Source: OJ L, 2025/302, 20.2.2025Current language: EN
- Digital operational resilience in the financial sector
ICT-related incidents
- ITS on templates for incident reporting
Article 5 Reclassification of major ICT-related incidents
Summary What does Article 5 of the ITS on templates for incident reporting say?
This article addresses the scenario where a financial entity, upon further review, determines that an ICT-related incident it previously reported as major never actually met the classification criteria for being major in the first place.
It sets out the procedure for correcting that classification by formally notifying the competent authority of the reclassification from major to non-major.
This article acts as a corrective mechanism that sits alongside the broader reporting framework established in earlier articles of this regulation.
Important points:
- If you previously reported an incident as major but later conclude it never met the threshold, notify the competent authority of the reclassification.
- Use the template in Annex II, specifically the fields 'type of report' and 'other information', to communicate the reclassification.
- The trigger is a conclusion that the incident never fulfilled the classification criteria at any point in time, not merely that it ceased to qualify after the fact.
Springlex's summary of the article, a reading aid, not a substitute for the legal text.
Where after further assessment, the financial entity concludes that the ICT-related incident previously reported as major, at no time fulfilled the classification criteria and thresholds set out in Article 8 of Delegated Regulation (EU) 2024/1772, the financial entity shall notify to the competent authority that it has reclassified the ICT-related incident from major to non-major by providing the information about that reclassification in the template laid down in Annex II to this Regulation in relation to the fields ‘type of report’ and ‘other information’.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
network and information system
Definition
ICT-related incident