Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats

This DORA regulatory technical standard sets the content and time limits for reporting major ICT-related incidents: an initial notification within four…

What Commission Delegated Regulation (EU) 2025/301 supplementing Regulation (EU) 2022/2554 with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats requires

This DORA regulatory technical standard sets the content and time limits for reporting major ICT-related incidents: an initial notification within four hours of classification (and no later than 24 hours from awareness), an intermediate report within 72 hours, and a final report no later than one month, and it specifies the content of the voluntary notification for significant cyber threats; it supplements DORA Article 20.

Pillar: Cybersecurity · Authority: European Commission · Version: 1.0.0 · Last updated:

Primary source: https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng

SHA-256 integrity: 8175d58f25dd57b0cbeb47704d7661f028073f4e7f1b2b9165e32a82d97d8f5b

Primary Citations — 7 traced to source

  • COMMISSION DELEGATED REGULATION (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats
  • for the initial report: as early as possible, but in any case, within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.