Lex Browse everything How it works For developers

Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554

as it stood on 2025-02-20, permalink: /eu-eurlex/32025r0302/2025-02-20

2024-10-232025-02-20

2 versions · click any mark to read the law as it stood that day · the one you are reading

Point-in-time view as at 2025-02-20. This version has been superseded, it applied 2025-02-20 → open. Jump to the version in force today or see exactly what changed next.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each article carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 9 provisions

Article premier Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9

Article premier, Modèle de déclaration des incidents majeurs liés aux TIC #art_1
Article 2, Soumission conjointe de la notification initiale ainsi que des rapports intermédiaire et final #art_2
Article 3, Incidents récurrents liés aux TIC #art_3
Article 4, Utilisation de canaux électroniques sécurisés #art_4
Article 5, Reclassement des incidents majeurs liés aux TIC #art_5
Article 6, Notification de l’externalisation des obligations de déclaration #art_6
Article 7, Déclaration agrégée #art_7
Article 8, Notification des cybermenaces importantes #art_8
Article 9, Entrée en vigueur #art_9
Provenance and validity dates, identifier, hash
as of2025-02-20 → this version applied
valid2025-02-20 → open publisher-asserted
typeREG_IMPL Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat
languageen
published2025-02-20
lex_ideu-eurlex:32025r0302:2025-02-20
record sha25602d946fa99e307651089a80265369a5a2970b4ebd55a6bb8bd1cb158d36928f7
New here? What am I looking at?

This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.

It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.

“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.

← previous version (2024-10-23)   what changed?   timeline   next version (2025-02-20) →

tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)