, a series of Technical Standards and Guidelines. Following an interinstitutional drafting process by the European Supervisory Authorities (”ESAs”), the following were adopted and have now been published in the EU Official Journal:

  1. Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT￾related incidents, and the content of the voluntary notification for significant cyber threats (access here);
  2. Commission Delegated Regulation (EU) 2025/295 of 24 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities (access here); and
  3. Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat (access here). 3 March 2025

Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt In addition, the European Supervisory Authorities have published a Report on the feasibility of further centralisation in the reporting of major ICT-related incidents in accordance with Article 21 of the Regulation (access here). The remaining Technical Standards are expected to be adopted and published in the EU Official Journal in due course. Authorised Persons may request further information by sending an email to the Supervisory ICT Risk and Cybersecurity function on sirc@mfsa.mt.