Chapter 7 of 11
Regulation 2024/1772: Materiality Thresholds, Cyber Threats, and Cross-Border Relevance
When does an operational event cross the line into a major incident, and when does a threat become significant before materialising? This chapter works through the remaining classification criteria, the major-incident decision rule, recurring-incident aggregation, cross-border relevance, authority information sharing, and final provisions.
1. From Classification Criteria to a Reporting Decision
The assessment sequence
Articles 4 to 7 assess incident characteristics. Articles 8 and 9 decide whether an incident is major. Article 10 deals with significant cyber threats before they materialise.
Current status
As of August 17, 2026, Regulation (EU) 2024/1772 is listed by EUR-Lex as in force. The listed corrigenda concern Regulation (EU) 2024/1774, not this Regulation.
A practical mental model
Use a funnel: identify impacts, measure them against thresholds, then apply the major-incident rule.
2. Article 4: Geographical Spread
The mandatory assessment
Article 4 requires financial entities to assess whether the incident has or had an impact in other Member States.
What cross-border impact can involve
Consider clients and counterparts, group branches or entities, and affected infrastructures or third-party providers, but provider information is considered only to the extent such information is available.
Threshold connection
Under Article 9(4), geographical spread is material where the incident has an impact in two or more Member States in accordance with Article 4.
3. Articles 5 and 6: Data Losses and Criticality
Four data dimensions
Article 5 separates availability, authenticity, integrity, and confidentiality. Do not treat them as interchangeable.
Availability and confidentiality
Availability covers data being temporarily or permanently inaccessible or unusable. Confidentiality covers access or disclosure to an unauthorised party or system.
Criticality assessment
Article 6 assesses critical or important functions, regulated financial services, and successful malicious unauthorised access to network and information systems.
4. Article 7: Calculating Economic Impact
Include incident costs
Article 7 includes direct and indirect incident costs, such as compensation, forgone revenues, overtime, replacement infrastructure, communications, legal advice, forensics, and remediation.
Exclude business-as-usual costs
Do not include day-to-day maintenance, business-enhancement costs after the incident, or insurance premiums.
Worked calculation
EUR 45,000 + EUR 30,000 + EUR 35,000 + EUR 15,000 = EUR 125,000. A EUR 20,000 future upgrade is excluded. The total exceeds the Article 9(6) threshold.
5. Article 8: The Major-Incident Decision Rule
Two required layers
Article 8 requires an impact on critical services under Article 6 and either the specific Article 9(5)(b) route or two or more other Article 9 thresholds.
Route 1
A major incident exists if critical services were affected and the Article 9(5)(b) threshold on successful malicious unauthorised access is met.
Route 2 and recurring events
Alternatively, critical services plus two or more other thresholds are required. Recurring incidents are aggregated only if all Article 8(2) conditions are satisfied.
6. Article 9: The Materiality Thresholds
Client and transaction thresholds
Article 9(1) uses alternatives: more than 10% of service users, more than 100,000 affected service users, more than 30% of relevant counterparts, or transaction-based triggers.
Time, geography, data, and money
Key triggers include incident duration over 24 hours, qualifying downtime over 2 hours, impact in two or more Member States, qualifying data losses, and costs above or likely above EUR 100,000.
Do not skip Article 8
Meeting an Article 9 threshold is not alone the complete major-incident conclusion. Apply Article 8 after assessing the thresholds.
Knowledge Check: Applying Articles 8 and 9
A financial entity experiences an incident that affects ICT services supporting a critical or important function. It lasts 30 hours and affects 12% of clients using that service. No successful malicious unauthorised access is identified.
Which conclusion follows from Articles 8 and 9?
Which conclusion follows from Articles 8 and 9?
- It is a major incident because Article 6 criticality is satisfied and two Article 9 thresholds are met: duration and affected clients.
- It is a major incident only if more than 100,000 clients are affected.
- It cannot be a major incident because no data confidentiality loss occurred.
- It is automatically a major incident because it lasted more than 24 hours.
Show Answer
Answer: A) It is a major incident because Article 6 criticality is satisfied and two Article 9 thresholds are met: duration and affected clients.
The incident affects critical services under Article 6. It also meets two Article 9 thresholds: duration longer than 24 hours under Article 9(3)(a), and affected clients higher than 10% under Article 9(1)(a). Article 8(1)(b) is therefore satisfied.
7. Article 10: Significant Cyber Threats
All conditions are required
A threat is significant only where all Article 10 conditions are fulfilled: potential impact, high probability of materialisation, and potential to meet specified criticality or materiality consequences.
Probability is evidence-based
Assess risks and exploitable vulnerabilities, known threat-actor capability and intent, and the persistence of the threat plus knowledge from related incidents.
Additional thresholds are optional
Where threat type and information support it, Article 9(2), (3), (5), and (6) thresholds may also be considered.
8. Articles 11 to 13: Cross-Border Relevance, Sharing, and Final Provisions
Article 11: relevance across borders
For competent-authority relevance, assess a root cause in another Member State or significant impact there on clients, group entities, infrastructure, or providers.
Article 12: no anonymisation
Shared details shall have the same level of information, without any anonymisation, as the major-incident notifications and reports received from financial entities.
Article 13
The Regulation entered into force on the twentieth day after Official Journal publication, is binding in its entirety, and is directly applicable in all Member States.
9. Rapid Review: Thresholds and Tests
Flip each card, state the rule aloud, then check whether you preserved the condition and the mandatory or optional wording.
- Article 8 major-incident rule
- Critical services under Article 6 must be affected, and either Article 9(5)(b) is met or two or more other Article 9 thresholds are met.
- Recurring incidents
- They must occur at least twice within 6 months, have the same apparent root cause, and collectively meet Article 8(1). Assessment is monthly, subject to the stated exclusions.
- Article 9 client percentage
- The threshold is met where affected clients are higher than 10% of all clients using the affected service.
- Duration and downtime
- Duration longer than 24 hours, or downtime longer than 2 hours for ICT services supporting critical or important functions.
- Economic impact
- Included incident costs and losses are summed without accounting for financial recoveries. The threshold is exceeded or likely exceeded at EUR 100,000.
- Significant cyber threat
- All Article 10 conditions are required: potential impact, high probability of materialisation, and potential to meet the specified criticality or materiality consequence.
- Article 12 sharing standard
- Information shared shall contain the same level of information, without any anonymisation, as notifications and reports received from financial entities.
Key Terms
- data integrity
- Whether non-authorised modification made data inaccurate or incomplete.
- major incident
- An incident satisfying Article 8's critical-services requirement and one of its two alternative materiality routes.
- affected service
- The service used as the reference point for Article 9(1) client, financial-counterpart, and transaction thresholds.
- data authenticity
- The trustworthiness of the source of data.
- data availability
- Whether data on demand have become temporarily or permanently inaccessible or unusable.
- recurring incident
- An individually non-major incident that may be aggregated under Article 8(2) when all stated conditions are met.
- geographical spread
- An Article 4 assessment of impact in other Member States; under Article 9(4), the threshold is met where there is impact in two or more Member States.
- data confidentiality
- Whether data were accessed by or disclosed to an unauthorised party or system.
- financial recoveries
- Amounts that Article 7(1) says are not accounted for when calculating incurred direct and indirect incident costs and losses.
- significant cyber threat
- A cyber threat for Article 18(2) of Regulation (EU) 2022/2554 that fulfils all Article 10 conditions.
- critical or important functions
- Functions supported by ICT services or network and information systems whose involvement is assessed under Article 6(a).