2024-10-23

Added · Updated

Commission Delegated Regulation (EU) 2025/301 on regulatory technical standards for major ICT-related incident notifications

The European Commission adopts regulatory technical standards specifying the content and time limits for financial entities to notify major ICT-related incidents and significant cyber threats. Financial entities must submit initial notifications within four hours of classifying an incident as major or within 24 hours of awareness, followed by intermediate reports within 72 hours and final reports within one month. The regulation mandates specific data points for initial, intermediate, and final reports, while defining limited content for voluntary notifications of significant cyber threats. These requirements apply to all financial entities under Regulation (EU) 2022/2554, with specific exclusions from weekend extensions for essential and important entities.

European Commission logo

European Union

European Commission

Scan of the document's first page
Share

Get EC alerts — same-day email on every new publication.

Read the rest free, and get an email when EC publishes again

Lineage: In force

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EC

We email you every new EC publication the day it's published.