Law / European Union

DORA Technical Standards on the Standard Forms, Templates and Procedures for Reporting Major ICT-Related Incidents and Notifying Significant Cyber Threats

Commission Implementing Regulation (EU) 2025/302

In force since .

A vulnerability and incident reporting rule binding private bodies.

Private right of action
No
Obligation class
Reporting

As of .

What it requires

  • This Regulation sets the forms and procedures for the reports under Article 19 of Regulation (EU) 2022/2554, so it reaches you if you are a financial entity under Article 2(1), points (a) to (t), of that Regulation that reports a major ICT-related incident or notifies a significant cyber threat, unless Article 2(3) takes you out of the Regulation or your Member State has excluded you under Article 2(4). A third-party service provider to which you have outsourced your reporting uses the same forms on your behalf (Articles 6 and 7).
  • Use the template in Annex I for the initial notification, the intermediate report and the final report, completing the data fields that correspond to the information that Articles 2, 3 and 4 of Delegated Regulation (EU) 2025/301 require for each report, follow the data glossary and instructions in Annex II, ensure that the information is complete and accurate, and give estimated values based on other available data and information where accurate data are not available for the initial notification or the intermediate report (Article 1).
  • When you submit an intermediate or a final report, use the Annex I template to submit all required information and update, where applicable, the information that you provided earlier (Article 1(4)).
  • If you combine two or all of the reports in one submission, which Article 2 allows where regular activities have recovered or the root cause analysis has been completed, meet the time limits of Article 5 of Delegated Regulation (EU) 2025/301 for each report (Article 2).
  • Provide information on non-major recurring ICT-related incidents that cumulatively meet the conditions for one major incident under Article 8(2) of Delegated Regulation (EU) 2024/1772 in an aggregated form (Article 3).
  • Submit the initial notification and the intermediate and final reports through the secure electronic channels your competent authority makes available. If you cannot use them, inform your competent authority about the major ICT-related incident through other secure means in agreement with the authority, and resubmit through the secure electronic channel once you are able to, if your authority requires it (Article 4).
  • If, after further assessment, you conclude that an incident you reported as major at no time fulfilled the classification criteria and thresholds of Article 8 of Delegated Regulation (EU) 2024/1772, notify your competent authority that you have reclassified it from major to non-major, using the Annex II template fields 'type of report' and 'other information' (Article 5).
  • If you outsource the obligation to report major ICT-related incidents under Article 19(5) of Regulation (EU) 2022/2554, inform your competent authority of the arrangement as soon as it is concluded and at the latest before the first notification or report, with the name, contact details and identification code of the third party that will submit the reports, and inform the authority as soon as you no longer outsource the reporting (Article 6).
  • If you are a credit institution of significant relevance under Article 2, point (16), of Regulation (EU) No 468/2014, an operator of a trading venue or a central counterparty, submit your notifications and reports individually to your competent authority. Where your competent authority requires information on the individual impact of an aggregated report on you, submit an individual notification or report on request (Article 7(2) and (3)).
  • If you notify a significant cyber threat to your competent authority under Article 19(2) of Regulation (EU) 2022/2554, use the template in Annex III, follow the data glossary and instructions in Annex IV, and ensure that the information is complete and accurate (Article 8).

Who enforces it

Enforcement body

The competent authority designated for each category of financial entity under Article 46 of Regulation (EU) 2022/2554, which ensures compliance with that Regulation in accordance with the powers granted by the respective legal acts.

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Commission Implementing Regulation (EU) 2025/302 lays down implementing technical standards for the application of Regulation (EU) 2022/2554 with regard to the standard forms, templates and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat.

Article 1(1) requires financial entities to use the template laid down in Annex I to submit the initial notification, the intermediate report and the final report referred to in Article 19(4) of Regulation (EU) 2022/2554.

Article 1(2) and (3) require the information in the initial notification and in the intermediate and final reports to be complete and accurate, with estimated values based on other available data where accurate data are not available for the initial notification or the intermediate report. Article 1(5) requires financial entities to follow the data glossary and instructions set out in Annex II when completing the template.

Article 2 lets financial entities combine the submission of the initial notification, the intermediate report and the final report where regular activities have recovered or the root cause analysis has been completed, provided that the time limits of Article 5 of Delegated Regulation (EU) 2025/301 are met.

Article 3 requires financial entities that provide information on non-major recurring ICT-related incidents that cumulatively meet the conditions for one major incident under Article 8(2) of Delegated Regulation (EU) 2024/1772 to provide it in an aggregated form. Article 4(1) requires financial entities to use the secure electronic channels made available by their competent authority to submit the initial notification and the intermediate and final reports.

Article 4(2) requires a financial entity that cannot use those channels to inform its competent authority of a major ICT-related incident through other secure means in agreement with the competent authority.

Article 5 requires a financial entity that concludes after further assessment that an incident reported as major at no time fulfilled the classification criteria and thresholds of Article 8 of Delegated Regulation (EU) 2024/1772 to notify the competent authority that it has reclassified the incident from major to non-major.

Article 6 requires a financial entity that has outsourced the obligation to report major ICT-related incidents under Article 19(5) of Regulation (EU) 2022/2554 to inform its competent authority of the arrangement as soon as it is concluded and at the latest before the first notification or report, giving the name, contact details and identification code of the third party.

Article 7(1) lets a third-party service provider to which reporting has been outsourced use the Annex I template to report a major incident affecting multiple financial entities in one notification where the incident originates from a third-party ICT service provider that provides the relevant service to more than one financial entity or to a group, each entity classifies it as major, the entities are in a single Member State under the same competent authority, and competent authorities have explicitly permitted this type of aggregation.

Article 7(2) excludes credit institutions of significant relevance, operators of trading venues and central counterparties from aggregated reporting, so that they submit notifications and reports individually to their competent authority. Article 8(1) requires financial entities that notify significant cyber threats under Article 19(2) of Regulation (EU) 2022/2554 to use the template laid down in Annex III and to follow the data glossary and instructions set out in Annex IV.

Article 9 provides that the Regulation enters into force on the twentieth day following that of its publication in the Official Journal of the European Union. The penalties for a breach are those of the parent Regulation, whose Article 50(3) requires Member States to lay down effective, proportionate and dissuasive administrative penalties and remedial measures.

When LexLint raises it

When your app profile says your app provides financial services.

Back to the example  ·  Lint your app