2026-04-02 | NBB_2026_04Added · Updated
Financial entities, including credit institutions, stockbroking firms, payment institutions, insurance companies, central securities depositories, central counterparties, and crypto-asset service providers, must report major ICT-related incidents and may voluntarily notify significant cyber threats to the National Bank of Belgium. This circular extends the scope to branches of third-country entities, replaces previous PSD2 and SSM cyber incident reporting frameworks, and mandates that reports be submitted via the OneGate platform with email as a contingency for platform unavailability. The classification criteria, materiality thresholds, content requirements, and applicable deadlines are governed by specific EU Delegated and Implementing Regulations.
NBB published 1 document in the last 30 days — get each new one by email the day it lands.
Public NBB_2026_04 – 31 March 2026 Circular - Page 1/4 14 Boulevard de Berlaimont - 1000 Brussels Tel. +32 2 221 23 88 Company number: 0203.201.340 Brussels RLE www.nbb.be Circular Public Brussels, 31 March 2026 Reference: NBB_2026_04 Your correspondent:
Thomas Plomteux
Tel. +32 2 221 21 97 - Mobile +32 489 97 32 27 thomas.plomteux@nbb.be Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA Scope credit institutions governed by Belgian law1 and branches established in Belgium of credit institutions governed by the law of a third country; stockbroking firms governed by Belgian law and branches established in Belgium of stockbroking firms governed by the law of a third country; payment institutions and electronic money institutions governed by Belgian law, including payment institutions of limited size registered in accordance with Article 82 of the Act of 11 March 2018,2 payment institutions offering account aggregation services within the meaning of Article 2(17) of the same legislation and electronic money institutions of limited size registered in accordance with
Article 200 of the same act;
insurance companies and reinsurance companies governed by Belgian law, except for those referred to in Article 275, 276 or 294 of the Act of 13 March 20163 and branches established in Belgium of insurance and reinsurance companies governed by the law of a third country; central securities depositories governed by Belgian law; central counterparties governed by Belgian law; 1 Including so-called «significant institutions», which fall under the direct supervision of the European Central Bank pursuant to the SSM Regulation (Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions). 2 Act of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions and access to the activity of payment service provider, to the activity of issuing electronic money and to payment systems. 3 Act of 13 March 2016 on the legal status and supervision of insurance companies and reinsurance companies.
Read the rest free, and get an email when NBB publishes again
Source: National Bank of Belgium — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBB
NBB published 1 document in the last 30 days. We email you each new one the day it's published.