2025-02-20

Added · Updated

Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regulatory technical standards on major ICT-related incident notifications and significant cyber threat reports

Financial entities are required to include specific general, initial, intermediate, and final report information when notifying major ICT-related incidents under Regulation (EU) 2022/2554. Initial notifications must be submitted within four hours of major classification or 24 hours of knowledge, intermediate reports within 72 hours of the initial notification, and final reports within one month of the intermediate report. Voluntary notifications for significant cyber threats must also contain specified details regarding detection, potential impact, and mitigation measures. The regulation applies to credit institutions, central counterparties, trading platform operators, and other financial entities classified as essential or important.

European Commission logo

European Union

European Commission

Click to view full text

More like this from EC

We email you every new EC publication the day it's published.

Topics
Share