2026-04-02 | NBB_2026_04Added · Updated
Financial entities, including credit institutions, stockbroking firms, payment institutions, insurance companies, central securities depositories, central counterparties, and crypto-asset service providers, must report major ICT-related incidents and may voluntarily notify significant cyber threats to the National Bank of Belgium. This circular extends the scope to branches of third-country entities, replaces previous PSD2 and SSM cyber incident reporting frameworks, and mandates that reports be submitted via the OneGate platform with email as a contingency for platform unavailability. The classification criteria, materiality thresholds, content requirements, and applicable deadlines are governed by specific EU Delegated and Implementing Regulations.