2024-03-13
Added · Updated
The European Commission adopted Delegated Regulation (EU) 2024/1772 to supplement Regulation (EU) 2022/2554 by establishing regulatory technical standards for classifying ICT-related incidents and cyber threats. The regulation defines specific criteria for assessing client impact, reputational damage, service downtime, geographical spread, data losses, criticality of services, and economic impact. It sets materiality thresholds for determining major incidents, including a rule that two or more non-major incidents with the same root cause occurring at least twice within six months must be reported as a single major incident. These requirements apply to financial entities such as credit institutions, payment institutions, and electronic money institutions.
Get EC alerts — same-day email on every new publication.
Skip to main content
EUR-Lex
Access to European Union law
This document is an excerpt from the EUR-Lex website
You are here
EUROPA
EUR-Lex home
Delegated regulation - EU - 2024/1772 - EN - EUR-Lex
Help
Quick search
Use quotation marks to search for an "exact phrase". Append an asterisk ( * ) to a search term to find variations of it (transp * , 32019R * ). Use a question mark ( ? ) instead of a single character in your search term to find variations of it (ca ? e finds case, cane, care).
Read the rest free, and get an email when EC publishes again
Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EC
We email you every new EC publication the day it's published.