My bookmarksSign up free

Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats

Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats

Delegated Regulation (EU) 2025/301 · Regulation · 7 articles

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

General information to be provided in initial notifications and intermediate and final reports on major ICT-related incidents

Article 1

Financial entities shall include in the initial notification, the intermediate report, and the final report, as referred to in Article 19(4) of Regulation (EU) 2022/2554, the following general information: (a) the type of submission (initial notification, intermediate report, or final report); (b) the name of the financial entity, its LEI code, and the type of financial entity, as referred to in Article 2(1) of Regulation (EU) 2022/2554; (c) the name and identification code of the entity that submits the initial notification, or intermediate or final report, for the financial entity; (d) where applicable, the names and LEI codes of all financial entities covered in the aggregated initial notification or intermediate or final report; (e) the contact details of the persons responsible for communicating with the competent authority on the major ICT-related incident; (f) where applicable, the identification of the parent undertaking of the group to which the financial entity belongs; (g) where there is monetary impact, the currency the amounts are based on.

Specific information to be provided in initial notifications

Article 2

Initial notifications as referred to in Article 19(4), point (a), of Regulation (EU) 2022/2554 shall contain at least all of the following specific information: (a) the incident reference code assigned by the financial entity; (b) the date of detection, time of detection, and classification of the incident pursuant to Article 8 of Commission Delegated Regulation (EU) 2024/1772  ( 7 ) ; (c) a description of the ICT-related incident; (d) the criteria, laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772, on the basis of which the financial entity classified the ICT-related incident as major; (e) the Members States that are impacted by the ICT-related incident; (f) information on how the ICT-related incident was discovered; (g) where available, information about the origin of the ICT-related incident; (h) information about whether the financial entity has activated a business continuity plan; (i) where applicable, information about the reclassification of the ICT-related incident from major to non-major; (j) where available, any other relevant information.

Specific information to be provided in intermediate reports

Article 3

Intermediate reports as referred to in Article 19(4), point (b), of Regulation (EU) 2022/2554 shall contain at least all of the following specific information: (a) where applicable, the incident reference code provided by the competent authority; (b) the date and time of occurrence of the ICT-related incident; (c) where applicable, the date and time when the financial entity has recovered its regular activities; (d) information about how the criteria laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 have been fulfilled, on the basis of which the financial entity classified the ITC-related incident as major; (e) the type of ICT-related incident; (f) where applicable, the threats and techniques used by the threat actor; (g) affected functional areas and business processes; (h) affected infrastructure components supporting business processes; (i) impact on the financial interest of clients; (j) information about reporting about the ICT-related incident to other authorities; (k) temporary actions or measures taken or planned to be taken by the financial entity to recover from the ICT-related incident; (l) where applicable, information on indicators of compromise.

Article Specific information to be provided in final reports

Article 4

Final reports as referred to in Article 19(4), point (c), of Regulation (EU) 2022/2554 shall contain all of the following specific information: (a) information about the root causes of the ICT-related incident; (b) dates and times when the ICT-related incident was resolved and the root cause(s) addressed; (c) information on the resolution of the ICT-related incident; (d) where applicable, information relevant for resolution authorities; (e) information about direct and indirect costs and losses stemming from the ICT-related incident and information about financial recoveries; (f) where applicable, information about recurring ICT-related incidents.

Time limits for the initial notification, and for the intermediate and final reports

Article 5

1.   Financial entities shall submit the initial notification and the intermediate and final reports as referred to in Article 19(4), points (a), (b) and (c), of Regulation (EU) 2022/2554 within the following time limits: (a) for the initial report: as early as possible, but in any case, within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident; (b) for the intermediate report: at the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed as referred to in Article 19(4), point (b), of Regulation (EU) 2022/2554. Financial entities shall submit an updated intermediate report without undue delay, and in any case when the regular activities have been recovered; (c) for the final report: no later than one month after either the submission of the intermediate report, or, where applicable, after the latest updated intermediate report. 2.   Where the financial entity has not classified an ICT-related incident as major within 24 hours from the moment the financial entity has become aware of the ITC-related incident but classifies that ICT-related incident as major at a later stage, the financial entity shall submit the initial notification within four hours from the classification of the ICT-related incident as a major incident. 3.   Financial entities that are unable to submit the initial notification, intermediate report, or final report within the time limits set out in paragraph 1, shall inform the competent authority thereof without undue delay, but no later than the respective time limits for the submission of the notification or report, and shall explain the reasons for the delay. 4.   Where the time limit for the submission of an initial notification, intermediate report, or a final report falls on a weekend day or a bank holiday in the Member State of the reporting financial entity, the financial entity may submit the initial notification, intermediate or final reports by noon of the next working day. 5.   Paragraph 4 shall not apply for the submission of an initial notification or an intermediate report by credit institutions, central counterparties, operators of trading venues, and other financial entities identified as essential or important entities pursuant to Article 3 of Directive (EU) 2022/2555. 6.   Competent authorities may decide that paragraph 4 shall not apply for the submission of an initial notification or an intermediate report by financial entities, other than those referred to in paragraph 5, which are significant or have a systemic character for the financial sector at national or Union level. Competent authorities shall notify their decision to the identified financial entities. The decision of the competent authority shall only apply in respect of incidents reported after the date of notification of the decision by the competent authority to the identified financial entities.

Content of the voluntary notification of significant cyber threats

Article 6

The content of the voluntary notification in relation to significant cyber threats as referred to in Article 19(2) of Regulation (EU) 2022/2554 shall cover all of the following: (a) general information about the notifying financial entity as set out in Article 1; (b) the date and time of detection of the significant cyber threat and any other relevant timestamps related to the significant cyber threat; (c) a description of the significant cyber threat; (d) information about the potential impact of the significant cyber threat on the financial entity, its clients, or financial counterparts; (e) the classification criteria that would have triggered a major incident report laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 if the cyber threat had materialised; (f) information about the status of the significant cyber threat and any changes in the threat activity; (g) where applicable, a description of the actions taken by the financial entity to prevent the materialisation of the significant cyber threats; (h) information about any notification of the significant cyber threat to other financial entities or authorities; (i) where applicable, information on indicators of compromise; (j) where available, any other relevant information.

Entry into force

Article 7

This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union .

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next