Source: OJ L, 2025/302, 20.2.2025
EN
Preamble Recitals
Recital 1
Single reporting template
Recital 1
Single reporting template
To ensure that financial entitiesas defined in Article 2, points (a) to (t) report major incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; to their competent authoritiesas defined in Article 46 in a consistent manner and to ensure that they provide those authorities with data of good quality, it should be specified which data fields financial entitiesas defined in Article 2, points (a) to (t) need to provide at the various stages of the reporting referred to in Article 19(4) of Regulation (EU) 2022/2554. It is important that that information is presented in a way that allows for a single overview of the incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;. It is therefore necessary to lay down a single reporting template for those purposes.
Recital 2
Filling in the reporting template
Recital 2
Filling in the reporting template
Financial entitiesas defined in Article 2, points (a) to (t) should complete those data fields of the reporting template that correspond to the information requirements of the respective notification or report. However, financial entitiesas defined in Article 2, points (a) to (t) that already have information which they are to provide at a later reporting stage, i.e. in the intermediate or final report, should be allowed to anticipate the submission of the data.
Recital 3
Recurring incidents
Recital 3
Recurring incidents
Since multiple or recurring incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; may constitute a major incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; as referred to in Article 8 of Commission Delegated Regulation (EU) 2024/1772 (2)Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents (OJ L, 2024/1772, 25.6.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1772/oj)., the design of the reporting template and of the data fields should enable financial entitiesas defined in Article 2, points (a) to (t) to report such recurring incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;.
Recital 4
Updating previous information
Recital 4
Updating previous information
To ensure accurate and up to-date information, the reporting template should enable financial entitiesas defined in Article 2, points (a) to (t), when submitting the intermediate and final report, to update any information that was submitted previously, and where necessary reclassify major incidents means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; as non-major.
Recital 5
Legal identification of entities
Recital 5
Legal identification of entities
The legal identification of entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; should be aligned with the identifiers specified in the implementing technical standards means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (^29^); Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12). adopted pursuant to Article 28(9) of Regulation (EU) 2022/2554.
Recital 6
Outsourcing of incident reporting obligations
Recital 6
Outsourcing of incident reporting obligations
Where financial entitiesas defined in Article 2, points (a) to (t) outsource the major ICT-related incident means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity; reporting obligations to a third party, competent authoritiesas defined in Article 46 should be aware of the identity of the third-party reporting on behalf of the financial entity means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations; prior to the submission of the first notification or reporting, in order to verify the legitimacy of the reporting third party.
Recital 7
Incidents concerning ICT third-party service providers
Recital 7
Incidents concerning ICT third-party service providers
To identify easily the impact of an incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; that occurred at, or was caused by a third-party provider, and that affects multiple financial entitiesas defined in Article 2, points (a) to (t) within a single Member State, and to reduce the reporting effort for financial entitiesas defined in Article 2, points (a) to (t), the reporting template should allow for the submission of an aggregated report covering aggregated information about the impact of the incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; on all impacted financial entitiesas defined in Article 2, points (a) to (t) that have classified the incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; as major.
Recital 8
Technology neutral template
Recital 8
Technology neutral template
The reporting template should be designed in a technology neutral way to allow for its implementation into various incident means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems; reporting solutions that already exist or that may be developed for the implementation of the requirements of Regulation (EU) 2022/2554.
Recital 9
Facilitate outsourced incident reporting
Recital 9
Facilitate outsourced incident reporting
The design of the reporting template and data fields should facilitate the reporting of major ICT-related incidents means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity; by third parties to whom financial entitiesas defined in Article 2, points (a) to (t) outsourced their reporting obligation in accordance with Article 19(5) of Regulation (EU) 2022/2554.
Recital 10
Draft implementing technical standards from ESAs
Recital 10
Draft implementing technical standards from ESAs
This Regulation is based on the draft implementing technical standards means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (^29^); Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12). submitted to the Commission by the European Supervisory Authorities.
Recital 11
Open public consultations
Recital 11
Open public consultations
The European Supervisory Authorities have conducted open public consultations on the draft implementing technical standards means a standard as defined in Article 2, point (1), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (^29^); Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (OJ L 316, 14.11.2012, p. 12). on which this Regulation is based, analysed the potential related costs and benefits and requested the advice of the Banking Stakeholder Group means a group as defined in Article 2, point (11), of Directive 2013/34/EU; established in accordance with Article 37 of Regulations (EU) No 1093/2010 (3)Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12, ELI: http://data.europa.eu/eli/reg/2010/1093/oj)., (EU) No 1094/2010 (4)Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/79/EC (OJ L 331, 15.12.2010, p. 48, ELI: http://data.europa.eu/eli/reg/2010/1094/oj)., (EU) No 1095/2010 (5)Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC (OJ L 331, 15.12.2010, p. 84, ELI: http://data.europa.eu/eli/reg/2010/1095/oj). of the European Parliament and of the Council.
Recital 12
Processing of personal data
Recital 12
Processing of personal data
The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (6)Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj). and delivered a positive opinion on 22 July 2024. Any processing of personal data within the scope of this Regulation should be performed in accordance with the applicable data protection principles and provisions set out in Regulation (EU) 2018/1725,