2026-03-31 | NBB_2026_04

Added

Reporting of major ICT-related incidents and voluntary notification of significant cyber threats under DORA

This circular revises previous guidance to extend mandatory reporting obligations to branches in Belgium of third-country credit institutions, stockbroking firms, and insurance companies, while updating the fallback email address for OneGate platform unavailability. Financial entities must submit major ICT-related incident reports via OneGate, with specific procedures for fallback channels and a requirement for single, non-aggregated reports per entity. The DORA reporting framework immediately replaces prior PSD2 and SSM cyber incident reporting requirements, utilizing classification criteria and deadlines defined in EU Delegated Regulations 2024/1772 and 2025/301.

National Bank of Belgium logo

Belgium

National Bank of Belgium

Scan of the document's first page
Share

NBB published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free, and get an email when NBB publishes again

Lineage: In force

Directive (EU) 2022/2555 of the…2022Circular No. NBB_2025_02 of 2025not in RegAlertReporting of major ICT-relatedincidents and voluntary notif…2026-03-31 · this document
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: National Bank of Belgium — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from NBB

NBB published 1 document in the last 30 days. We email you each new one the day it's published.

Topics