2024-10-23
Added · Updated
The European Commission adopts implementing technical standards requiring financial entities to use specific templates and procedures for reporting major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554. The regulation mandates the use of standardized data fields for initial notifications, intermediate reports, and final reports, while permitting the aggregation of reports for incidents caused by third-party providers affecting multiple entities within a single Member State. It also establishes rules for reclassifying incidents as non-major, notifying outsourcing arrangements, and utilizing secure electronic channels for submission. This regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.