2024-10-23
Added · Updated
The European Commission adopts regulatory technical standards specifying the content and time limits for financial entities to notify major ICT-related incidents and significant cyber threats. Financial entities must submit initial notifications within four hours of classifying an incident as major or within 24 hours of awareness, followed by intermediate reports within 72 hours and final reports within one month. The regulation mandates specific data points for initial, intermediate, and final reports, while defining limited content for voluntary notifications of significant cyber threats. These requirements apply to all financial entities under Regulation (EU) 2022/2554, with specific exclusions from weekend extensions for essential and important entities.
Get EC alerts — same-day email on every new publication.
Skip to main content
EUR-Lex
Access to European Union law
This document is an excerpt from the EUR-Lex website
You are here
EUROPA
EUR-Lex home
Delegated regulation - EU - 2025/301 - EN - EUR-Lex
Help
Quick search
Use quotation marks to search for an "exact phrase". Append an asterisk ( * ) to a search term to find variations of it (transp * , 32019R * ). Use a question mark ( ? ) instead of a single character in your search term to find variations of it (ca ? e finds case, cane, care).
Read the rest free, and get an email when EC publishes again
Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EC
We email you every new EC publication the day it's published.