Updated 09/05/2025
In force

Initial Legal Act
Search within this legal act

Recitals

COMMISSION DELEGATED REGULATION (EU) 2025/301

of 23 October 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (1), and in particular Article 20, third subparagraph thereof,

Whereas:

(1)

To ensure the harmonisation and simplication of the notification and reporting requirements for major ICT-related incidents referred to in Article 19(4) of Regulation (EU) 2022/2554, the time limits for reporting major ICT-related incidents should follow a consistent approach for all types of financial entities. For these reasons, the time limits should also, to the greatest extent possible, follow a consistent approach with, and at least be equivalent in effect to, the requirements set out in Directive (EU) 2022/2555 of the European Parliament and of the Council (2).

(2)

To avoid imposing an undue reporting burden on financial entities at a time when they are handling the ICT-related incident, the content of the initial notification should be limited to the most significant information. To be able to take proper supervisory action, competent authorities need to receive information about major ICT-related incidents as quickly as possible after the financial entity has classified an ICT-related incident as major. Consequently, the time limit for submitting an initial notification as referred to in Article 19(4), point (a), of Regulation (EU) 2022/2554 should be as short as possible after an ICT-related incident has been classified as major, whilst still allowing for flexibility, especially for service business models that are not particularly time-critical, in case financial entities need more time to handle the ICT-related incident after becoming aware of it.

(3)

After having received the initial notification, competent authorities should receive more detailed information about the ICT-related incident in the intermediate report and all relevant information in the final report. The information in those reports should enable competent authorities to further assess the ICT-related incident and evaluate supervisory actions they may want to take.

(4)

The reporting time limits referred to in Article 20, first paragraph, point (a)(ii), of Regulation (EU) 2022/2554 should therefore balance the need for competent authorities to receive the information quickly, with the need to provide financial entities with sufficient time to obtain complete and accurate information.

(5)

Taking into account the criteria set out in Article 20, first paragraph, point (a), of Regulation (EU) 2022/2554, the reporting timelines should not pose a disproportionate burden to microenterprises and to other financial entities that are not significant. In addition, to avoid a disproportional burden on financial entities, the reporting time limits should take into account weekends and bank holidays.

(6)

Since significant cyber threats are to be notified on a voluntary basis, the content of such notifications should not impose a burden on financial entities and should be more limited than the information requested for major ICT-related incidents.

(7)

This Regulation is based on the draft regulatory technical standards submitted to the Commission by the European Supervisory Authorities.

(8)

The European Supervisory Authorities have conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential related costs and benefits and requested the advice of the Stakeholders Groups established in accordance with Article 37 of Regulations (EU) No 1093/2010 (3), (EU) No 1094/2010 (4) and (EU) No 1095/2010 (5) of the European Parliament and of the Council.

(9)

The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (6) and delivered a positive opinion on 22 July 2024. Any processing of personal data within the scope of this Regulation should be performed in accordance with the applicable data protection principles and provisions from Regulation (EU) 2018/1725,

HAS ADOPTED THIS REGULATION:


(1)   OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.

(2)  Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj).

(3)  Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12, ELI: http://data.europa.eu/eli/reg/2010/1093/oj).

(4)  Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/79/EC (OJ L 331, 15.12.2010, p. 48, ELI: http://data.europa.eu/eli/reg/2010/1094/oj).

(5)  Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC (OJ L 331, 15.12.2010, p. 84, ELI: http://data.europa.eu/eli/reg/2010/1095/oj).

(6)  Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj).