ITS on templates for incident reporting

Commission Implementing Regulation (EU) 2025/302

of 23 October 2024

laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council

with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience means the ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions; for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011(1)OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj., and in particular Article 20, fourth paragraph, thereof,

Whereas:

Open full page
Recital 1 Single reporting template

To ensure that financial entitiesas defined in Article 2, points (a) to (t) report major incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; to their competent authoritiesas defined in Article 46 in a consistent manner and to ensure that they provide those authorities with data of good quality, it should be specified which data fields financial entitiesas defined in Article 2, points (a) to (t) need to provide at the various stages of the reporting referred to in Article 19(4) of Regulation (EU) 2022/2554. It is important that that information is presented in a way that allows for a single overview of the incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;. It is therefore necessary to lay down a single reporting template for those purposes.

Recital 2 Filling in the reporting template

Financial entitiesas defined in Article 2, points (a) to (t) should complete those data fields of the reporting template that correspond to the information requirements of the respective notification or report. However, financial entitiesas defined in Article 2, points (a) to (t) that already have information which they are to provide at a later reporting stage, i.e. in the intermediate or final report, should be allowed to anticipate the submission of the data.

Recital 3 Recurring incidents

Since multiple or recurring incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; may constitute a major incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; as referred to in Article 8 of Commission Delegated Regulation (EU) 2024/1772(2)Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (OJ L, 2024/1772, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1772/oj)., the design of the reporting template and of the data fields should enable financial entitiesas defined in Article 2, points (a) to (t) to report such recurring incidents means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555;.

HAS ADOPTED THIS REGULATION:

  1. Article 1Template for reporting ICT-related major incidents
  2. Article 2Joint submission of initial notification, intermediate and final reports
  3. Article 3Recurring ICT-related incidents
  4. Article 4Use of secure electronic channels
  5. Article 5Reclassification of major ICT-related incidents
  6. Article 6Notification of outsourcing of the reporting obligations
  7. Article 7Aggregated reporting
  8. Article 8Notification of significant cyber threats
  9. Article 9Entry into force
Annexes(1 – 4)
  1. Annex ITemplates for the reporting of major incidents
  2. Annex IIData glossary and instructions for the reporting of major incidents
  3. Annex IIITemplates for notification of significant cyber threats
  4. Annex IVData glossary and instructions for notification of significant cyber threats

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 23 October 2024.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod