2024-03-13

Added · Updated

Commission Delegated Regulation (EU) 2024/1772 on ICT incident classification and reporting standards

The European Commission adopted Delegated Regulation (EU) 2024/1772 to supplement Regulation (EU) 2022/2554 by establishing regulatory technical standards for classifying ICT-related incidents and cyber threats. The regulation defines specific criteria for assessing client impact, reputational damage, service downtime, geographical spread, data losses, criticality of services, and economic impact. It sets materiality thresholds for determining major incidents, including a rule that two or more non-major incidents with the same root cause occurring at least twice within six months must be reported as a single major incident. These requirements apply to financial entities such as credit institutions, payment institutions, and electronic money institutions.

European Commission logo

European Union

European Commission

Click to view full text