Lex Browse everything How it works For developers

What changed, Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554

2024-10-23 → 2025-02-20 · no interpretation, just the text delta

on 2024-10-23eu-eurlex:32025r0301:2024-10-23 (2024-10-23 → 2025-02-19) · official source ↗
on 2025-02-20eu-eurlex:32025r0301:2025-02-20 (2025-02-20 → open) · official source ↗

Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated

195 line(s) in the old middle, 127 in the new; 1 unchanged leading and 1 trailing lines trimmed.

+ ### Article premier — Informations générales à fournir dans les notifications initiales et les rapports intermédiaire et final sur les incidents majeurs liés aux TIC
− ### art_1
+ Les entités financières incluent dans la notification initiale, le rapport intermédiaire et le rapport final, visés à l’article 19, paragraphe 4, du règlement (UE) 2022/2554, les informations générales suivantes:
− Article 1
+ a) le type de soumission (notification initiale, rapport intermédiaire ou rapport final);
− Financial entities shall include in the initial notification, the intermediate report, and the final report, as referred to in Article 19(4) of Regulation (EU) 2022/2554, the following general information:
+ b) le nom de l’entité financière, son code LEI et le type d’entité financière visé à l’article 2, paragraphe 1, du règlement (UE) 2022/2554;
− | (a) | the type of submission (initial notification, intermediate report, or final report); |
− | --- | --- |
+ c) le nom et le code d’identification de l’entité qui soumet la notification initiale, ou le rapport intermédiaire ou final, pour l’entité financière;
− | (b) | the name of the financial entity, its LEI code, and the type of financial entity, as referred to in Article 2(1) of Regulation (EU) 2022/2554; |
− | --- | --- |
+ d) le cas échéant, les noms et codes LEI de toutes les entités financières couvertes par la notification initiale agrégée ou le rapport intermédiaire ou final;
− | (c) | the name and identification code of the entity that submits the initial notification, or intermediate or final report, for the financial entity; |
− | --- | --- |
+ e) les coordonnées des personnes chargées de communiquer avec l’autorité compétente au sujet de l’incident majeur lié aux TIC;
− | (d) | where applicable, the names and LEI codes of all financial entities covered in the aggregated initial notification or intermediate or final report; |
− | --- | --- |
+ f) le cas échéant, l’identification de l’entreprise mère du groupe auquel l’entité financière appartient;
− | (e) | the contact details of the persons responsible for communicating with the competent authority on the major ICT-related incident; |
− | --- | --- |
+ g) en cas d’incidence sur la situation monétaire, la monnaie dans laquelle les montants sont calculés.
− | (f) | where applicable, the identification of the parent undertaking of the group to which the financial entity belongs; |
− | --- | --- |
+ ### Article 2 — Informations spécifiques à fournir dans les notifications initiales
− | (g) | where there is monetary impact, the currency the amounts are based on. |
− | --- | --- |
+ Les notifications initiales visées à l’article 19, paragraphe 4, point a), du règlement (UE) 2022/2554 contiennent au moins toutes les informations spécifiques suivantes:
− ### art_2
+ a) le code de référence de l’incident attribué par l’entité financière;
− Article 2
+ b) la date et l’heure de détection de l’incident et sa classification conformément à l’article 8 du règlement délégué (UE) 2024/1772 de la Commission (1);
− Initial notifications as referred to in Article 19(4), point (a), of Regulation (EU) 2022/2554 shall contain at least all of the following specific information:
+ c) une description de l’incident lié aux TIC;
− | (a) | the incident reference code assigned by the financial entity; |
− | --- | --- |
+ d) les critères énoncés aux articles 1er à 8 du règlement délégué (UE) 2024/1772, sur la base desquels l’entité financière a classé l’incident lié aux TIC comme majeur;
− | (b) | the date of detection, time of detection, and classification of the incident pursuant to Article 8 of Commission Delegated Regulation (EU) 2024/1772 (7); |
− | --- | --- |
+ e) les États membres touchés par l’incident lié aux TIC;
− | (c) | a description of the ICT-related incident; |
− | --- | --- |
+ f) des informations sur la manière dont l’incident lié aux TIC a été détecté;
− | (d) | the criteria, laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772, on the basis of which the financial entity classified the ICT-related incident as major; |
− | --- | --- |
+ g) le cas échéant, des informations sur l’origine de l’incident lié aux TIC;
− | (e) | the Members States that are impacted by the ICT-related incident; |
− | --- | --- |
+ h) des informations indiquant si l’entité financière a activé un plan de continuité des activités;
− | (f) | information on how the ICT-related incident was discovered; |
− | --- | --- |
+ i) le cas échéant, des informations sur le reclassement de l’incident lié aux TIC de majeur à non majeur;
− | (g) | where available, information about the origin of the ICT-related incident; |
− | --- | --- |
+ j) le cas échéant, toute autre information pertinente.
− | (h) | information about whether the financial entity has activated a business continuity plan; |
− | --- | --- |
+ ### Article 3 — Informations spécifiques à fournir dans les rapports intermédiaires
− | (i) | where applicable, information about the reclassification of the ICT-related incident from major to non-major; |
− | --- | --- |
+ Les rapports intermédiaires visés à l’article 19, paragraphe 4, point b), du règlement (UE) 2022/2554 contiennent au moins toutes les informations spécifiques suivantes:
− | (j) | where available, any other relevant information. |
− | --- | --- |
+ a) le cas échéant, le code de référence de l’incident attribué par l’autorité compétente;
− ### art_3
+ b) la date et l’heure auxquelles l’incident lié aux TIC est survenu;
− Article 3
+ c) le cas échéant, la date et l’heure auxquelles l’entité financière a repris ses activités régulières;
− Intermediate reports as referred to in Article 19(4), point (b), of Regulation (EU) 2022/2554 shall contain at least all of the following specific information:
+ d) des informations sur la manière dont les critères énoncés aux articles 1er à 8 du règlement délégué (UE) 2024/1772 ont été remplis, sur la base desquels l’entité financière a classé l’incident lié aux TIC comme majeur;
− | (a) | where applicable, the incident reference code provided by the competent authority; |
− | --- | --- |
+ e) le type d’incident lié aux TIC;
− | (b) | the date and time of occurrence of the ICT-related incident; |
− | --- | --- |
+ f) le cas échéant, les menaces et les techniques utilisées par l’acteur de la menace;
− | (c) | where applicable, the date and time when the financial entity has recovered its regular activities; |
− | --- | --- |
+ g) les domaines fonctionnels et les processus opérationnels concernés;
− | (d) | information about how the criteria laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 have been fulfilled, on the basis of which the financial entity classified the ITC-related incident as major; |
− | --- | --- |
+ h) les composants d’infrastructure concernés soutenant les processus opérationnels;
− | (e) | the type of ICT-related incident; |
− | --- | --- |
+ i) l’incidence sur les intérêts financiers des clients;
− | (f) | where applicable, the threats and techniques used by the threat actor; |
− | --- | --- |
+ j) des informations sur la notification de l’incident lié aux TIC à d’autres autorités;
− | (g) | affected functional areas and business processes; |
− | --- | --- |
+ k) les actions ou mesures temporaires prises ou prévues par l’entité financière pour se rétablir à la suite de l’incident lié aux TIC;
− | (h) | affected infrastructure components supporting business processes; |
− | --- | --- |
+ l) le cas échéant, des informations sur les ►C1 indicateurs de compromission** ◄ **.
− | (i) | impact on the financial interest of clients; |
− | --- | --- |
+ ### Article 4 — Informations spécifiques à fournir dans les rapports finaux
− | (j) | information about reporting about the ICT-related incident to other authorities; |
− | --- | --- |
+ Les rapports finaux visés à l’article 19, paragraphe 4, point c), du règlement (UE) 2022/2554 contiennent toutes les informations spécifiques suivantes:
− | (k) | temporary actions or measures taken or planned to be taken by the financial entity to recover from the ICT-related incident; |
− | --- | --- |
+ a) des informations sur les causes originelles de l’incident lié aux TIC;
− | (l) | where applicable, information on indicators of compromise. |
− | --- | --- |
+ b) les dates et heures auxquelles l’incident lié aux TIC a été résolu et la ou les causes originelles ont été traitées;
− ### art_4
+ c) des informations sur la résolution de l’incident lié aux TIC;
− Article 4
+ d) le cas échéant, les informations pertinentes pour les autorités de résolution;
− Final reports as referred to in Article 19(4), point (c), of Regulation (EU) 2022/2554 shall contain all of the following specific information:
+ e) des informations sur les coûts et pertes directs et indirects découlant de l’incident lié aux TIC et des informations sur les recouvrements financiers;
− | (a) | information about the root causes of the ICT-related incident; |
− | --- | --- |
+ f) le cas échéant, des informations sur les incidents récurrents liés aux TIC.
− | (b) | dates and times when the ICT-related incident was resolved and the root cause(s) addressed; |
− | --- | --- |
+ ### Article 5 — Délais pour la notification initiale et pour les rapports intermédiaire et final
− | (c) | information on the resolution of the ICT-related incident; |
− | --- | --- |
+ **1.** Les entités financières soumettent la notification initiale et les rapports intermédiaire et final visés à l’article 19, paragraphe 4, points a), b) et c), du règlement (UE) 2022/2554 dans les délais suivants:a) pour le rapport initial: le plus tôt possible, mais en tout état de cause, dans u…
− | (d) | where applicable, information relevant for resolution authorities; |
− | --- | --- |
+ **2.** Lorsque l’entité financière n’a pas classé un incident lié aux TIC comme majeur dans un délai de 24 heures à compter du moment où elle en a eu connaissance, mais qu’elle classe cet incident comme majeur à un stade ultérieur, elle soumet la notification initiale dans un délai de quatre heures …
− | (e) | information about direct and indirect costs and losses stemming from the ICT-related incident and information about financial recoveries; |
− | --- | --- |
+ **3.** Les entités financières qui ne sont pas en mesure de soumettre la notification initiale, le rapport intermédiaire ou le rapport final dans les délais fixés au paragraphe 1 en informent l’autorité compétente dans les meilleurs délais, mais au plus tard dans les délais respectifs pour la soumis…
− | (f) | where applicable, information about recurring ICT-related incidents. |
− | --- | --- |
+ **4.** Lorsque le délai de soumission d’une notification initiale, d’un rapport intermédiaire ou d’un rapport final expire un jour de week-end ou un jour férié dans l’État membre de l’entité financière déclarante, l’entité financière peut soumettre la notification initiale, le rapport intermédiaire …
− ### art_5
+ **5.** Le paragraphe 4 ne s’applique pas à la soumission d’une notification initiale ou d’un rapport intermédiaire par les établissements de crédit, les contreparties centrales, les opérateurs de plates-formes de négociation et d’autres entités financières considérées comme des entités essentielles …
− Article 5
+ **6.** Les autorités compétentes peuvent décider que le paragraphe 4 ne s’applique pas à la soumission d’une notification initiale ou d’un rapport intermédiaire par les entités financières, autres que celles visées au paragraphe 5, qui sont classées comme importantes ou présentent un caractère systé…
− 1. Financial entities shall submit the initial notification and the intermediate and final reports as referred to in Article 19(4), points (a), (b) and (c), of Regulation (EU) 2022/2554 within the following time limits:
+ ### Article 6 — Contenu de la notification volontaire des cybermenaces importantes
− | (a) | for the initial report: as early as possible, but in any case, within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident; |
− | --- | --- |
+ Le contenu de la notification volontaire en ce qui concerne les cybermenaces importantes visée à l’article 19, paragraphe 2, du règlement (UE) 2022/2554 couvre l’ensemble des éléments suivants:
− | (b) | for the intermediate report: at the latest within 72 hours from the submission of the initial notification, even where the status or the handling of the incident have not changed as referred to in Article 19(4), point (b), of Regulation (EU) 2022/2554. Financial entities shall submit an upda…
− | --- | --- |
+ a) des informations générales sur l’entité financière notifiante, conformément à l’article 1er;
− | (c) | for the final report: no later than one month after either the submission of the intermediate report, or, where applicable, after the latest updated intermediate report. |
− | --- | --- |
+ b) la date et l’heure de détection de la cybermenace importante et de tout autre horodatage pertinent lié à cette dernière;
− 2. Where the financial entity has not classified an ICT-related incident as major within 24 hours from the moment the financial entity has become aware of the ITC-related incident but classifies that ICT-related incident as major at a later stage, the financial entity shall submit the initial notifi…
+ c) une description de la cybermenace importante;
− 3. Financial entities that are unable to submit the initial notification, intermediate report, or final report within the time limits set out in paragraph 1, shall inform the competent authority thereof without undue delay, but no later than the respective time limits for the submission of the notif…
+ d) des informations sur l’incidence potentielle de la cybermenace importante sur l’entité financière, ses clients ou ses contreparties financières;
− 4. Where the time limit for the submission of an initial notification, intermediate report, or a final report falls on a weekend day or a bank holiday in the Member State of the reporting financial entity, the financial entity may submit the initial notification, intermediate or final reports by noo…
+ e) les critères de classification susceptibles d’avoir été à l’origine d’un rapport d’incident majeur prévus aux articles 1er à 8 du règlement délégué (UE) 2024/1772 en cas de matérialisation de la cybermenace;
− 5. Paragraph 4 shall not apply for the submission of an initial notification or an intermediate report by credit institutions, central counterparties, operators of trading venues, and other financial entities identified as essential or important entities pursuant to Article 3 of Directive (EU) 2022/…
+ f) des informations sur la situation de la cybermenace importante et sur tout changement dans l’activité de la menace;
− 6. Competent authorities may decide that paragraph 4 shall not apply for the submission of an initial notification or an intermediate report by financial entities, other than those referred to in paragraph 5, which are significant or have a systemic character for the financial sector at national or …
+ g) le cas échéant, une description des mesures prises par l’entité financière pour empêcher la matérialisation des cybermenaces importantes;
− ### art_6
+ h) des informations sur toute notification de la cybermenace importante à d’autres entités ou autorités financières;
− Article 6
+ i) le cas échéant, des informations sur les ►C1 indicateurs de compromission** ◄ **;
− The content of the voluntary notification in relation to significant cyber threats as referred to in Article 19(2) of Regulation (EU) 2022/2554 shall cover all of the following:

− | (a) | general information about the notifying financial entity as set out in Article 1; |
− | --- | --- |
+ j) le cas échéant, toute autre information pertinente.
− | (b) | the date and time of detection of the significant cyber threat and any other relevant timestamps related to the significant cyber threat; |
− | --- | --- |
+ ### Article 7 — Entrée en vigueur
− | (c) | a description of the significant cyber threat; |
− | --- | --- |
+ Le présent règlement entre en vigueur le vingtième jour suivant celui de sa publication au *Journal officiel de l’Union européenne*.
− | (d) | information about the potential impact of the significant cyber threat on the financial entity, its clients, or financial counterparts; |
− | --- | --- |

− | (e) | the classification criteria that would have triggered a major incident report laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 if the cyber threat had materialised; |
− | --- | --- |

− | (f) | information about the status of the significant cyber threat and any changes in the threat activity; |
− | --- | --- |

− | (g) | where applicable, a description of the actions taken by the financial entity to prevent the materialisation of the significant cyber threats; |
− | --- | --- |

− | (h) | information about any notification of the significant cyber threat to other financial entities or authorities; |
− | --- | --- |

− | (i) | where applicable, information on indicators of compromise; |
− | --- | --- |

− | (j) | where available, any other relevant information. |
− | --- | --- |

− ### art_7

− Article 7

− This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)