2024-10-23

Added · Updated

Commission Implementing Regulation (EU) 2025/302 on standard forms and procedures for reporting major ICT incidents and cyber threats

The European Commission adopts implementing technical standards requiring financial entities to use specific templates and procedures for reporting major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554. The regulation mandates the use of standardized data fields for initial notifications, intermediate reports, and final reports, while permitting the aggregation of reports for incidents caused by third-party providers affecting multiple entities within a single Member State. It also establishes rules for reclassifying incidents as non-major, notifying outsourcing arrangements, and utilizing secure electronic channels for submission. This regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union.

European Commission logo

European Union

European Commission

Click to view full text