Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554
as it stood on 2024-10-23, permalink: /eu-eurlex/32025r0302/2024-10-23
2 versions · click any mark to read the law as it stood that day · ▌ the one you are reading
Article 1
- Financial entities shall use the template laid down in Annex I to submit the initial notification, the intermediate report, and the final report referred to in Article 19(4) of Regulation (EU) 2022/2554 as follows:
| (a) | financial entities that submit an initial notification shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 2 of Commission Delegated Regulation (EU) 2025/301 (7), and may, where they already have that information, complete those data fields the completion of which is not required for an initial notification but is required for an intermediate or final report; |
|---|
| (b) | financial entities that submit an intermediate report shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 3 of Delegated Regulation (EU) 2025/301 and may, where they already have the relevant information, complete data fields the completion of which is not required for the intermediate report, but is required for the final report. |
|---|
| (c) | financial entities that submit a final report shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 4 of Delegated Regulation (EU) 2025/301. |
|---|
Financial entities shall ensure that the information contained in the initial notification, and in the intermediate and final report, is complete and accurate.
Financial entities shall provide estimated values based on other available data and information, to the extent possible, where accurate data are not available at the time of reporting for the initial notification or the intermediate report.
When submitting an intermediate or final report, financial entities shall use the template laid down in Annex I to submit all required information and update, where applicable, the information that was previously provided in the initial notification or in the intermediate report.
Financial entities shall follow the data glossary and instructions set out in Annex II when completing the template laid down in Annex I.
Article 2
Financial entities may combine the submission of the initial notification, the intermediate report, and the final report to provide two or all of those at the same time, where regular activities have recovered or the root cause analysis has been completed and provided that the time limits set out in Article 5 of Delegated Regulation (EU) 2025/301 are met.
Article 3
Financial entities that provide information on non-major recurring ICT-related incidents that cumulatively meet the conditions for one major ICT-related incident as set out in Article 8(2) of Delegated Regulation (EU) 2024/1772, shall provide that information in an aggregated form.
Article 4
Financial entities shall use secure electronic channels as made available by their competent authority to submit the initial notification and the intermediate and final reports.
Financial entities that are unable to use the secure electronic channels as made available by their competent authority shall inform their competent authority about a major ICT-related incident through other secure means in agreement with the competent authority. If required by the competent authority, financial entities shall resubmit the initial notification, or intermediate or final report, through the secure electronic channel as made available by their competent authority once they are able to do so.
Article 5
Where after further assessment, the financial entity concludes that the ICT-related incident previously reported as major, at no time fulfilled the classification criteria and thresholds set out in Article 8 of Delegated Regulation (EU) 2024/1772, the financial entity shall notify to the competent authority that it has reclassified the ICT-related incident from major to non-major by providing the information about that reclassification in the template laid down in Annex II to this Regulation in relation to the fields ‘type of report’ and ‘other information’.
Article 6
Financial entities that have outsourced the obligation to report major ICT-related incidents in accordance with Article 19(5) of Regulation (EU) 2022/2554 shall inform their competent authority of that outsourcing arrangement as soon as the outsourcing arrangement has been concluded and at the latest prior to the first notification or reporting.
Financial entities shall provide the competent authority with the name, contact details, and identification code of the third-party that will submit the major ICT-related incident notifications or reports for them.
Financial entities shall inform their competent authority as soon as they no longer outsource their reporting obligations as referred to in Article 19(5) of Regulation (EU) 2022/2554.
Article 7
- A third-party service provider to whom reporting obligations have been outsourced as referred to in Article 19(5) of Regulation (EU) 2022/2554 may use the template set out in Annex I to this Regulation to provide aggregated information about a major ICT-related incident impacting multiple financial entities in one single notification or report, and submit that notification or report to the competent authority on behalf of all impacted financial entities, provided that all of the following conditions are met:
| (a) | the major ICT-related incident to be reported originates from or is being caused by a third-party ICT service provider; |
|---|
| (b) | that third-party service provider provides the relevant ICT service to more than one financial entity, or to a group; |
|---|
| (c) | the ICT-related incident is classified as major by each financial entity covered in the aggregated notification or report; |
|---|
| (d) | the major ICT-related incident affects financial entities within a single Member State and the aggregated report relates to financial entities which are supervised by the same competent authority; |
|---|
| (e) | competent authorities have explicitly permitted this type of financial entities to aggregate their reporting. |
|---|
Paragraph 1 shall not apply to credit institutions that are considered to be of significant relevance as referred to in Article 2 point (16) of Regulation (EU) No 468/2014 of the European Central Bank (8), operators of trading venues, and central counterparties, which shall only use the template in Annex I to submit major ICT-related incident notifications or reports individually to their competent authority.
Where competent authorities require information on the individual impact of the major ICT-related incident on a single financial entity, upon request of the competent authority, the financial entity shall submit an individual notification or a report on the major ICT-related incident.
Article 8
Financial entities that notify significant cyber threats to competent authorities in accordance with Article 19(2) of Regulation (EU) 2022/2554 shall use the template laid down in Annex III to this Regulation and follow the data glossary and instructions set out Annex IV to this Regulation.
Financial entities shall ensure that the information contained in the notification of significant cyber threats is complete and accurate.
Article 9
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2024-10-23 → this version applied |
| valid | 2024-10-23 → 2025-02-19 publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat |
| language | en |
| published | 2024-10-23 |
| lex_id | eu-eurlex:32025r0302:2024-10-23 |
| record sha256 | 834fd674bc3d6b0a4a2d0758bcae0f025fd4daac5b500322c6d45f091bd4607d |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2024-10-23) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |