Chapter 10 of 11
Regulation 2025/301: Major Incident Reports, Deadlines, and Voluntary Cyber-Threat Notifications
Classification becomes regulatory communication under Regulation 2025/301. This chapter moves from the lean initial notification to detailed intermediate and final reports, testing each deadline and extension rule before examining voluntary significant cyber-threat notifications and the instrument’s legislative references.
1. Orientation: What Regulation 2025/301 Does
Purpose
Regulation 2025/301 supplements DORA by specifying what financial entities report about major ICT-related incidents and when they report it.
Legal basis and status
The legal basis includes "and in particular Article 20, third subparagraph thereof". Article 7 made the Regulation effective from 12 March 2025.
Three reports, one voluntary route
The operational sequence is initial notification, intermediate report, and final report. Article 6 separately covers voluntary notifications of significant cyber threats.
2. Recitals: Why the Reporting Design Looks This Way
Harmonisation
Recital (1) says "the time limits for reporting major ICT-related incidents should follow a consistent approach for all types of financial entities".
Lean initial notification
Recital (2) says "the content of the initial notification should be limited to the most significant information" while the entity is managing the incident.
Proportionality and voluntary notices
Recital (5) addresses microenterprises, non-significant entities, weekends, and bank holidays. Recital (6) frames voluntary threat notifications as more limited.
3. Article 1: General Information in Every Report
A common information layer
Article 1 applies to all three mandatory submissions: the initial notification, intermediate report, and final report.
Identity fields
Every submission includes "the name of the financial entity, its LEI code, and the type of financial entity, as referred to in Article 2(1) of Regulation (EU) 2022/2554".
Keep the qualifiers
Aggregation, parent-undertaking identification, and currency fields retain Article 1's conditions: "where applicable" and "where there is monetary impact".
4. Article 2: Building the Initial Notification
Initial-notification content
Article 2 requires the entity's incident code, detection and classification timing, description, classification basis, affected Member States, discovery method, and other specified fields.
Classification must be explained
The notice includes "the criteria, laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772, on the basis of which the financial entity classified the ICT-related incident as major".
Example
A payment-system outage may be described quickly in the initial notification, but a full investigation of why it occurred is reserved for the final report.
5. Quiz: Initial Notification Scope
Choose the best answer based on Article 2.
Which item is expressly required only "where available" in Article 2?
- Information about the origin of the ICT-related incident
- The incident reference code assigned by the financial entity
- The Member States impacted by the ICT-related incident
- Information on whether a business continuity plan was activated
Show Answer
Answer: A) Information about the origin of the ICT-related incident
Article 2(g) requires information about the incident's origin "where available". The incident reference code, impacted Member States, and business-continuity-plan information are listed without that qualifier.
6. Article 3: The Intermediate Report
From alert to operational detail
Article 3 moves beyond the first alert. It covers occurrence, affected functions, supporting infrastructure, client financial interests, reporting to other authorities, and recovery.
Recovery actions
The intermediate report includes "temporary actions or measures taken or planned to be taken by the financial entity to recover from the ICT-related incident".
Conditional information remains conditional
Competent-authority codes, recovery time, threat-actor information, and indicators of compromise are included "where applicable".
7. Article 4: The Final Report
Root cause and resolution
The final report includes "information about the root causes of the ICT-related incident" and the dates and times of resolution and root-cause remediation.
Financial consequences
Article 4 requires "information about direct and indirect costs and losses stemming from the ICT-related incident and information about financial recoveries".
What Article 4 does not add
Article 4 requires the listed information, but this provision does not itself set a method for calculating costs, losses, or recoveries.
8. Article 5: Calculate the Reporting Deadlines
Initial deadline
Submit as early as possible and, in any event, "within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident".
Intermediate and updated reports
The intermediate report is due within 72 hours of the initial notification even if nothing has changed. An updated intermediate report is required without undue delay and when regular activities recover.
Final deadline
The final report is due no later than one month after the intermediate report, or, where applicable, the latest updated intermediate report.
Delay notice
If submission is impossible within time, the entity must inform the competent authority without undue delay, by the relevant deadline at the latest, and explain why.
Weekend rule is conditional
A noon-next-working-day option may apply when a deadline falls on a weekend or bank holiday, but Article 5(5) and Article 5(6) create important exclusions.
9. Timeline Exercise: Apply Article 5
Build the reporting timeline
A financial entity becomes aware of an ICT-related incident at 08:00 on Monday. It classifies the incident as major at 11:00 on Monday. It submits its initial notification at 13:30 on Monday. Regular activities recover at 09:00 on Thursday.
Work through these questions before revealing your answer:
- What is the latest initial-notification deadline under Article 5(1)(a)?
- What is the latest intermediate-report deadline under Article 5(1)(b)?
- Does recovery trigger an updated intermediate report?
- From which submission is the final-report deadline calculated in this scenario?
Suggested answer
- The four-hour deadline from classification is 15:00 Monday. The 24-hour outer limit from awareness is 08:00 Tuesday. The earlier applicable limit is 15:00 Monday. The 13:30 submission is timely.
- The intermediate report is due no later than 13:30 Thursday, 72 hours after the initial notification.
- Yes. Article 5(1)(b) says: "Financial entities shall submit an updated intermediate report without undue delay, and in any case when the regular activities have been recovered".
- The final report is due no later than one month after the latest updated intermediate report, where applicable. The scenario does not state exactly when the updated intermediate report was submitted, so it does not permit calculation of a calendar deadline beyond that rule.
10. Article 6: Voluntary Notifications of Significant Cyber Threats
A voluntary notification
Article 6 covers a voluntary notification of a significant cyber threat under DORA Article 19(2), rather than the mandatory three-report sequence for a major incident.
Potential impact and counterfactual test
The notice includes potential impact and the criteria that would have triggered a major incident report if the cyber threat had materialised.
Prevention and indicators
Where applicable, the entity describes preventive actions and includes indicators of compromise. Other relevant information is included where available.
11. Key Rules to Recall
Flip each card and test whether you can connect the requirement to the correct Article.
- Article 1
- Applies general information to initial notifications, intermediate reports, and final reports, including entity identity, LEI code, submitter, contacts, and conditional aggregation, group, and currency details.
- Initial notification deadline
- As early as possible and, in any event, within four hours from classification as major and no later than 24 hours from awareness of the ICT-related incident.
- Intermediate report deadline
- At the latest within 72 hours from submission of the initial notification, even if the status or handling of the incident has not changed.
- Updated intermediate report
- Submit without undue delay and, in any case, when regular activities have been recovered.
- Final report deadline
- No later than one month after the intermediate report or, where applicable, the latest updated intermediate report.
- Delay notice
- Inform the competent authority without undue delay, no later than the relevant reporting deadline, and explain the reasons for the delay.
- Article 6 counterfactual
- Identify the criteria in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 that would have triggered a major incident report if the cyber threat had materialised.
- Article 7
- This Regulation shall enter into force on the twentieth day following publication in the Official Journal and shall be binding in its entirety and directly applicable in all Member States.
Key Terms
- DORA
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.
- LEI code
- Legal Entity Identifier code used to identify a legal entity.
- Document ELI
- ELI: http://data.europa.eu/eli/reg_del/2025/301/oj
- Final report
- The report under Article 19(4)(c) of DORA and Article 4 of Regulation 2025/301, including causes, resolution, costs, losses, and recoveries.
- DORA citation
- OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.
- NIS 2 Directive
- Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.
- Financial entity
- An entity within the scope referred to in Article 2(1) of Regulation (EU) 2022/2554.
- Intermediate report
- The more detailed report under Article 19(4)(b) of DORA and Article 3 of Regulation 2025/301.
- Initial notification
- The first, time-critical submission on a major ICT-related incident under Article 19(4)(a) of DORA and Article 2 of Regulation 2025/301.
- Publication identifier
- ISSN 1977-0677 (electronic edition)
- Indicators of compromise
- Information that may indicate that a system, account, device, or environment has been compromised; Articles 3 and 6 require it where applicable.
- Significant cyber threat
- A cyber threat that may be voluntarily notified under Article 19(2) of DORA, using the content requirements in Article 6 of Regulation 2025/301.
- Major ICT-related incident
- An ICT-related incident that a financial entity has classified as major using the relevant criteria, including those in Delegated Regulation (EU) 2024/1772.