2026-04-02 | NBB_2026_04

Added · Updated

Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA

Financial entities, including credit institutions, stockbroking firms, payment institutions, insurance companies, central securities depositories, central counterparties, and crypto-asset service providers, must report major ICT-related incidents and may voluntarily notify significant cyber threats to the National Bank of Belgium. This circular extends the scope to branches of third-country entities, replaces previous PSD2 and SSM cyber incident reporting frameworks, and mandates that reports be submitted via the OneGate platform with email as a contingency for platform unavailability. The classification criteria, materiality thresholds, content requirements, and applicable deadlines are governed by specific EU Delegated and Implementing Regulations.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Click to view full text