2026-04-02 | NBB_2026_04Added · Updated
Financial entities, including credit institutions, stockbroking firms, payment institutions, insurance companies, central securities depositories, central counterparties, and crypto-asset service providers, must report major ICT-related incidents and may voluntarily notify significant cyber threats to the National Bank of Belgium. This circular extends the scope to branches of third-country entities, replaces previous PSD2 and SSM cyber incident reporting frameworks, and mandates that reports be submitted via the OneGate platform with email as a contingency for platform unavailability. The classification criteria, materiality thresholds, content requirements, and applicable deadlines are governed by specific EU Delegated and Implementing Regulations.
Public NBB_2026_04 – 31 March 2026 Circular - Page 1/4 14 Boulevard de Berlaimont - 1000 Brussels Tel. +32 2 221 23 88 Company number: 0203.201.340 Brussels RLE www.nbb.be Circular Public Brussels, 31 March 2026 Reference: NBB_2026_04 Your correspondent: Thomas Plomteux Tel. +32 2 221 21 97 - Mobile +32 489 97 32 27 thomas.plomteux@nbb.be Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA Scope credit institutions governed by Belgian law1 and branches established in Belgium of credit institutions governed by the law of a third country; stockbroking firms governed by Belgian law and branches established in Belgium of stockbroking firms governed by the law of a third country; payment institutions and electronic money institutions governed by Belgian law, including payment institutions of limited size registered in accordance with Article 82 of the Act of 11 March 2018,2 payment institutions offering account aggregation services within the meaning of Article 2(17) of the same legislation and electronic money institutions of limited size registered in accordance with Article 200 of the same act; insurance companies and reinsurance companies governed by Belgian law, except for those referred to in Article 275, 276 or 294 of the Act of 13 March 20163 and branches established in Belgium of insurance and reinsurance companies governed by the law of a third country; central securities depositories governed by Belgian law; central counterparties governed by Belgian law; 1 Including so-called «significant institutions», which fall under the direct supervision of the European Central Bank pursuant to the SSM Regulation (Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions). 2 Act of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions and access to the activity of payment service provider, to the activity of issuing electronic money and to payment systems. 3 Act of 13 March 2016 on the legal status and supervision of insurance companies and reinsurance companies.
Public NBB_2026_04 – 31 March 2026 Circular - Page 2/4 providers of crypto-asset services governed by Belgian law authorised under the MiCA Regulation4 and issuers of asset-referenced tokens governed by Belgian law, subject to supervision by the National Bank of Belgium (hereinafter, the “Bank”).5 These entities are hereinafter referred to as “financial entities”. Summary/objectives This circular constitutes a revision of circular NBB_2025_02 on the same subject, in order to extend its scope to branches established in Belgium of credit institutions, stockbroking firms and insurance and reinsurance companies governed by the law of a third country.6 This opportunity is used to make an adjustment to the email address that should be used in the event of unavailability of the NBB OneGate platform. This circular implements the first subparagraphs of Article 19(1) and (2) of DORA7 relating to the mandatory reporting of major ICT-related incidents and the voluntary notification of significant cyber threats. 4 Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937. 5 More specifically, to the extent the supervision of compliance with DORA falls within the Bank’s supervisory powers over these entities. 6 For more information, reference is made to Q&A DORA102 - 3097 - European Insurance and Occupational Pensions Authority. 7 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (https://eur-lex.europa.eu/eli/reg/2022/2554/oj).
Public NBB_2026_04 – 31 March 2026 Circular - Page 3/4 Dear Sir, Madam, The first subparagraph of Article 19(1) of DORA requires financial entities to report major ICT-related incidents to the relevant competent authority, in this case the Bank.8 In addition, the first subparagraph of Article 19(2) provides that financial entities may, on a voluntary basis, notify significant cyber threats to the same competent authority9 when they deem the threat to be of relevance to the financial system, service users or clients. The Bank wishes to emphasise that the timely receipt of quality incident reports and threat notifications from financial entities is crucial to allow it to fulfil the tasks conferred on it, in particular ensuring the operational resilience and financial stability of the Belgian financial sector. The classification criteria and materiality thresholds to be used for these notifications are set out in Delegated Regulation (EU) 2024/177210. The content of these notifications, as well as the applicable deadlines, are specified in Delegated Regulation (EU) 2025/30111. The applicable procedures and templates to be used are detailed in Implementing Regulation (EU) 2025/30212. 8 The third subparagraph of Article 19(1) of DORA specifically obliges credit institutions classified as significant in accordance with Article 6(4) of the SSM Regulation to report major ICT-related incidents to the national competent authority designated in accordance with Article 4 of Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC. 9 The second subparagraph of Article 19(2) of DORA specifically states that credit institutions classified as significant in accordance with Article 6(4) of the SSM Regulation may notify significant cyber threats on a voluntary basis to the national competent authority designated in accordance with the aforementioned Article 4 of Directive 2013/36/EU. 10 Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (https://eur-lex.europa.eu/eli/reg/2024/1772/oj). 11 Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats (https://eur-lex.europa.eu/eli/reg_del/2025/301/oj). 12 Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat (https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj).
Public NBB_2026_04 – 31 March 2026 Circular - Page 4/4 By means of this circular, the Bank wishes to clarify the following: the notifications can be submitted via OneGate. To this end, the Bank will post on its website (https://www.nbb.be/OneGate → “documentation” → “domain-dor”13) practical information on how to submit the notifications as well as answers to frequently asked questions; reporting via other channels (e.g. phone, email, etc.) does not detract from a financial entity’s obligation to report incidents via OneGate in accordance with the applicable deadlines and procedures; should OneGate be unavailable or if a financial entity is unable to submit an incident report via the platform, the report may be sent to operational.crisis.supervision@nbb.be. If it is not possible to submit the report by email, the institution should contact their NBB file manager by telephone. However, it is important to emphasise that, in such cases, the Bank will always ask the financial entity to submit a report via OneGate as soon as it is again able to do so; for financial entities for which this is relevant, incident reports shall be transmitted to the competent authority pursuant to Directive (EU) 2022/255514 so that a separate, direct notification by the financial entity to this authority will not be required; the Bank wishes to receive a single incident report per financial entity for which the classification criteria are met. Consequently, the Bank will not accept incident reports aggregated across multiple financial entities; the DORA reporting framework integrates and thus replaces the PSD2 incident reporting15 (for payment service providers) and the SSM cyber incident reporting (for significant credit institutions) with immediate effect.16 This circular replaces circular NBB_2025_02 on the reporting of major ICT-related incidents and the voluntary notification of significant cyber threats under DORA and is applicable with immediate effect. A copy of this circular will be sent to your institution’s accredited auditor/audit firm or accredited statutory auditor/audit firm. Yours faithfully, Pierre Wunsch Governor 13 At the publication of this circular, this results in the following URL: Domain DOR | nbb.be. 14 Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures to ensure a high common level of cybersecurity in the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (NIS 2 Directive). 15 Revised European Banking Authority (EBA) Guidelines of 10 June 2021 on PSD2 major incident reporting (EBA/GL/2021/03), available at https://www.eba.europa.eu/guidelines-major-incidents-reporting-under-psd2. 16 Article 23 of the DORA Regulation clarifies that the requirements laid down in Chapter III shall also apply to operational or security payment-related incidents and to major operational or security payment-related incidents, where they concern credit institutions, payment institutions, account information service providers, and electronic money institutions.