2024-10-23

Added · Updated

Commission Delegated Regulation (EU) 2025/301 on regulatory technical standards for major ICT-related incident notifications

The European Commission adopts regulatory technical standards specifying the content and time limits for financial entities to notify major ICT-related incidents and significant cyber threats. Financial entities must submit initial notifications within four hours of classifying an incident as major or within 24 hours of awareness, followed by intermediate reports within 72 hours and final reports within one month. The regulation mandates specific data points for initial, intermediate, and final reports, while defining limited content for voluntary notifications of significant cyber threats. These requirements apply to all financial entities under Regulation (EU) 2022/2554, with specific exclusions from weekend extensions for essential and important entities.

European Commission logo

European Union

European Commission

Click to view full text