2026-03-31 | NBB_2026_04Added
This circular revises previous guidance to extend mandatory reporting obligations to branches in Belgium of third-country credit institutions, stockbroking firms, and insurance companies, while updating the fallback email address for OneGate platform unavailability. Financial entities must submit major ICT-related incident reports via OneGate, with specific procedures for fallback channels and a requirement for single, non-aggregated reports per entity. The DORA reporting framework immediately replaces prior PSD2 and SSM cyber incident reporting requirements, utilizing classification criteria and deadlines defined in EU Delegated Regulations 2024/1772 and 2025/301.
NBB published 1 document in the last 30 days — get each new one by email the day it lands.
Public NBB_2026_04 – 31 March 2026 Circular - Page 1/4 14 Boulevard de Berlaimont - 1000 Brussels Tel. +32 2 221 23 88 Company number: 0203.201.340 Brussels RLE www.nbb.be Circular Public Brussels, 31 March 2026 Reference: NBB_2026_04 Your correspondent:
Thomas Plomteux
Tel. +32 2 221 21 97 - Mobile +32 489 97 32 27 thomas.plomteux@nbb.be Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA Scope credit institutions governed by Belgian law 1 and branches established in Belgium of credit institutions governed by the law of a third country; stockbroking firms governed by Belgian law and branches established in Belgium of stockbroking firms governed by the law of a third country; payment institutions and electronic money institutions governed by Belgian law, including payment institutions of limited size registered in accordance with Article 82 of the Act of 11 March 2018, 2 payment institutions offering account aggregation services within the meaning of Article 2(17) of the same legislation and electronic money institutions of limited size registered in accordance with
Article 200 of the same act;
insurance companies and reinsurance companies governed by Belgian law, except for those referred to in Article 275, 276 or 294 of the Act of 13 March 2016 3 and branches established in Belgium of insurance and reinsurance companies governed by the law of a third country; central securities depositories governed by Belgian law; central counterparties governed by Belgian law; 1 Including so-called «significant institutions», which fall under the direct supervision of the European Central Bank pursuant to the SSM Regulation (Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions). 2 Act of 11 March 2018 on the legal status and supervision of payment institutions and electronic money institutions and access to the activity of payment service provider, to the activity of issuing electronic money and to payment systems. 3 Act of 13 March 2016 on the legal status and supervision of insurance companies and reinsurance companies.
Read the rest free, and get an email when NBB publishes again
Source: National Bank of Belgium — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBB
NBB published 1 document in the last 30 days. We email you each new one the day it's published.