Bidda Sovereign Intelligence · 10,090 Verified Nodes · 39 Sovereign Pillars

Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for standard forms, templates and procedures for financial entities to report major ICT-related incidents and notify significant cyber threats

Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 lays down implementing technical standards for the application of Regulation (EU)…

What Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for standard forms, templates and procedures for financial entities to report major ICT-related incidents and notify significant cyber threats requires

Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 lays down implementing technical standards for the application of Regulation (EU) 2022/2554 (DORA). It specifies the standard forms, templates and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat. Financial entities must use the template in Annex I for initial notifications, intermediate reports and final reports under DORA Article 19(4). The template includes data fields for general information about the financial entity, content of the initial notification (e.g. detection date, classification date, description), content of the intermediate report (e.g. occurrence date, recovery date, number of affected clients) and content of the final report (e.g. root cause classification, incident resolution summary). Financial entities must follow the data glossary and instructions in Annex II. Joint submission of initial notification, intermediate and final reports is allowed where regular activities have recovered or root cause analysis is complete, provided time limits in Delegated Regulation (EU) 2025/301 are met. Recurring ICT-related incidents that cumulatively meet the conditions for a major incident under Delegated Regulation (EU) 2024/1772 Article 8(2) must be reported in aggregated form. Financial entities must use secure electronic channels made available by their competent authority. Reclassification of a major ICT-related incident to non-major requires notification using Annex II fields 'type of report' and 'other information'. Outsourcing of reporting obligations must be communicated to the competent authority prior to the first notification. Aggregated reporting by a third-party provider is permitted under certain conditions, but does not apply to significant credit institutions, operators of trading venues and central counterparties. Notification of significant cyber threats must use the template in Annex III and follow Annex IV. The Regulation entered into force on the twentieth day after publication in the Official Journal.

Pillar: Banking & Global Finance · Authority: European Union · Version: 1.0.0 · Last updated:

Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32025R0302

SHA-256 integrity: 78eb4c9cde605be2176b53f8a5eafaa688f42950c77eae3db36d260a9d8b4da1

Primary Citations — 7 traced to source

  • Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat, Article 1 - Template for reporting ICT-related major incidents
  • Commission Implementing Regulation (EU) 2025/302 of 23 October 2024, Article 1(1) - Use of Annex I template for initial notification, intermediate report, and final report

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.