2025-02-20

Added · Updated

Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regulatory technical standards on major ICT-related incident notifications and significant cyber threat reports

Financial entities are required to include specific general, initial, intermediate, and final report information when notifying major ICT-related incidents under Regulation (EU) 2022/2554. Initial notifications must be submitted within four hours of major classification or 24 hours of knowledge, intermediate reports within 72 hours of the initial notification, and final reports within one month of the intermediate report. Voluntary notifications for significant cyber threats must also contain specified details regarding detection, potential impact, and mitigation measures. The regulation applies to credit institutions, central counterparties, trading platform operators, and other financial entities classified as essential or important.

European Commission logo

European Union

European Commission

Click to view thumbnail

Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats — consolidated text as at 2025-02-20

Article 1 General information to be provided in initial notifications and intermediate and final reports on major ICT-related incidents

Financial entities shall include the following general information in the initial notification, the intermediate report and the final report referred to in Article 19(4) of Regulation (EU) 2022/2554:

(a) the type of submission (initial notification, intermediate report or final report);

(b) the name of the financial entity, its LEI code and the type of financial entity referred to in Article 2(1) of Regulation (EU) 2022/2554;

(c) the name and identification code of the entity submitting the initial notification, or the intermediate or final report, on behalf of the financial entity;

(d) where applicable, the names and LEI codes of all financial entities covered by the aggregated initial notification or the intermediate or final report;

(e) the contact details of the persons responsible for communicating with the competent authority regarding the major ICT-related incident;

(f) where applicable, the identification of the parent undertaking of the group to which the financial entity belongs;

(g) in the event of an impact on the monetary situation, the currency in which the amounts are calculated.

Article 2 Specific information to be provided in initial notifications

Initial notifications referred to in Article 19(4)(a) of Regulation (EU) 2022/2554 shall contain at least all of the following specific information:

(a) the reference code for the incident assigned by the financial entity;

(b) the date and time of detection of the incident and its classification in accordance with Article 8 of Commission Delegated Regulation (EU) 2024/1772 (1);

(c) a description of the ICT-related incident;

(d) the criteria set out in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772, on the basis of which the financial entity has classified the ICT-related incident as major;

(e) the Member States affected by the ICT-related incident;

(f) information on how the ICT-related incident was detected;

(g) where applicable, information on the origin of the ICT-related incident;

(h) information indicating whether the financial entity has activated a business continuity plan;

(i) where applicable, information on the reclassification of the ICT-related incident from major to non-major;

(j) where applicable, any other relevant information.

Article 3 Specific information to be provided in intermediate reports

Intermediate reports referred to in Article 19(4)(b) of Regulation (EU) 2022/2554 shall contain at least all of the following specific information:

(a) where applicable, the reference code for the incident assigned by the competent authority;

(b) the date and time at which the ICT-related incident occurred;

(c) where applicable, the date and time at which the financial entity resumed its normal activities;

(d) information on how the criteria set out in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 were met, on the basis of which the financial entity has classified the ICT-related incident as major;

(e) the type of ICT-related incident;

(f) where applicable, the threats and techniques used by the threat actor;

(g) the functional areas and operational processes affected;

(h) the infrastructure components supporting the operational processes affected;

(i) the impact on the financial interests of clients;

(j) information on the notification of the ICT-related incident to other authorities;

(k) the temporary actions or measures taken or planned by the financial entity to recover from the ICT-related incident;

(l) where applicable, information on indicators of compromise.

Article 4 Specific information to be provided in final reports

Final reports referred to in Article 19(4)(c) of Regulation (EU) 2022/2554 shall contain all of the following specific information:

(a) information on the root causes of the ICT-related incident;

(b) the dates and times at which the ICT-related incident was resolved and the root cause or causes were addressed;

(c) information on the resolution of the ICT-related incident;

(d) where applicable, information relevant to resolution authorities;

(e) information on the direct and indirect costs and losses arising from the ICT-related incident and information on financial recoveries;

(f) where applicable, information on recurring ICT-related incidents.

Article 5 Time limits for the initial notification and for the intermediate and final reports

  1. Financial entities shall submit the initial notification and the intermediate and final reports referred to in Article 19(4)(a), (b) and (c) of Regulation (EU) 2022/2554 within the following time limits:

(a) for the initial report: as soon as possible, but in any event within a period of four hours from the classification of the ICT-related incident as major and no later than 24 hours from the moment the financial entity became aware of it;

(b) for the intermediate report: no later than within a period of 72 hours from the submission of the initial notification, even if the situation or the handling of the incident has not changed in accordance with Article 19(4)(b) of Regulation (EU) 2022/2554. Financial entities shall submit an updated intermediate report without unjustified delay and, in any event, when normal activities have resumed;

(c) for the final report: no later than one month after the submission of the intermediate report or, where applicable, after the last update of the intermediate report.

  1. Where the financial entity has not classified an ICT-related incident as major within 24 hours from the moment it became aware of it, but classifies it as major at a later stage, it shall submit the initial notification within a period of four hours from the classification of the ICT-related incident as major.

  2. Financial entities that are unable to submit the initial notification, the intermediate report or the final report within the time limits set out in paragraph 1 shall inform the competent authority as soon as possible, but no later than within the respective time limits for the submission of the notification or report, and explain the reasons.

  3. Where the deadline for the submission of an initial notification, an intermediate report or a final report expires on a weekend or a public holiday in the Member State of the reporting financial entity, the financial entity may submit the initial notification, the intermediate report or the final report no later than 12.00 on the next working day.

  4. Paragraph 4 shall not apply to the submission of an initial notification or an intermediate report by credit institutions, central counterparties, trading platform operators and other financial entities considered as essential or important entities in accordance with Article 3 of Directive (EU) 2022/2555.

  5. Competent authorities may decide that paragraph 4 shall not apply to the submission of an initial notification or an intermediate report by financial entities, other than those referred to in paragraph 5, which are classified as important or have a systemic character for the financial sector at national or Union level. Competent authorities shall notify their decision to the financial entities concerned. The decision of the competent authority shall apply only with regard to incidents reported after the date of notification of the decision by the competent authority to the financial entities concerned.

Article 6 Content of the voluntary notification on significant cyber threats

The content of the voluntary notification on significant cyber threats referred to in Article 19(2) of Regulation (EU) 2022/2554 shall cover all of the following:

(a) general information on the notifying financial entity, in accordance with Article 1;

(b) the date and time of detection of the significant cyber threat and any other relevant timestamp related to it;

(c) a description of the significant cyber threat;

(d) information on the potential impact of the significant cyber threat on the financial entity, its clients or its financial counterparties;

(e) the classification criteria likely to have triggered a major incident report under Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 in the event of the cyber threat materialising;

(f) information on the status of the significant cyber threat and on any change in the threat activity;

(g) where applicable, a description of the measures taken by the financial entity to prevent the materialisation of the significant cyber threats;

(h) information on any notification of the significant cyber threat to other financial entities or authorities;

(i) where applicable, information on indicators of compromise;

(j) where applicable, any other relevant information.

Article 7 Entry into force

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

(1) Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by establishing regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting significant impact thresholds and specifying the details of major incident reports (OJ L, 2024/1772, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1772/oj).

More like this from EC

We email you every new EC publication the day it's published.

Topics
Share