See Full Document Text
Official Journal EN
of the European Union L series
2025/302 20.2.2025
COMMISSION IMPLEMENTING REGULATION (EU) 2025/302
of 23 October 2024
laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of
the European Parliament and of the Council with regard to the standard forms, templates, and
procedures for financial entities to report a major ICT-related incident and to notify a significant
cyber threat
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on
digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012,
(EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011(1), and in particular Article 20, fourth paragraph, thereof,
Whereas:
(1) To ensure that financial entities report major incidents to their competent authorities in a consistent manner and to
ensure that they provide those authorities with data of good quality, it should be specified which data fields financial
entities need to provide at the various stages of the reporting referred to in Article 19(4) of Regulation
(EU) 2022/2554. It is important that that information is presented in a way that allows for a single overview of the
incident. It is therefore necessary to lay down a single reporting template for those purposes.
(2) Financial entities should complete those data fields of the reporting template that correspond to the information
requirements of the respective notification or report. However, financial entities that already have information
which they are to provide at a later reporting stage, i.e. in the intermediate or final report, should be allowed to
anticipate the submission of the data.
(3) Since multiple or recurring incidents may constitute a major incident as referred to in Article 8 of Commission
Delegated Regulation (EU) 2024/1772(2), the design of the reporting template and of the data fields should enable
financial entities to report such recurring incidents.
(4) To ensure accurate and up to-date information, the reporting template should enable financial entities, when
submitting the intermediate and final report, to update any information that was submitted previously, and where
necessary reclassify major incidents as non-major.
(5) The legal identification of entities should be aligned with the identifiers specified in the implementing technical
standards adopted pursuant to Article 28(9) of Regulation (EU) 2022/2554.
(6) Where financial entities outsource the major ICT-related incident reporting obligations to a third party, competent
authorities should be aware of the identity of the third-party reporting on behalf of the financial entity prior to the
submission of the first notification or reporting, in order to verify the legitimacy of the reporting third party.
(1) OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.
(2) Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European
Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related
incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (OJ L,
2024/1772, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1772/oj).
ELI: http://data.europa.eu/eli/reg_impl/2025/302/oj 1/44EN
OJ L, 20.2.2025
(7) To identify easily the impact of an incident that occurred at, or was caused by a third-party provider, and that affects
multiple financial entities within a single Member State, and to reduce the reporting effort for financial entities, the
reporting template should allow for the submission of an aggregated report covering aggregated information about
the impact of the incident on all impacted financial entities that have classified the incident as major.
(8) The reporting template should be designed in a technology neutral way to allow for its implementation into various
incident reporting solutions that already exist or that may be developed for the implementation of the requirements
of Regulation (EU) 2022/2554.
(9) The design of the reporting template and data fields should facilitate the reporting of major ICT-related incidents by
third parties to whom financial entities outsourced their reporting obligation in accordance with Article 19(5) of
Regulation (EU) 2022/2554.
(10) This Regulation is based on the draft implementing technical standards submitted to the Commission by the
European Supervisory Authorities.
(11) The European Supervisory Authorities have conducted open public consultations on the draft implementing
technical standards on which this Regulation is based, analysed the potential related costs and benefits and
requested the advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulations
(EU) No 1093/2010(3), (EU) No 1094/2010(4), (EU) No 1095/2010(5) of the European Parliament and of the
Council.
(12) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation
(EU) 2018/1725 of the European Parliament and of the Council(6) and delivered a positive opinion on 22 July
2024. Any processing of personal data within the scope of this Regulation should be performed in accordance with
the applicable data protection principles and provisions set out in Regulation (EU) 2018/1725,
HAS ADOPTED THIS REGULATION:
Article 1
Template for reporting ICT-related major incidents
1. Financial entities shall use the template laid down in Annex I to submit the initial notification, the intermediate
report, and the final report referred to in Article 19(4) of Regulation (EU) 2022/2554 as follows:
(a) financial entities that submit an initial notification shall complete the data fields of the template which correspond to
the information to be provided in accordance with Article 2 of Commission Delegated Regulation (EU) 2025/301(7),
and may, where they already have that information, complete those data fields the completion of which is not
required for an initial notification but is required for an intermediate or final report;
(3) Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission
Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12, ELI: http://data.europa.eu/eli/reg/2010/1093/oj).
(4) Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and
repealing Commission Decision 2009/79/EC (OJ L 331, 15.12.2010, p. 48, ELI: http://data.europa.eu/eli/reg/2010/1094/oj).
(5) Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission
Decision 2009/77/EC (OJ L 331, 15.12.2010, p. 84, ELI: http://data.europa.eu/eli/reg/2010/1095/oj).
(6) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons
with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of
such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.
europa.eu/eli/reg/2018/1725/oj).
(7) Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European
Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial
notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for
significant cyber threats. (OJ L, 2025/301, 20.2.2025, ELI: http://data.europa.eu/eli/reg_del/2025/301/oj).
2/44 ELI: http://data.europa.eu/eli/reg_impl/2025/302/ojEN
OJ L, 20.2.2025
(b) financial entities that submit an intermediate report shall complete the data fields of the template which correspond
to the information to be provided in accordance with Article 3 of Delegated Regulation (EU) 2025/301 and may,
where they already have the relevant information, complete data fields the completion of which is not required for
the intermediate report, but is required for the final report.
(c) financial entities that submit a final report shall complete the data fields of the template which correspond to the
information to be provided in accordance with Article 4 of Delegated Regulation (EU) 2025/301.
2. Financial entities shall ensure that the information contained in the initial notification, and in the intermediate and
final report, is complete and accurate.
3. Financial entities shall provide estimated values based on other available data and information, to the extent possible,
where accurate data are not available at the time of reporting for the initial notification or the intermediate report.
4. When submitting an intermediate or final report, financial entities shall use the template laid down in Annex I to
submit all required information and update, where applicable, the information that was previously provided in the initial
notification or in the intermediate report.
5. Financial entities shall follow the data glossary and instructions set out in Annex II when completing the template
laid down in Annex I.
Article 2
Joint submission of initial notification, intermediate and final reports
Financial entities may combine the submission of the initial notification, the intermediate report, and the final report to
provide two or all of those at the same time, where regular activities have recovered or the root cause analysis has been
completed and provided that the time limits set out in Article 5 of Delegated Regulation (EU) 2025/301 are met.
Article 3
Recurring ICT-related incidents
Financial entities that provide information on non-major recurring ICT-related incidents that cumulatively meet the
conditions for one major ICT-related incident as set out in Article 8(2) of Delegated Regulation (EU) 2024/1772, shall
provide that information in an aggregated form.
Article 4
Use of secure electronic channels
1. Financial entities shall use secure electronic channels as made available by their competent authority to submit the
initial notification and the intermediate and final reports.
2. Financial entities that are unable to use the secure electronic channels as made available by their competent authority
shall inform their competent authority about a major ICT-related incident through other secure means in agreement with
the competent authority. If required by the competent authority, financial entities shall resubmit the initial notification, or
intermediate or final report, through the secure electronic channel as made available by their competent authority once
they are able to do so.
ELI: http://data.europa.eu/eli/reg_impl/2025/302/oj 3/44EN
OJ L, 20.2.2025
Article 5
Reclassification of major ICT-related incidents
Where after further assessment, the financial entity concludes that the ICT-related incident previously reported as major, at
no time fulfilled the classification criteria and thresholds set out in Article 8 of Delegated Regulation (EU) 2024/1772, the
financial entity shall notify to the competent authority that it has reclassified the ICT-related incident from major to non-
major by providing the information about that reclassification in the template laid down in Annex II to this Regulation in
relation to the fields ‘type of report’ and ‘other information’.
Article 6
Notification of outsourcing of the reporting obligations
1. Financial entities that have outsourced the obligation to report major ICT-related incidents in accordance with
Article 19(5) of Regulation (EU) 2022/2554 shall inform their competent authority of that outsourcing arrangement as
soon as the outsourcing arrangement has been concluded and at the latest prior to the first notification or reporting.
2. Financial entities shall provide the competent authority with the name, contact details, and identification code of the
third-party that will submit the major ICT-related incident notifications or reports for them.
3. Financial entities shall inform their competent authority as soon as they no longer outsource their reporting
obligations as referred to in Article 19(5) of Regulation (EU) 2022/2554.
Article 7
Aggregated reporting
1. A third-party service provider to whom reporting obligations have been outsourced as referred to in Article 19(5) of
Regulation (EU) 2022/2554 may use the template set out in Annex I to this Regulation to provide aggregated information
about a major ICT-related incident impacting multiple financial entities in one single notification or report, and submit
that notification or report to the competent authority on behalf of all impacted financial entities, provided that all of the
following conditions are met:
(a) the major ICT-related incident to be reported originates from or is being caused by a third-party ICT service provider;
(b) that third-party service provider provides the relevant ICT service to more than one financial entity, or to a group;
(c) the ICT-related incident is classified as major by each financial entity covered in the aggregated notification or report;
(d) the major ICT-related incident affects financial entities within a single Member State and the aggregated report relates
to financial entities which are supervised by the same competent authority;
(e) competent authorities have explicitly permitted this type of financial entities to aggregate their reporting.
2. Paragraph 1 shall not apply to credit institutions that are considered to be of significant relevance as referred to in
Article 2 point (16) of Regulation (EU) No 468/2014 of the European Central Bank(8), operators of trading venues, and
central counterparties, which shall only use the template in Annex I to submit major ICT-related incident notifications or
reports individually to their competent authority.
3. Where competent authorities require information on the individual impact of the major ICT-related incident on a
single financial entity, upon request of the competent authority, the financial entity shall submit an individual notification
or a report on the major ICT-related incident.
(8) Regulation (EU) No 468/2014 of the European Central Bank of 16 April 2014 establishing the framework for cooperation within the
Single Supervisory Mechanism between the European Central Bank and national competent authorities and with national designated
authorities (SSM Framework Regulation) (ECB/2014/17) (OJ L 141, 14.5.2014, p. 1, ELI: http://data.europa.eu/eli/reg/2014/468/oj).
4/44 ELI: http://data.europa.eu/eli/reg_impl/2025/302/ojEN
OJ L, 20.2.2025
Article 8
Notification of significant cyber threats
1. Financial entities that notify significant cyber threats to competent authorities in accordance with Article 19(2) of
Regulation (EU) 2022/2554 shall use the template laid down in Annex III to this Regulation and follow the data glossary
and instructions set out Annex IV to this Regulation.
2. Financial entities shall ensure that the information contained in the notification of significant cyber threats is
complete and accurate.
Article 9
Entry into force
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the
European Union.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 23 October 2024.
For the Commission
The President
Ursula VON DER LEYEN
ELI: http://data.europa.eu/eli/reg_impl/2025/302/oj 5/44ANNEX I
TEMPLATES FOR THE REPORTING OF MAJOR INCIDENTS
Number of field Data field
General information about the financial entity
1.1 Type of submission
1.2 Name of the entity submitting the report
1.3 Identification code of the entity submitting the report
1.4 Type of financial entity affected
1.5 Name of the financial entity affected
1.6 LEI code of the financial entity affected
1.7 Primary contact person name
1.8 Primary contact person email
1.9 Primary contact person telephone
1.10 Second contact person name
1.11 Second contact person email
1.12 Second contact person telephone
1.13 Name of the ultimate parent undertaking
1.14 LEI code of the ultimate parent undertaking
1.15 Reporting currency
Content of the initial notification
2.1 Incident reference code assigned by the financial entity
2.2 Date and time of detection of the major ICT-related incident
2.3 Date and time of classification of the ICT-related incident as major
2.4 Description of the major ICT-related incident
2.5 Classification criteria that triggered the incident report
2.6 Materiality thresholds for the classification criterion ‘Geographical spread’
2.7 Discovery of the major ICT-related incident
6/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Number of field Data field
2.8 Indication whether the major ICT-related incident originates from a third-party provider or another financial
entity
2.9 Activation of business continuity plan, if activated
2.10 Other relevant information
Content of the intermediate report
3.1 Incident reference code provided by the competent authority
3.2 Date and time of occurrence of the major ICT-related incident
3.3 Date and time when services, activities or operations have been recovered
3.4 Number of clients affected
3.5 Percentage of clients affected
3.6 Number of financial counterparts affected
3.7 Percentage of financial counterparts affected
3.8 Impact on relevant clients or financial counterparts
3.9 Number of affected transactions
3.10 Percentage of affected transactions
3.11 Value of affected transactions
3.12 Information on whether the numbers are actual or estimates, or whether there has not been any impact
3.13 Reputational impact
3.14 Contextual information about the reputational impact
3.15 Duration of the major ICT-related incident
3.16 Service downtime
3.17 Information on whether the numbers for duration and service downtime are actual or estimates.
3.18 Types of impact in the Member States
3.19 Description of how the major ICT-related incident has an impact in other Member States
3.20 Materiality thresholds for the classification criterion ‘Data losses’
3.21 Description of the data losses
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
7/44
OJ
L,
20.2.2025
ENNumber of field Data field
3.22 Classification criterion ‘Critical services affected’
3.23 Type of the major ICT-related incident
3.24 Other types of incidents
3.25 Threats and techniques used by the threat actor
3.26 Other types of techniques
3.27 Information about affected functional areas and business processes
3.28 Affected infrastructure components supporting business processes
3.29 Information about affected infrastructure components supporting business processes
3.30 Impact on the financial interest of clients
3.31 Reporting to other authorities
3.32 Specification of ‘other’ authorities
3.33 Temporary actions/measures taken or planned to be taken to recover from the incident
3.34 Description of any temporary actions and measures taken or planned to be taken to recover from the incident
3.35 Indicators of compromise
Content of the final report
4.1 High-level classification of root causes of the incident
4.2 Detailed classification of root causes of the incident
4.3 Additional classification of root causes of the incident
4.4 Other types of root cause types
4.5 Information about the root causes of the incident
4.6 Incident resolution summary
4.7 Date and time when the incident root cause was addressed
4.8 Date and time when the incident was resolved
4.9 Information if the permanent resolution date of the incident differs from the initially planned implementation
date
4.10 Assessment of risk to critical functions for resolution purposes
4.11 Information relevant for resolution authorities
8/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Number of field Data field
4.12 Materiality threshold for the classification criterion ‘Economic impact’
4.13 Amount of gross direct and indirect costs and losses
4.14 Amount of financial recoveries
4.15 Information on whether the non-major incidents have been recurring
4.16 Date and time of occurrence of recurring incidents
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
9/44
OJ
L,
20.2.2025
ENANNEX II
DATA GLOSSARY AND INSTRUCTIONS FOR THE REPORTING OF MAJOR INCIDENTS
Mandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
General information about the financial entity
1.1. Type of submission Indicate the type of incident notification or report being Yes Yes Yes Choice:
submitted to the competent authority. — initial notification;
— intermediate report;
— final report;
— major incident reclassified as non-major.
1.2. Name of the entity Full legal name of the entity submitting the report. Yes Yes Yes Alphanumeric
submitting the
report
1.3. Identification code Identification code of the entity submitting the report. Yes Yes Yes Alphanumeric
of the entity
submitting the Where financial entities submit the notification/report, the
report identification code shall be a Legal Entity Identifier (LEI), which
is a unique 20 alphanumeric character code, based on ISO
17442-1:2020.
A third-party provider that submits a report for a financial
entity can use an identification code as specified in the
implementing technical standards adopted pursuant to
Article 28(9) of Regulation (EU) 2022/2554.
1.4. Type of the affected Type of the entity as referred to in Article 2(1), points (a) to (t), Yes Yes Yes Choice (multiselect):
financial entity of Regulation (EU) 2022/2554 for whom the report is — credit institution;
submitted. — payment institution;
— exempted payment institution;
In case of aggregated reporting as referred to in Article 7 of this — account information service provider;
Regulation, the different types of financial entities covered in — electronic money institution;
the aggregated report to be selected. — exempted electronic
money institution;
— investment firm;
— crypto-asset service provider;
— issuer of asset-referenced tokens;
— central securities depository;
— central counterparty;
— trading venue;
— trade repository;
10/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
— manager of alternative
investment fund;
— management company;
— data reporting service provider;
— insurance and reinsurance undertaking;
— insurance intermediary, reinsurance
intermediary and ancillary insurance
intermediary;
— institution for occupational retirement
provision;
— credit rating agency;
— administrator of critical benchmarks;
— crowdfunding service provider;
— securitisation repository.
1.5. Name of the Full legal name of the financial entity affected by the major ICT- Yes, if the Yes, if the Yes, if the Alphanumeric
financial entity related incident and required to report the major incident to its financial financial financial
affected competent authority under Article 19 of Regulation entity entity affected entity affected
(EU) 2022/2554. affected by by the incident by the incident
the incident is different is different
In case of aggregated reporting: is different from the entity from the entity
from the submitting the submitting the
(a) list of all names of the financial entities affected by the
entity report and in report and in
major ICT-related incident, separated by a semicolon;
submitting case of case of
(b) the third-party provider submitting a major incident
the report aggregated aggregated
notification or report in an aggregated manner as
and in case of reporting reporting
referred to in Article 7 of this Regulation, to list the names
aggregated
of all financial entities impacted by the incident, separated
reporting
by a semicolon.
1.6. LEI code of the Legal Entity Identifier (LEI) of the financial entity affected by the Yes, if the Yes, if the Yes, if the Unique 20 alphanumeric character code,
financial entity major ICT-related incident assigned in accordance with the financial financial financial based on ISO 17442-1:2020
affected International Organisation for Standardisation. entity entity affected entity affected
affected by by the major by the major
In case of aggregated reporting: the major ICT-related ICT-related
ICT-related incident is incident is
(a) a list of all LEI codes of the financial entities affected by the
incident is different from different from
major ICT-related incident, separated by a semicolon.
different the entity
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
11/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(b) the third-party provider submitting a major incident from the submitting the the entity
notification or report in an aggregated manner as entity report and in submitting the
referred to in Article 7 of this Regulation to list the LEI submitting case of report and in
codes of all financial entities impacted by the incident, the report aggregated case of
separated by a semicolon. and in case of reporting aggregated
aggregated reporting
The order of appearance of LEI codes and financial entities reporting
names shall be identical.
1.7. Primary contact Name and surname of the primary contact person of the Yes Yes Yes Alphanumeric
person name financial entity.
In case of aggregated reporting as referred to in Article 7 of this
Regulation, the name of the primary contact person in the
entity submitting the aggregated report.
1.8. Primary contact Email address of the primary contact person that can be used Yes Yes Yes Alphanumeric
person email by the competent authority for follow-up communication.
In case of aggregated reporting as referred to in Article 7 of this
Regulation, the email of the primary contact person in the
entity submitting the aggregated report.
1.9. Primary contact The telephone number of the primary contact person that can Yes Yes Yes Alphanumeric
person telephone be used by the competent authority for follow-up
communication.
In case of aggregated reporting as referred to in Article 7 of this
Regulation, the telephone number of the primary contact
person in the entity submitting the aggregated report.
The telephone number shall be reported with all international
prefixes (e.g. +33XXXXXXXXX)
1.10. Second contact Name and surname of the second contact person or the name Yes Yes Yes Alphanumeric
person name of the responsible team of the financial entity or an entity
submitting the report on behalf of the financial entity
1.11. Second contact Email address of the second contact person or a functional Yes Yes Yes Alphanumeric
person email email address of the team that can be used by the competent
authority for follow-up communication.
12/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
1.12. Second contact The telephone number of the second contact person, or of a Yes Yes Yes Alphanumeric
person telephone team, that can be used by the competent authority for
follow-up communication.
The telephone number shall be reported with all international
prefixes (e.g. +33XXXXXXXXX)
1.13. Name of the Name of the ultimate parent undertaking of the group to which Yes, if the FE Yes, if the FE Yes, if the FE Alphanumeric
ultimate parent the affected financial entity belongs, where applicable. belongs to a belongs to a belongs to a
undertaking group group group
1.14. LEI code of the LEI of the ultimate parent undertaking of the group to which Yes, if the FE Yes, if the FE Yes, if the FE Unique 20 alphanumeric character code,
ultimate parent the affected financial entity belongs, where applicable. belongs to a belongs to a belongs to a based on ISO 17442-1:2020
undertaking Assigned in accordance with the International Organisation for group group group
Standardisation.
1.15. Reporting currency Currency used for the incident reporting Yes Yes Yes Choice populated by using ISO 4217
currency codes
Content of the initial notification
2.1. Incident reference Unique reference code issued by the financial entity Yes Yes Yes Alphanumeric
code assigned by unequivocally identifying the major ICT-related incident.
the financial entity
In case of aggregated reporting as referred to in Article 7 of this
Regulation, the incident reference code assigned by the third-
party provider.
2.2. Date and time of Date and time at which the financial entity has become aware Yes Yes Yes ISO 8601 standard UTC (YYYY-MM-DD
detection of the of the ICT-related incident. Thh: mm:ss)
ICT-related incident
For recurring incidents, the date and the time at which the last
ICT-related incident was detected.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
13/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
2.3. Date and time of Date and time when the ICT-related incident was classified as Yes Yes Yes ISO 8601 standard UTC (YYYY-MM-DD
classification of the major according to the classification criteria established in Thh: mm:ss)
incident as major Delegated Regulation (EU) 2024/1772
2.4. Description of the Description of the most relevant aspects of the major ICT- Yes Yes Yes Alphanumeric
ICT-related incident related incident.
Financial entities shall provide a high-level overview of the
following information such as possible causes, immediate
impacts, systems affected, and others. Financial entities, shall
include, where known or reasonably expected, whether the
incident impacts third-party providers or other financial
entities, the type of provider or financial entity, their name,
their respective identification codes and type of the
identification code (e.g. LEI or EUID).
In subsequent reports, the field content can evolve over time to
reflect the ongoing understanding of the ICT-related incident
and describe any other relevant information about the ICT-
related incident not captured by the data fields, including the
internal severity assessment by the financial entity (e.g. very
low, low, medium, high, very high) and an indication of the
level and name of most senior decision structures that has been
involved in response to the ICT-related incident.
2.5. Classification Classification criteria under Delegated Regulation Yes Yes Yes Choice (multiple):
criteria that (EU) 2024/1772 that have triggered determination of the ICT- — clients, financial counterparts and
triggered the related incident as major and subsequent notification and transactions affected;
incident report reporting. — reputational impact;
— duration and service downtime;
In the case of aggregated reporting as referred to in Article 7 of — geographical spread;
this Regulation, the classification criteria that have triggered — data losses;
determination of the ICT-related incident as major for at least — critical services affected;
one or more financial entities. — economic impact.
2.6. Materiality EEA Member States impacted by the major ICT-related incident Yes, if Yes, if Yes, if Choice (multiple) populated by using ISO
thresholds for the ‘Geographi- ‘Geographical ‘Geographical 3166 ALPHA-2 of the affected countries
classification When assessing the impact of the major ICT-related incident in cal spread’ spread’ spread’
criterion other Member States, financial entities shall take into account threshold is threshold is threshold is
‘Geographical Articles 4 and 12 of Delegated Regulation 2024/1772. met met met
spread’
14/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
2.7. Discovery of the Indication of how the major ICT-related incident has been Yes Yes Yes Choice:
major ICT-related discovered. — IT Security;
incident — staff;
— internal audit;
— external audit;
— clients;
— financial counterparts;
— third-party provider;
— attacker;
— monitoring systems;
— authority/agency/ law enforcement
body;
— other.
2.8. Indication whether Indication whether the major ICT-related incident originates Yes, if the Yes, if the Yes, if the Alphanumeric
the incident from a third-party provider or another financial entity. incident incident incident
originates from a originates originates originates
third-party provider Financial entities shall indicate whether the major ICT-related from a third- from a third- from a third-
or another financial incident originates from a third-party provider or another party party provider party provider
entity financial entity (including financial entities belonging to the provider or or another or another
same group as the reporting entity) and the name, another financial financial
identification code of the third-party provider or financial financial entity entity
entity and type of the identification code (e.g. LEI or EUID). entity
2.9. Activation of Indication of whether there has been a formal activation of the Yes Yes Yes Boolean (Yes or No)
business continuity business continuity response measures of the financial entity.
plan, if activated
2.10. Other relevant Any further information not covered in the template. Yes, if there is Yes, if there is Yes, if there is Alphanumeric
information other other other
Financial entities that have reclassified a major ICT-related information information information
incident as non-major shall describe the reasons why the ICT- not covered not covered in not covered in
related incident does not fulfil, and is not expected to fulfil, the in the the template the template or
criteria to be considered as a major ICT-related incident. template or or if the major
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
15/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
if the major ICT-related if the major
ICT-related incident has ICT-related
incident has been incident has
been reclassified as been
reclassified non-major reclassified as
as non- non-major
major.
Content of the intermediate report
3.1. Incident reference Unique reference code assigned by the competent authority at No Yes, if Yes, if Alphanumeric
code provided by the time of receipt of the initial notification to unequivocally applicable applicable
the competent identify the major ICT-related incident.
authority
3.2. Date and time of Date and time at which the major ICT-related incident has No Yes Yes ISO 8601 standard UTC (YYYY-MM-DD
occurrence of the occurred, if different from the time the financial entity has Thh: mm:ss)
incident become aware of the major ICT-related incident.
For recurring major ICT-related incidents, the date and the time
at which the last major ICT-related incident has occurred.
3.3. Date and time when Information on the date and time of the recovery of the No Yes, if data Yes, if data field ISO 8601 standard UTC (YYYY-MM-DD
services, activities or services, activities or operations affected by the major ICT- field 3.16. 3.16. ‘Service Thh: mm:ss)
operations have related incident. ‘Service downtime’ has
been recovered downtime’ has been
been populated
populated
3.4. Number of clients Number of clients affected by the major ICT-related incident No Yes Yes Numerical integer
affected that use the service provided by the financial entity.
When assessing the number of clients affected, financial
entities shall take into account Articles 1(1) and 9(1), point (b),
of Delegated Regulation (EU) 2024/1772 in their assessment.
A financial entity that cannot determine the actual number of
clients impacted shall use estimates based on available data
from comparable reference periods.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, the total number of clients affected across all
financial entities.
16/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
3.5. Percentage of clients Percentage of clients affected by the major ICT-related incident No Yes Yes Expressed as percentage – any value up to 5
affected in relation to the total number of clients that make use of the numeric characters including up to 1
affected service provided by the financial entity. In case of more decimal place expressed as percentage (e.g.
than one service affected, the services shall be provided in an 2,4 instead of 2,4 %). If the value has more
aggregated manner. than 1 digit after the decimal, reporting
counterparties shall round half-up
Financial entities shall take into account Article 1(1) and
Article 9(1), point (a), of Delegated Regulation
(EU) 2024/1772 in their assessment.
A financial entity that cannot determine the actual percentage
of clients impacted shall use estimates based on available data
from comparable reference periods.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, a financial entity shall divide the sum of all
affected clients by the total number of clients of all impacted
financial entities.
3.6. Number of financial Number of financial counterparts affected by the major ICT- No Yes Yes Numerical integer
counterparts related incident that have concluded a contract with the
affected financial entity.
When assessing the number of financial counterparts affected,
financial entities shall take into account Article 1(2) of
Delegated Regulation (EU) 2024/1772 in their assessment. A
financial entity that cannot determine the actual number of
financial counterparts impacted shall use estimates based on
available data from comparable reference periods.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, the total number of financial counterparts
affected across all financial entities.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
17/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
3.7. Percentage Percentage of financial counterparts affected by the major ICT- No Yes Yes Expressed as percentage – any value up to 5
of financial related incident in relation to the total number of financial numeric characters including up to 1
counterparts counterparts that have concluded a contract with the financial decimal place expressed as percentage (e.g.
affected entity. 2,4 instead of 2,4 %). If the value has more
than 1 digit after the decimal, reporting
When assessing the percentage of financial counterparts counterparties shall round half-up
affected, financial entities shall take into account Articles 1(1)
and 9(1), point (c) of Delegated Regulation (EU) 2024/1772 in
their assessment.
A financial entity that cannot determine the actual percentage
of financial counterparts impacted shall use estimates based on
available data from comparable reference periods.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, indicate the sum of all affected financial
counterparts divided by the total number of financial
counterparts of all impacted financial entities.
3.8. Impact on relevant Any identified impact on relevant clients or financial No Yes, if Yes, if Boolean (Yes or No)
clients or financial counterpart as referred to in Article 1(3) and Article 9(1), point ‘Relevance of ‘Relevance of
counterparts (f), of Delegated Regulation (EU) 2024/1772. clients and clients and
financial financial
counterparts’ counterparts’
threshold is threshold is
met met
3.9. Number of affected Number of transactions affected by the major ICT-related No Yes, if any Yes, if any Numerical integer
transactions incident. transaction transaction
has been has been
When assessing the impact on transactions, financial entities affected by the affected by the
shall take into account Article 1(4) of Delegated Regulation incident incident
(EU) 2024/1772, including all affected domestic and cross-
border transactions containing a monetary amount that have
at least one part of the transaction carried out in the Union.
18/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
A financial entity that cannot determine the actual number of
transactions impacted shall use estimates based on available
data from comparable reference periods.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, indicate the total number of transactions
affected across all financial entities.
3.10. Percentage of Percentage of affected transactions in relation to the daily No Yes, if any Yes, if any Expressed as percentage – any value up to 5
affected average number of domestic and cross-border transactions transaction transaction numeric characters including up to 1
transactions carried out by the financial entity related to the affected service. has been has been decimal place expressed as percentage (e.g.
affected by the affected by the 2,4 instead of 2,4 %). If the value has more
Financial entities shall take into account Article 1(4) and incident incident than 1 digit after the decimal, reporting
Article 9(1), point (d), of Delegated Regulation counterparties shall round half-up
(EU) 2024/1772.
A financial entity that cannot determine the actual percentage
of transactions impacted shall use estimates.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, a financial entity shall sum the number of all
affected transactions and divide the sum by the total number of
transactions of all impacted financial entities.
3.11. Value of affected Total value of the transactions affected by the major ICT-related No Yes, if any Yes, if any Monetary
transactions incident shall be assessed in accordance with Article 1(4) and transactions transaction Financial entities shall report the data point
Article 9(1), point (e) of Delegated Regulation (EU) 2024/1772. have been has been in units using a minimum precision
affected by the affected by the equivalent to thousands of units (e.g. 2,5
A financial entity that cannot determine the actual value of incident incident instead of EUR 2 500).
transactions impacted shall use estimates based on available
data from comparable reference periods.
A financial entity shall report the monetary amount as a
positive value.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, the total value of the transactions affected
across all financial entities.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
19/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
3.12. Information on Information on whether the values reported in the data fields No Yes Yes Choice (multiple):
whether the 3.4 to 3.11 are actual or estimates, or whether there has not — actual figures for clients affected;
numbers are actual been any impact. — actual figures for financial
or estimates, or counterparts affected;
whether there has — actual figures for transactions affected;
not been any impact — estimates for clients affected;
— estimates for financial counterparts
affected;
— estimates for transactions affected;
— no impact on clients;
— no impact on financial counterparts;
— no impact on transactions.
3.13. Reputational Information about the reputational impact resulting from the No Yes, if Yes, if Choice (multiple):
impact major ICT-related incident as referred to in Articles 2 and 10 of ‘Reputational ‘Reputational — the major ICT-related incident has been
Delegated Regulation (EU) 2024/1772. impact’ impact’ reflected in the media;
criterion met criterion met — the major ICT-related incident has
In the case of aggregated reporting as referred to in Article 7 of resulted in repetitive complaints from
this Regulation, the reputational impact categories that apply different clients or financial
to at least one financial entity. counterparts on client-facing services
or critical business relationships
— the financial entity will not be able to or
is likely not to be able to meet
regulatory requirements as a result of
the major ICT-related incident;
— the financial entity will or is likely to
lose clients or financial counterparts
with a material impact on its business
as a result of the major ICT-related
incident.
3.14. Contextual Information describing how the major ICT-related incident has No Yes, if Yes, if Alphanumeric
information about affected or could affect the reputation of the financial entity, ‘Reputational ‘Reputational
the reputational including infringements of law, regulatory requirements not impact’ impact’
impact met, number of client complaints, and other. criterion met. criterion met.
20/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
The contextual information shall include the type of media (e.g.
traditional and digital media, blogs, streaming platforms) and
media coverage, including reach of the media (local, national,
international). Media coverage in this context shall not mean a
few negative comments by followers or users of social
networks.
The financial entity shall also indicate whether the media
coverage highlighted significant risks for its clients in relation
to the major ICT-related incident, including the risk of the
financial entity’s insolvency or the risk of losing funds.
Financial entities shall also indicate whether they have
provided information to the media that served to reliably
inform the public about the major ICT-related incident and its
consequences.
Financial entities may also indicate whether there was false
information in the media in relation to the ICT-related incident,
including information based on deliberate misinformation
spread by threat actors, or information relating to or
illustrating defacement of the financial entity’s website.
3.15. Duration of Financial entities shall measure the duration of the major ICT- No Yes Yes DD:HH:MM
the incident related incident from the moment the major ICT-related
incident occurred until the moment the incident was resolved.
Financial entities that are unable to determine the moment
when the major ICT-related incident has occurred shall
measure the duration of the major ICT-related incident from
the earlier between the moment the financial entity detected
the incident and the moment when the financial entity
recorded the incident in network or system logs or other data
sources. Financial entities that do not yet know the moment
when the major ICT-related incident will be resolved shall
apply estimates. The value shall be expressed in days, hours,
and minutes.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, financial entities shall measure the longest
duration of the major ICT-related incident in case of differences
between financial entities.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
21/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
3.16. Service downtime Service downtime measured from the moment the service is No Yes, if the Yes, if the DD:HH:MM
fully or partially unavailable to clients, financial counterparts incident has incident has
or other internal or external users, until the moment when caused a caused a
regular activities or operations have been restored to the level service service
of service that was provided prior to the major ICT-related downtime downtime
incident.
Where the service downtime causes a delay in the provision of
service after regular activities or operations have been restored,
financial entities shall measure the downtime from the start of
the major ICT-related incident until the moment when that
delayed service is provided. Financial entities that are unable to
determine the moment when the service downtime has started,
shall measure the service downtime from the earlier between
the moment the incident was detected and the moment when it
has been recorded.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, financial entities shall measure the longest
duration of the service downtime in case of differences
between financial entities.
3.17. Information on Information on whether the values reported in data fields 3.15 No Yes, if Yes, if Choice:
whether the and 3.16 are actual or estimates. ‘Duration and ‘Duration and — Actual figures;
numbers for service service — Estimates;
duration and service downtime’ downtime’ — Actual figures and estimates;
downtime are actual criterion met criterion met — No information available.
or estimates
3.18. Types of impact in Type of impact in the respective EEA Member States. No Yes, if Yes, if Choice (multiple):
the Member States ‘Geographical ‘Geographical — clients;
Indication of whether the major ICT-related incident has had spread’ spread’ — financial counterparts;
an impact in other EEA Member States (other than the Member threshold is threshold is — branch of the financial entity;
State of the competent authority to which the incident is met met — financial entities within the group
directly reported), in accordance with Article 4 of Delegated carrying out activities in the
Regulation (EU) 2024/1772, and in particular with regard to respective Member State;
the significance of the impact in relation to: — financial market infrastructure;
(a) clients and financial counterparts affected in other — third-party providers that may be
Member States; or common to other financial entities.
22/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
(b) branches or other financial entities within the group
carrying out activities in other Member States; or
(c) financial market infrastructures or third-party providers,
which may affect financial entities in other Member States
to which they provide services.
3.19. Description of how Description of the impact and severity of the major ICT-related No Yes, if Yes, if Alphanumeric
the incident has an incident in each affected Member State, including an ‘Geographical ‘Geographical
impact in other assessment of the impact and severity on: spread’ spread’
Member States (a) clients; threshold is threshold is
(b) financial counterparts; met met
(c) branches of the financial entity;
(d) other financial entities within the group carrying out
activities in the respective Member State;
(e) financial market infrastructures;
(f) third-party providers that may be common to other
financial entities as applicable in other Member State(s).
3.20. Materiality Type of data losses that the major ICT-related incident entails in No Yes, if ‘Data Yes, if ‘Data Choice (multiple):
thresholds for the relation to availability, authenticity, integrity, and losses’ losses’ — availability;
classification confidentiality of data. criterion is criterion is — authenticity;
criterion ‘Data met met — integrity;
losses’ Financial entities shall take into account Articles 5 and 13 of — confidentiality.
Delegated Regulation (EU) 2024/1772 in their assessment.
In case of aggregated reporting as referred to in Article 7 of this
Regulation, the data losses affecting at least one financial entity.
3.21. Description of the Description of the impact of the major ICT-related incident on No Yes, if ‘Data Yes, if ‘Data Alphanumeric
data losses availability, authenticity, integrity, and confidentiality of losses’ losses’
critical data in accordance with Articles 5 and 13 of Delegated criterion is criterion is
Regulation (EU) 2024/1772. met met
Information about the impact on the implementation of the
business objectives of the financial entity or on meeting
regulatory requirements.
As part of the information provided, financial entities shall
indicate whether the data affected are client data, other entities’
data (e.g. financial counterparts), or data of the financial entity
itself.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
23/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
The financial entity may also indicate the type of data involved
in the incident – in particular, whether the data is confidential
and what type of confidentiality was involved (e.g. commercial/
business confidentiality, personal data, professional secrecy:
banking secrecy, insurance secrecy, payment services secrecy,
etc.).
The information may also include possible risks associated
with the data losses, such as whether the data affected by the
incident can be used to identify individuals and could be used
by the threat actor to obtain credit or loans without their
consent, to conduct spear phishing attacks, to disclose
information publicly.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, a general description of the impact of the
incident on the affected financial entities. Where there are
differences of the impact, the description of the impact shall
clearly indicate the specific impact on the different financial
entities.
3.22. Classification Information related to the criterion ‘Critical services affected’. No Yes Yes Alphanumeric
criterion ‘Critical
services affected’ Financial entities shall take into account Articles 6 of Delegated
Regulation (EU) 2024/1772 in their assessment, including
information about:
— the affected services or activities that require
authorisation, registration or that are supervised by
competent authorities; or
— the ICT services or network and information systems that
support critical or important functions of the financial
entity; and
— the nature of the malicious and unauthorised access to the
network and information systems of the financial entity.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, the impact on critical services that apply to at
least one financial entity.
24/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
3.23. Type of the incident Classification of incidents by type. No Yes Yes Choice (multiple):
— Cybersecurity-related;
— Process failure;
— System failure;
— External event;
— Payment-related;
— Other (please specify).
3.24. Other types of Other types of ICT-related incidents: financial entities that have No Yes, if ‘other’ Yes, if ‘other’ Alphanumeric
incidents selected ‘other’ type of incidents in the data field 3.23, shall type of type of
specify the type of ICT-related incident. incidents is incidents is
selected in selected in data
data field 3.23 field 3.23
3.25. Threats and Indicate the threats and techniques used by the threat actor, No Yes, if the type of Yes, if the type Choice (multiple):
techniques used by including: the ICT-related of the ICT- — Social engineering (including
the threat actor (a) social engineering, including phishing; incident is related phishing);
(b) (D)DoS; ‘cybersecurity- incident is — (D)DoS;
(c) identity theft; related’ in field ‘cybersecur- — Identity theft;
(d) data encryption for impact, including ransomware; 3.23 ity-related’ in — Data encryption for impact, including
(e) resource hijacking; field 3.23 ransomware;
(f) data exfiltration and manipulation, excluding identity — Resource hijacking;
theft; — Data exfiltration and manipulation,
(g) data destruction; including identity theft;
(h) defacement; — Data destruction;
(i) supply-chain attack; — Defacement;
(j) other (please specify). — Supply-chain attack;
— Other (please specify).
3.26. Other types of Other types of techniques No Yes, if other’ Yes, if other’ Alphanumeric
techniques type of type of
Financial entities that have selected ‘other’ type of techniques in techniques is techniques is
data field 3.25 shall specify the type of technique. selected in selected in data
data field 3.25 field 3.25
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
25/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
3.27. Information about Indication of the functional areas and business processes that No Yes Yes Alphanumeric
affected functional are affected by the incident, including products and services.
areas and business The functional areas shall include but are not limited to:
processes (a) marketing and business development;
(b) customer service;
(c) product management;
(d) regulatory compliance;
(e) risk management;
(f) finance and accounting;
(g) HR and general services;
(h) information Technology.
The business processes shall include but are not limited to:
— account information;
— actuarial services;
— acquiring of payment transactions;
— authentication/authorization;
— authority;
— client on-boarding;
— benefit administration;
— benefit payment management;
— buying and selling packaged insurances policies between
insurances;
— card payments;
— cash management;
— cash placement or withdrawals;
— insurance claim management;
— claim process insurance;
— clearing;
— corporate loans conglomerates;
— collective insurances;
— credit transfers;
— custody and asset safekeeping;
— customer onboarding;
— data ingestion;
— data processing;
— direct debits;
— export insurances;
— finalizing trades/deals;
— financial instruments placing;
— fund accounting;
26/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
— FX money;
— investment advice;
— investment management;
— issuing of payment instruments;
— lending management;
— life insurance payments process;
— money remittance;
— net asset calculation;
— order;
— payment initiation;
— insurance underwriting;
— portfolio management;
— premium collection;
— reception/transmission/execution;
— reinsurance;
— settlement;
— transaction monitoring.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, the affected functional areas and business
processes in at least one financial entity.
3.28. Affected Information on whether infrastructure components (servers, No Yes Yes Choice:
infrastructure operating systems, software, application servers, middleware, — Yes;
components network components, others) supporting business processes — No;
supporting business have been affected by the major ICT-related incident. — Information not available.
processes
3.29. Information about Description on the impact of the major ICT-related incident on No Yes, if the Yes, if the Alphanumeric
affected infrastructure components supporting business processes incident has incident has
infrastructure including hardware and software. affected affected
components infrastructure infrastructure
supporting business Hardware includes servers, computers, data centres, switches, components components
processes routers, hubs. Software includes operating systems, supporting supporting
applications, databases, security tools, network components, business business
others please specify. The descriptions shall describe or name processes processes
affected infrastructure components or systems, and, where
available:
(a) version information;
(b) internal infrastructure/partially outsourced/fully
outsourced – third-party provider name;
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
27/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(c) whether the infrastructure is used or shared across
multiple business functions;
(d) relevant resilience/continuity/recovery/ substitutability
arrangements in place.
3.30. Impact on the Information on whether the major ICT-related incident has No Yes Yes Choice:
financial interest of impacted the financial interest of clients. — Yes;
clients — No;
— Information not available.
3.31. Reporting to other Specification of which authorities were informed about the No Yes Yes Choice (multiple):
authorities major ICT-related incident. — Police/Law Enforcement;
— CSIRT;
Taking into account the differences resulting from the national — Data Protection Authority;
legislation of the Member States, the concept of law — National Cybersecurity Agency;
enforcement authorities shall be understood by financial — None;
entities broadly to include public authorities empowered to — Other (please specify).
prosecute cybercrime, including police, law enforcement
agencies, and public prosecutors.
3.32. Specification of Specification of ‘other’ types of authorities informed about the No Yes, if ‘other’ Yes, if ‘other’ Alphanumeric
‘other’ authorities major ICT-related incident. type of type of
authorities authorities
If selected in Data field 3.31 ‘Other’, the description shall have been have been
include more detailed information about the authority to informed by informed by
which the financial entity has submitted information about the the financial the financial
major ICT-related incident. entity about entity about
the major ICT- the major ICT-
related related
incident. incident
3.33. Temporary actions/ Indication of whether financial entity has implemented (or No Yes Yes Boolean (Yes or No)
measures taken or plan to implement) any temporary actions that have been taken
planned to be taken (or planned to be taken) to recover from the major ICT-related
to recover from the incident.
incident
28/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
3.34. Description of any The information shall describe the immediate actions taken, No Yes, if Yes, if Alphanumeric
temporary actions including the isolation of the incident at the network level, temporary temporary
and measures taken workaround procedures activated, USB ports blocked, Disaster actions/ actions/
or planned to be Recovery site activated, any other additional security controls measures have measures have
taken to recover temporarily put in place. been taken or been taken or
from the incident are planned to are planned to
Financial entities shall indicate the date and the time of the be taken (data be taken (data
implementation of the temporary actions and the expected field 3.33) field 3.33)
date of return to the primary site. For any temporary actions
that have not been implemented but are still planned,
indication of the date by when their implementation is
expected.
If no temporary actions/measures have been taken, please
indicate the reason.
3.35. Indicators of Information related to the major ICT-related incident that may No Yes, if Yes, if Alphanumeric
compromise help identify malicious activity within a network or cybersecurity- cybersecurity-
information system (Indicators of Compromise, or IoC), where related is related is
applicable. selected as a selected as a
type of type of
The field applies only to those financial entities that fall within incident in incident in
the scope of Directive (EU) 2022/2555 of the European data field 3.23 data field 3.23
Parliament and of the Council(1)and those financial entities
financial entities identified as essential or important entities
pursuant to national rules transposing Article 3 of Directive
(EU) 2022/2555, where relevant.
The IoC provided by the financial entity shall include the
following categories of data:
(a) IP addresses;
(b) URL addresses;
(c) domains;
(d) file hashes;
(e) malware data (malware name, file names and their
locations, specific registry keys associated with malware
activity);
(f) network activity data (ports, protocols, addresses,
referrers, user agents, headers, specific logs or distinctive
patterns in network traffic);
(g) email message data (sender, recipient, subject, header,
content);
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
29/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(h) DNS requests and registry configurations;
(i) user account activities (logins, privileged user account
activity, privilege escalation);
(j) database traffic (read/write), requests to the same file.
In practice, this type of information may include data relating
to, inter alia, indicators describing patterns in network traffic
corresponding to known attacks/botnet communications, IP
addresses of machines infected with malware (bots), data
relating to ‘command and control’ servers used by malware
(usually domains or IP addresses), and URLs relating to
phishing sites or websites observed hosting malware or exploit
kits.
Content of the final report
4.1. High-level High-level classification of root cause of the major ICT-related No No Yes Choice (multiple):
classification of root incident under the incident types, including the following high- — malicious actions;
causes of the level categories: — process failure;
incident (a) malicious actions; — system failure / malfunction;
(b) process failure; — human error;
(c) system failure/malfunction; — external event.
(d) human error;
(e) external event.
4.2. Detailed Detailed classification of root causes of the major ICT-related No No Yes Choice (multiple):
classification of root incident under the incident types, including the following — malicious actions: deliberate internal
causes of the detailed categories linked to the high-level categories that are actions;
incident reported in data field 4.1: — malicious actions: deliberate physical
damage/manipulation/theft;
1. Malicious actions (if selected, choose one or more the — malicious actions: fraudulent actions;
following): — process failure: insufficient monitoring
(a) deliberate internal actions; or failure of monitoring and control;
(b) deliberate physical damage/manipulation/theft; — process failure: insufficient/unclear
(c) fraudulent actions. roles and responsibilities;
— process failure: ICT risk management
2. Process failure (if selected, choose one or more the
process failure;
following):
— process failure: insufficient or failure of
(a) insufficient monitoring or failure of monitoring and
ICT operations and ICT security
control;
operations;
30/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
(b) insufficient/unclear roles and responsibilities; — process failure: insufficient or failure of
(c) ICT risk management process failure; ICT project management;
(d) insufficient or failure of ICT operations and ICT — process failure: inadequacy of internal
security operations; policies, procedures and
(e) insufficient or failure of ICT project management; documentation;
(f) inadequate internal policies, procedures and — Process failure: inadequate ICT systems
documentation; acquisition, development, and
(g) inadequate ICT systems acquisition, development, or maintenance;
maintenance; — process failure: other (please specify);
(h) other (please specify). — system failure: hardware capacity and
performance;
3. System failure/malfunction (if selected, choose one or — system failure: hardware maintenance;
more the following): — system failure: hardware obsolescence/
(a) hardware capacity and performance: major ICT- ageing;
related incidents caused by hardware resources — system failure: software compatibility/
which prove inadequate in terms of capacity or configuration;
performance to fulfil the applicable legislative — system failure: software performance;
requirements; — system failure: network configuration;
(b) hardware maintenance: major ICT-related incidents — system failure: physical damage;
resulting from inadequate or insufficient — system failure: other (please specify);
maintenance of hardware components, other than — human error: omission;
‘Hardware obsolescence/ageing’; — human error: mistake;
(c) hardware obsolescence/ageing: this root cause type — human error: skills & knowledge;
involves major ICT-related incidents resulting from — human error: inadequate human
outdated or aging hardware components; resources;
(d) software compatibility/configuration: major ICT- — human error miscommunication;
related incidents caused by software components — human error: other (please specify);
that are incompatible with other software or system — external event: natural disasters/force
configurations, including major ICT-related incidents majeure;
resulting from software conflicts, incorrect settings, — external event: third-party failures;
or misconfigured parameters that impact the overall — external event: other (please specify).
system functionality;
(e) software performance: major ICT-related incidents
resulting from software components that exhibit
poor performance or inefficiencies, for reasons other
than those specified under ‘Software compatibility/
configuration’, including major ICT-related incidents
caused by slow response times, excessive resource
consumption, or inefficient query execution
impacting the performance of the software or system;
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
31/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(f) network configuration: major ICT-related incidents
resulting from incorrect or misconfigured network
settings or infrastructure, including major ICT-related
incidents caused by network configuration errors,
routing issues, firewall misconfigurations, or other
network-related problems affecting connectivity or
communication;
(g) physical damage: major ICT-related incidents caused
by physical damage to ICT infrastructure which lead
to system failures;
(h) other (please specify).
4. Human error (if selected, choose one or more the
following):
(a) omission (unintentional);
(b) mistake;
(c) skills & knowledge: major ICT-related incidents
resulting from a lack of expertise or proficiency in
handling ICT systems or processes that may be caused
by inadequate training, insufficient knowledge, or
gaps in skills required to perform specific tasks or
address technical challenges;
(d) inadequate human resources: major ICT-related
incidents caused by a lack of necessary resources,
including hardware, software, infrastructure, or
personnel, and including situations where insufficient
resources lead to operational inefficiencies, system
failures, or an inability to meet business demands;
(e) miscommunication;
(f) other (please specify).
5. External event (if selected, choose one or more the
following):
(a) natural disasters/force majeure;
(b) third-party failures;
32/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
(c) other (please specify).
Financial entities shall consider that for recurring major ICT-
related incidents, the specific apparent root cause of the
incident is taken into account and not the broad categories
included in this field.
4.3. Additional Additional classification of root causes of the major ICT-related No No Yes Choice (multiple):
classification of root incident under the incident type, including the following — monitoring of policy adherence;
causes of the additional classification categories linked to the detailed — monitoring of third-party service
incident categories that are to be reported in data field 4.2. providers;
— monitoring and verification of
The field is mandatory for the final report if specific categories remediation of vulnerabilities;
that require further granularity are reported in data field 4.2. — identity and access management;
— encryption and cryptography;
2(a) Insufficient or failure of monitoring and control:
— logging;
(a) monitoring of policy adherence;
— failure in specifying accurate risk
(b) monitoring of third-party service providers;
tolerance levels;
(c) monitoring and verification of remediation of
— insufficient vulnerability and threat
vulnerabilities;
assessments;
(d) identity and access management;
— inadequate risk treatment measures;
(e) encryption and cryptography;
— poor management of residual ICT
(f) logging.
risks;
— vulnerability and patch management;
2(c) ICT risk management process failure:
— change management;
(a) failure in specifying accurate risk tolerance levels;
— capacity and performance
(b) insufficient vulnerability and threat assessments;
management;
(c) inadequate risk treatment measures;
— ICT asset management and
(d) poor management of residual ICT risks.
information classification;
2(d) Insufficient or failure of ICT operations and ICT — backup and restore;
security operations: — error handling;
(a) vulnerability and patch management; — inadequate ICT systems acquisition,
(b) change management; development, and maintenance;
(c) capacity and performance management; — insufficient or failure of software
(d) ICT asset management and information testing.
classification;
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
33/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(e) backup and restore;
(f) error handling.
2(g) Inadequate ICT Systems acquisition, development,
and maintenance:
(a) inadequate ICT Systems acquisition, development,
and maintenance;
(b) insufficient software testing or failure of software
testing.
4.4. Other types of root Financial entities that have selected ‘other’ type of root cause in No No Yes, if ‘other’ Alphanumeric
cause types data field 4.2 shall specify other types of root cause types type of root
causes is
selected in data
field 4.2.
4.5. Information about Description of the sequence of events that led to the major ICT- No No Yes Alphanumeric
the root causes of related incident and description of how the major ICT-related
the incident incident has a similar apparent root cause if that incident is
classified as a recurring incident, including a concise
description of all underlying reasons and primary factors that
contributed to the occurrence of the major ICT-related
incident.
Where there were malicious actions, description of the modus
operandi of the malicious action, including the tactics,
techniques and procedures used, as well as the entry vector of
the major ICT-related incident, including a description of the
investigations and analysis that led to the identification of the
root causes, if applicable.
4.6. Incident resolution Additional information regarding the actions/measures taken/ No No Yes Alphanumeric
planned to permanently resolve the major ICT-related incident
and to prevent that incident from happening again.
Lessons learnt from the major ICT-related incident.
34/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
The description shall contain the following points:
1. Resolution actions description
(a) Actions taken to permanently resolve the major ICT-
related incident (excluding any temporary actions);
(b) for each action taken, indicate the potential
involvement of a third-party provider and of the
financial entity;
(c) indicate whether procedures have been adapted
following the major ICT-related incident;
(d) indicate any additional controls that were put in place
or that are planned with related implementation
timeline.
Potential issues identified regarding the robustness of the IT
systems impacted /or in terms of the procedures or controls in
place, if applicable.
Financial entities shall clearly indicate how the envisaged
remediation actions will address the identified root causes and
when the major ICT-related incident is expected to be resolved
permanently.
2. Lessons learnt
Financial entities shall describe findings from the post-incident
review.
4.7. Date and time when Date and time when the incident root cause was addressed. No No Yes ISO 8601 standard UTC (YYYY-MM-DD
the incident root Thh: mm:ss)
cause was addressed
4.8. Date and time when Date and time when the incident was resolved. No No Yes ISO 8601 standard UTC (YYYY-MM-DD
the incident was Thh: mm:ss)
resolved
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
35/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
4.9. Information if the Descriptions of the reason why the permanent resolution date No No Yes Alphanumeric
permanent of the major ICT-related incidents is different from the initially
resolution date of planned implementation date, where applicable.
the incidents differs
from the initially
planned
implementation
date
4.10. Assessment of risk Assessment of whether the major ICT-related incident poses a No No Yes, if the Alphanumeric
to critical functions risk to critical functions within the meaning of Article 2(1), incident poses
for resolution point (35), of Directive 2014/59/EU of the European a risk to critical
purposes Parliament and of the Council(2). functions of
financial
Entities as referred to in Article 1(1) of Directive 2014/59/EU entities under
shall indicate whether the incident poses a risk to the critical Article 2(1),
functions within the meaning of Article 2(1), point (35), of point 35, of
Directive 2014/59/EU, and as reported in Template Z07.01 of Directive
Commission Implementing Regulation (EU) 2018/1624(3) 2014/59/EU
and mapped to the specific entity in Template Z07.02.
4.11. Information Description of whether and, if so, how the major ICT-related No No Yes, if the Alphanumeric
relevant for incident has affected the resolvability of the entity or the group. incident has
resolution affected the
Entities as referred to in Article 1(1) of Directive 2014/59/EU
authorities resolvability of
shall provide information on whether and, if so, how the major
the entity or
ICT-related incident has affected the resolvability of the entity
the group
or the group.
Those entities shall also indicate whether the major ICT-related
incident affects the solvency or liquidity of the financial entity
and the potential quantification of the impact.
Those entities shall also provide information on the impact on
operational continuity, impact on resolvability of the entity,
any additional impact on the costs and losses from the major
ICT-related incident, including on the financial entity’s capital
position, and whether the contractual arrangements on the use
of ICT services are still robust and fully enforceable in the event
of resolution of the entity.
36/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
4.12. Materiality Detailed information about thresholds eventually reached by No No Yes Alphanumeric
threshold for the the major ICT-related incident in relation to the criterion
classification ‘Economic impact’ referred to in Articles 7 and 14 of the
criterion ‘Economic Delegated Regulation (EU) 2024/1772.
impact’
4.13. Amount of gross Total amount of gross direct and indirect costs and losses No No Yes Monetary
direct and indirect incurred by the financial entity stemming from the major ICT-
costs and losses related incident, including:
(a) the amount of expropriated funds or financial assets for
which the financial entity is liable;
(b) the amount of replacement or relocation costs of software,
hardware or infrastructure;
(c) the amount of staff costs, including costs associated to
replacing or relocating staff, hiring extra staff,
remuneration of overtime and recovering lost or impaired
skills of staff;
(d) the amount of fees due to non-compliance with
contractual obligations;
(e) the amount of customer redress and compensation costs;
(f) the amount of losses due to forgone revenues;
(g) the amount of costs associated with internal and external
communication;
(h) the amount of advisory costs, including costs associated
with legal counselling, forensic and remediation services;
(i) the amount other costs and losses, including:
(i) direct charges, including impairments and
settlement charges, to the profit and loss account
and write-downs due to the major ICT-related
incident;
(ii) provisions or reserves accounted for in the profit
and loss account against probable losses related to
the major ICT-related incident;
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
37/44
OJ
L, 20.2.2025
ENMandatory for Mandatory for
Mandatory for
Data field Description initial intermediate Field type
final report
notification report
(iii) pending losses, in the form of losses stemming
from the major ICT-related incident, which are
temporarily booked in transitory or suspense
accounts and are not yet reflected in the profit and
loss which are planned to be included within a
time period commensurate to the size and age of
the pending item;
(iv) material uncollected revenues, related to
contractual obligations with third parties,
including the decision to compensate a client
following the major ICT-related incident, rather
than by a reimbursement or direct payment,
through a revenue adjustment waiving or reducing
contractual fees for a specific future period of time;
(v) timing losses, where they span more than one
financial accounting year and give rise to legal risk.
Financial entities shall take into account in their assessment
Article 7(1) and (2) of Delegated Regulation (EU) 2024/1772.
Financial entities shall not include in this figure financial
recoveries of any type.
Financial entities shall report the monetary amount as a
positive value.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, financial entities shall take into account the
total amount of costs and losses across all financial entities.
Financial entities shall report the data point in units using a
minimum precision equivalent to thousands of units.
4.14. Amount of financial Total amount of financial recoveries. No No Yes Monetary
recoveries Financial recoveries shall relate to the original loss caused by Financial entities shall report the data point
the incident, independently from the time when the financial in units using a minimum precision
recoveries in the form of funds or inflows of economic benefits equivalent to thousands of units
are received.
38/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Mandatory for Mandatory for
Mandatory for Data field Description initial intermediate Field type final report notification report
Financial entities shall report the monetary amount as a
positive value.
In the case of aggregated reporting as referred to in Article 7 of
this Regulation, financial entities shall take into account the
total amount of financial recoveries across all financial entities.
4.15. Information on Information on whether more than one non-major ICT-related No No Yes, if the Alphanumeric
whether the non- incident have been recurring and are together considered to be major incident
major incidents a major incident within the meaning of Article 8(2) of comprises
have been recurring Delegated Regulation (EU) 2024/1772. more than one
non-major
Financial entities shall indicate whether the non-major ICT- recurring
related incidents have been recurring and are together incidents.
considered as one major ICT-related incident.
Financial entities shall also indicate the number of occurrences
of these non-major ICT-related incidents.
4.16. Date and time of Where financial entities report recurring ICT-related incidents, No No Yes, for ISO 8601 standard UTC (YYYY-MM-DD
occurrence of date and time at which the first ICT-related incident has recurring Thh: mm:ss)
recurring incidents occurred. incidents
(1) Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU)
No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive) (OJ L 333, 27.12.2022, p. 80, http://data.europa.eu/eli/dir/2022/2555/oj).
(2) Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014establishing a framework for the recovery and resolution of credit institutions and investment firms and amending
Council Directive 82/891/EEC, and Directives 2001/24/EC, 2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU) No 1093/2010 and (EU)
No 648/2012, of the European Parliament and of the Council (OJ L 173, 12.6.2014, p. 190, http://data.europa.eu/eli/dir/2014/59/oj).
(3) Commission Implementing Regulation (EU) 2018/1624 of 23 October 2018laying down implementing technical standards with regard to procedures and standard forms and templates for the provision of
information for the purposes of resolution plans for credit institutions and investment firms pursuant to Directive 2014/59/EU of the European Parliament and of the Council, and repealing Commission
Implementing Regulation (EU) 2016/1066 (OJ L 277, 7.11.2018, p. 1, http://data.europa.eu/eli/reg_impl/2018/1624/oj).
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
39/44
OJ
L, 20.2.2025
ENANNEX III
TEMPLATES FOR NOTIFICATION OF SIGNIFICANT CYBER THREATS
Number of
Data field
field
1 Name of the entity submitting the notification
2 Identification code of the entity submitting the notification
3 Type of the financial entity submitting the notification
4 Name of the financial entity
5 LEI code of the financial entity
6 Primary contact person name
7 Primary contact person email
8 Primary contact person telephone
9 Second contact person name
10 Second contact person email
11 Second contact person telephone
12 Date and time of detection of the cyber threat
13 Description of the significant cyber threat
14 Information about potential impact
15 Potential incident classification criteria
16 Status of the cyber threat
17 Actions taken to prevent materialisation
18 Notification to other stakeholders
19 Indicators of compromise
20 Other relevant information
40/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025ANNEX IV
DATA GLOSSARY AND INSTRUCTIONS FOR NOTIFICATION OF SIGNIFICANT CYBER THREATS
Data field Description Mandatory field Field type
1. Name of the Full legal name of the entity submitting the notification. Yes Alphanumeric
entity
submitting
the
notification
2. Identification Identification code of the entity submitting the notification. Yes Alphanumeric
code of the
entity Where financial entities submit the notification/report, the identification code shall be a
submitting Legal Entity Identifier (LEI), which is a unique 20 alphanumeric character code, based on
the ISO 17442-1:2020.
notification
Where a third-party provider submits a report for a financial entity, it may use an
identification code as specified in the implementing technical standards adopted
pursuant to Article 28(9) of Regulation (EU) 2022/2554.
3. Type Type of the entity referred to in Article 2(1), points (a) to (t) of Regulation Yes, if the report is not provided by Choice (multiselect):
of financial (EU) 2022/2554 submitting the report. the affected financial entity — credit institution;
entity directly. — payment institution;
submitting — exempted payment institution;
the report — account information service
provider;
— electronic money institution;
— exempted electronic money
institution;
— investment firm;
— crypto-asset service provider;
— issuer of asset-referenced tokens;
— central securities depository;
— central counterparty;
— trading venue;
— trade repository;
— manager of alternative
investment fund;
— management company;
— data reporting service provider;
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
41/44
OJ
L,
20.2.2025
ENData field Description Mandatory field Field type
— insurance and reinsurance
undertaking;
— insurance intermediary,
reinsurance intermediary and
ancillary insurance
intermediary;
— institution for occupational
retirement provision;
— credit rating agency;
— administrator of critical
benchmarks;
— crowdfunding service provider;
— securitisation repository.
4. Name of the Full legal name of the financial entity notifying the significant cyber threat. Yes, if the financial entity is Alphanumeric
financial different from the entity
entity submitting the notification
5. LEI code of Legal Entity Identifier (LEI) of the financial entity notifying the significant cyber threat, Yes, if the financial entity notifying Unique alphanumeric 20 character
the financial assigned in accordance with the International Organisation for Standardisation. the significant cyber threat is code, based on ISO 17442-1:2020
entity different from the entity
submitting the report
6. Primary Name and surname of the primary contact person of the financial entity. Yes Alphanumeric
contact
person name
7. Primary Email address of the primary contact person that can be used by the competent authority Yes Alphanumeric
contact for follow-up communication.
person email
8. Primary The telephone number of the primary contact person that can be used by the competent Yes Alphanumeric
contact authority for follow-up communication.
person
telephone The telephone number shall be reported with all international prefixes (e.g.
+33XXXXXXXXX)
9. Second Name and surname of the second contact person of the financial entity or an entity Yes, if name and surname of the Alphanumeric
contact submitting the notification on behalf of the financial entity, where available. second contact person of the
person name financial entity or an entity
submitting the notification for the
financial entity is available
42/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025Data field Description Mandatory field Field type
10. Second Email address of the second contact person or a functional email address of the team that Yes, if email address of the second Alphanumeric
contact can be used by the competent authority for follow-up communication, where available. contact person or a functional
person email email address of the team that can
be used by the competent
authority for follow-up
communication is available
11. Second The telephone number of the second contact person that can be used by the competent Yes, if the telephone number of the Alphanumeric
contact authority for follow-up communication, where available. second contact person that can be
person used by the competent authority
The telephone number shall be reported with all international prefixes (e.g.
telephone for follow-up communication is
+33XXXXXXXXX).
available
12. Date and time Date and time at which the financial entity has become aware of the significant cyber Yes ISO 8601 standard UTC (YYYY-
of detection threat. MM-DD Thh: mm:ss)
of the cyber
threat
13. Description Description of the most relevant aspects of the significant cyber threat. Yes Alphanumeric
of the Financial entities shall provide:
significant (a) a high-level overview of the most relevant aspects of the significant cyber threat;
cyber threat (b) the related risks arising from it, including potential vulnerabilities of the systems of
the financial entity that can be exploited;
(c) information about the probability of materialisation of the significant cyber
threat; and
(d) information about the source of information about the cyber threat.
14. Information Information about the potential impact of the cyber threat on the financial entity, its Yes Alphanumeric
about clients or financial counterparts if the cyber threat has materialised
potential
impact
15. Potential The classification criteria that could have triggered a major incident report if the cyber Yes Choice (multiple):
incident threat had materialised. — clients, financial counterparts
classification and transactions affected;
criteria — reputational impact;
— duration and service downtime;
— geographical spread;
— data losses;
— critical services affected;
— economic impact.
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
43/44
OJ
L,
20.2.2025
ENData field Description Mandatory field Field type
16. Status of the Information about the status of the cyber threat for the financial entity and whether there Yes Choice:
cyber threat have been any changes in the threat activity. — active;
— inactive.
Where the cyber threat has stopped communicating with the financial entity’s
information systems, the status can be marked as inactive. If the financial entity has
information that the threat remains active against other parties or the financial system as
a whole, the status shall be marked as active.
17. Actions taken High-level information about the actions taken by the financial entity to prevent the Yes Alphanumeric
to prevent materialisation of the significant cyber threats, if applicable.
materialisa-
tion
18. Notification Information about notification of the cyber threat to other financial entities or Yes, if other financial entities or Alphanumeric
to other authorities. authorities have been informed
stakeholders about the cyber threat)
19. Indicators of Information related to the significant threat that may help identify malicious activity Yes, if information about Alphanumeric
compromise within a network or information system (Indicators of Compromise, or IoC), where indicators of compromise
applicable. connected with the cyber threat
are available)
The IoC provided by the financial entity may include, but is not to be limited to, the
following categories of data:
(a) IP addresses;
(b) URL addresses;
(c) domains;
(d) file hashes;
(e) malware data (malware name, file names and their locations, specific registry keys
associated with malware activity);
(f) network activity data (ports, protocols, addresses, referrers, user agents, headers,
specific logs or distinctive patterns in network traffic);
(g) email message data (sender, recipient, subject, header, content);
(h) DNS requests and registry configurations;
(i) user account activities (logins, privileged user account activity, privilege escalation);
(j) database traffic (read/write), requests to the same file.
This type of information may include data relating to indicators describing patterns in
network traffic corresponding to known attacks/botnet communications, IP addresses of
machines infected with malware (bots), data relating to ‘command and control’ servers
used by malware (usually domains or IP addresses), and URLs relating to phishing sites or
websites observed hosting malware or exploit kits.
20. Other Any other relevant information about the significant cyber threat Yes, if applicable and if there is Alphanumeric
relevant other information available, not
information covered in the template
44/44
ELI:
http://data.europa.eu/eli/reg_impl/2025/302/oj
EN
OJ
L,
20.2.2025