Lex Browse everything How it works For developers

Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554

as it stood on 2025-02-20, permalink: /eu-eurlex/32025r0301/2025-02-20

2024-10-232025-02-20

2 versions · click any mark to read the law as it stood that day · the one you are reading

Point-in-time view as at 2025-02-20. This version has been superseded, it applied 2025-02-20 → open. Jump to the version in force today or see exactly what changed next.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each article carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 7 provisions

Article premier Article 2 Article 3 Article 4 Article 5 Article 6 Article 7

Article premier, Informations générales à fournir dans les notifications initiales et les rapports intermédiaire et final sur les incidents majeurs liés aux TIC #art_1
Article 2, Informations spécifiques à fournir dans les notifications initiales #art_2
Article 3, Informations spécifiques à fournir dans les rapports intermédiaires #art_3
Article 4, Informations spécifiques à fournir dans les rapports finaux #art_4
Article 5, Délais pour la notification initiale et pour les rapports intermédiaire et final #art_5
Article 6, Contenu de la notification volontaire des cybermenaces importantes #art_6
Article 7, Entrée en vigueur #art_7
Provenance and validity dates, identifier, hash
as of2025-02-20 → this version applied
valid2025-02-20 → open publisher-asserted
typeREG_DEL Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats
languageen
published2025-02-20
lex_ideu-eurlex:32025r0301:2025-02-20
record sha256cf2582bf02331e29c0b552c6098e1c815bb9bcb1581b246d6781cd9b0e034e92
New here? What am I looking at?

This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.

It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.

“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.

← previous version (2024-10-23)   what changed?   timeline   next version (2025-02-20) →

tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)