What changed, Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standar…
2024-10-23 → 2025-02-20 · no interpretation, just the text delta
| on 2024-10-23 | eu-eurlex:32025r0302:2024-10-23 (2024-10-23 → 2025-02-19) · official source ↗ |
| on 2025-02-20 | eu-eurlex:32025r0302:2025-02-20 (2025-02-20 → open) · official source ↗ |
Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated
97 line(s) in the old middle, 55 in the new; 1 unchanged leading and 1 trailing lines trimmed.
+ ### Article premier — Modèle de déclaration des incidents majeurs liés aux TIC − ### art_1 + **1.** Les entités financières utilisent le modèle figurant à l’annexe I pour soumettre la notification initiale, le rapport intermédiaire et le rapport final visés à l’article 19, paragraphe 4, du règlement (UE) 2022/2554, selon les modalités suivantes:a) les entités financières qui soumettent une … − Article 1 + **2.** Les entités financières veillent à ce que les informations figurant dans la notification initiale ainsi que dans le rapport intermédiaire et le rapport final soient complètes et exactes. − 1. Financial entities shall use the template laid down in Annex I to submit the initial notification, the intermediate report, and the final report referred to in Article 19(4) of Regulation (EU) 2022/2554 as follows: + **3.** Lorsque des données exactes ne sont pas disponibles au moment de soumettre la notification initiale ou le rapport intermédiaire, les entités financières fournissent, dans la mesure du possible, des valeurs estimées fondées sur d’autres données et informations disponibles. − | (a) | financial entities that submit an initial notification shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 2 of Commission Delegated Regulation (EU) 2025/301 (7), and may, where they already have that information, compl… − | --- | --- | + **4.** Lorsqu’elles soumettent un rapport intermédiaire ou final, les entités financières utilisent le modèle figurant à l’annexe I pour communiquer toutes les informations requises et mettre à jour, s’il y a lieu, les informations précédemment fournies dans la notification initiale ou dans le rappo… − | (b) | financial entities that submit an intermediate report shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 3 of Delegated Regulation (EU) 2025/301 and may, where they already have the relevant information, complete data … − | --- | --- | + **5.** Lorsqu’elles remplissent le modèle figurant à l’annexe I, les entités financières se conforment au glossaire de données et aux instructions figurant à l’annexe II. − | (c) | financial entities that submit a final report shall complete the data fields of the template which correspond to the information to be provided in accordance with Article 4 of Delegated Regulation (EU) 2025/301. | − | --- | --- | + ### Article 2 — Soumission conjointe de la notification initiale ainsi que des rapports intermédiaire et final − 2. Financial entities shall ensure that the information contained in the initial notification, and in the intermediate and final report, is complete and accurate. + Les entités financières peuvent soumettre conjointement la notification initiale, le rapport intermédiaire et le rapport final afin de transmettre deux ou la totalité de ces documents simultanément, lorsque les activités régulières ont repris ou que l’analyse des causes originelles est terminée, et … − 3. Financial entities shall provide estimated values based on other available data and information, to the extent possible, where accurate data are not available at the time of reporting for the initial notification or the intermediate report. + ### Article 3 — Incidents récurrents liés aux TIC − 4. When submitting an intermediate or final report, financial entities shall use the template laid down in Annex I to submit all required information and update, where applicable, the information that was previously provided in the initial notification or in the intermediate report. + Les entités financières qui fournissent des informations sur les incidents récurrents non majeurs liés aux TIC qui remplissent cumulativement les conditions applicables à un incident majeur lié aux TIC énoncées à l’article 8, paragraphe 2, du règlement délégué (UE) 2024/1772 transmettent ces informa… − 5. Financial entities shall follow the data glossary and instructions set out in Annex II when completing the template laid down in Annex I. + ### Article 4 — Utilisation de canaux électroniques sécurisés − ### art_2 + **1.** Les entités financières utilisent des canaux électroniques sécurisés mis à disposition par leur autorité compétente pour soumettre la notification initiale et les rapports intermédiaire et final. − Article 2 + **2.** Les entités financières qui ne sont pas en mesure d’utiliser les canaux électroniques sécurisés mis à disposition par leur autorité compétente informent cette dernière d’un incident majeur lié aux TIC par d’autres moyens de communication sécurisés, en accord avec l’autorité compétente. Si l’a… − Financial entities may combine the submission of the initial notification, the intermediate report, and the final report to provide two or all of those at the same time, where regular activities have recovered or the root cause analysis has been completed and provided that the time limits set out in… + ### Article 5 — Reclassement des incidents majeurs liés aux TIC − ### art_3 + Si, à l’issue d’une évaluation complémentaire, l’entité financière conclut que l’incident lié aux TIC précédemment déclaré comme incident majeur ne remplissait à aucun moment les critères de classification ni n’atteignait les seuils visés à l’article 8 du règlement délégué (UE) 2024/1772, elle notif… − Article 3 + ### Article 6 — Notification de l’externalisation des obligations de déclaration − Financial entities that provide information on non-major recurring ICT-related incidents that cumulatively meet the conditions for one major ICT-related incident as set out in Article 8(2) of Delegated Regulation (EU) 2024/1772, shall provide that information in an aggregated form. + **1.** Les entités financières qui ont externalisé l’obligation de déclarer les incidents majeurs liés aux TIC en vertu de l’article 19, paragraphe 5, du règlement (UE) 2022/2554 informent leur autorité compétente de cet accord d’externalisation dès que celui-ci a été conclu et, au plus tard, avant … − ### art_4 + **2.** Les entités financières communiquent à l’autorité compétente le nom, les coordonnées et le code d’identification du tiers qui soumettra, en leur nom, les notifications ou rapports d’incidents majeurs liés aux TIC. − Article 4 + **3.** Les entités financières informent leur autorité compétente dès qu’elles n’externalisent plus leurs obligations de déclaration selon l’article 19, paragraphe 5, du règlement (UE) 2022/2554. − 1. Financial entities shall use secure electronic channels as made available by their competent authority to submit the initial notification and the intermediate and final reports. + ### Article 7 — Déclaration agrégée − 2. Financial entities that are unable to use the secure electronic channels as made available by their competent authority shall inform their competent authority about a major ICT-related incident through other secure means in agreement with the competent authority. If required by the competent auth… + **1.** Un prestataire tiers de services auprès duquel des obligations de déclaration ont été externalisées conformément à l’article 19, paragraphe 5, du règlement (UE) 2022/2554 peut utiliser le modèle figurant à l’annexe I du présent règlement pour fournir, dans une seule et même notification ou un… − ### art_5 + **2.** Le paragraphe 1 ne s’applique pas aux établissements de crédit jugés d’importance significative au sens de l’article 2, point 16), du règlement (UE) no 468/2014 de la Banque centrale européenne (2), aux opérateurs de plates-formes de négociation et aux contreparties centrales, qui utilisent u… − Article 5 + **3.** Lorsque les autorités compétentes exigent des informations relatives à l’incidence individuelle de l’incident majeur lié aux TIC sur une seule et même entité financière, à la demande de l’autorité compétente, l’entité financière soumet une notification individuelle ou un rapport sur l’inciden… − Where after further assessment, the financial entity concludes that the ICT-related incident previously reported as major, at no time fulfilled the classification criteria and thresholds set out in Article 8 of Delegated Regulation (EU) 2024/1772, the financial entity shall notify to the competent a… − − ### art_6 + ### Article 8 — Notification des cybermenaces importantes − Article 6 + **1.** Les entités financières qui notifient des cybermenaces importantes aux autorités compétentes conformément à l’article 19, paragraphe 2, du règlement (UE) 2022/2554 utilisent le modèle figurant à l’annexe III du présent règlement et se conforment au glossaire de données et aux instructions fig… − 1. Financial entities that have outsourced the obligation to report major ICT-related incidents in accordance with Article 19(5) of Regulation (EU) 2022/2554 shall inform their competent authority of that outsourcing arrangement as soon as the outsourcing arrangement has been concluded and at the la… + **2.** Les entités financières veillent à ce que les informations figurant dans la notification des cybermenaces importantes soient complètes et exactes. − 2. Financial entities shall provide the competent authority with the name, contact details, and identification code of the third-party that will submit the major ICT-related incident notifications or reports for them. + ### Article 9 — Entrée en vigueur − 3. Financial entities shall inform their competent authority as soon as they no longer outsource their reporting obligations as referred to in Article 19(5) of Regulation (EU) 2022/2554. + Le présent règlement entre en vigueur le vingtième jour suivant celui de sa publication au *Journal officiel de l’Union européenne*. − ### art_7 − − Article 7 − − 1. A third-party service provider to whom reporting obligations have been outsourced as referred to in Article 19(5) of Regulation (EU) 2022/2554 may use the template set out in Annex I to this Regulation to provide aggregated information about a major ICT-related incident impacting multiple financi… − − | (a) | the major ICT-related incident to be reported originates from or is being caused by a third-party ICT service provider; | − | --- | --- | − − | (b) | that third-party service provider provides the relevant ICT service to more than one financial entity, or to a group; | − | --- | --- | − − | (c) | the ICT-related incident is classified as major by each financial entity covered in the aggregated notification or report; | − | --- | --- | − − | (d) | the major ICT-related incident affects financial entities within a single Member State and the aggregated report relates to financial entities which are supervised by the same competent authority; | − | --- | --- | − − | (e) | competent authorities have explicitly permitted this type of financial entities to aggregate their reporting. | − | --- | --- | − − 2. Paragraph 1 shall not apply to credit institutions that are considered to be of significant relevance as referred to in Article 2 point (16) of Regulation (EU) No 468/2014 of the European Central Bank (8), operators of trading venues, and central counterparties, which shall only use the template … − − 3. Where competent authorities require information on the individual impact of the major ICT-related incident on a single financial entity, upon request of the competent authority, the financial entity shall submit an individual notification or a report on the major ICT-related incident. − − ### art_8 − − Article 8 − − 1. Financial entities that notify significant cyber threats to competent authorities in accordance with Article 19(2) of Regulation (EU) 2022/2554 shall use the template laid down in Annex III to this Regulation and follow the data glossary and instructions set out Annex IV to this Regulation. − − 2. Financial entities shall ensure that the information contained in the notification of significant cyber threats is complete and accurate. − − ### art_9 − − Article 9 − − This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |