2024-10-23
Added · Updated
The European Commission adopts implementing technical standards requiring financial entities to use specific templates and procedures for reporting major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554. The regulation mandates the use of standardized data fields for initial notifications, intermediate reports, and final reports, while permitting the aggregation of reports for incidents caused by third-party providers affecting multiple entities within a single Member State. It also establishes rules for reclassifying incidents as non-major, notifying outsourcing arrangements, and utilizing secure electronic channels for submission. This regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.
Get EC alerts — same-day email on every new publication.
Skip to main content
EUR-Lex
Access to European Union law
This document is an excerpt from the EUR-Lex website
You are here
EUROPA
EUR-Lex home
Implementing regulation - EU - 2025/302 - EN - EUR-Lex
Help
Quick search
Use quotation marks to search for an "exact phrase". Append an asterisk ( * ) to a search term to find variations of it (transp * , 32019R * ). Use a question mark ( ? ) instead of a single character in your search term to find variations of it (ca ? e finds case, cane, care).
Read the rest free, and get an email when EC publishes again
Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EC
We email you every new EC publication the day it's published.