2026-04-02 | NBB_2026_04

Added · Updated

Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA

Financial entities, including credit institutions, stockbroking firms, payment institutions, insurance companies, central securities depositories, central counterparties, and crypto-asset service providers, must report major ICT-related incidents and may voluntarily notify significant cyber threats to the National Bank of Belgium. This circular extends the scope to branches of third-country entities, replaces previous PSD2 and SSM cyber incident reporting frameworks, and mandates that reports be submitted via the OneGate platform with email as a contingency for platform unavailability. The classification criteria, materiality thresholds, content requirements, and applicable deadlines are governed by specific EU Delegated and Implementing Regulations.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Scan of the document's first page
Share

NBB published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free, and get an email when NBB publishes again

Lineage: In force

Regulation (EU) 2022/2554 of th…2022Directive (EU) 2022/2555 of the…2022Circular No. NBB_2025_02 of 2025not in RegAlertReporting of major ICT-relatedincidents and voluntary notif…2026-04-02 · this document
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: National Bank of Belgium — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from NBB

NBB published 1 document in the last 30 days. We email you each new one the day it's published.

Topics