SkarpSkarp

Chapter 10 of 11

Regulation 2025/301: Major Incident Reports, Deadlines, and Voluntary Cyber-Threat Notifications

Classification becomes regulatory communication under Regulation 2025/301. This chapter moves from the lean initial notification to detailed intermediate and final reports, testing each deadline and extension rule before examining voluntary significant cyber-threat notifications and the instrument’s legislative references.

19 min readen

1. Orientation: What Regulation 2025/301 Does

Purpose

Regulation 2025/301 supplements DORA by specifying what financial entities report about major ICT-related incidents and when they report it.

Legal basis and status

The legal basis includes "and in particular Article 20, third subparagraph thereof". Article 7 made the Regulation effective from 12 March 2025.

Three reports, one voluntary route

The operational sequence is initial notification, intermediate report, and final report. Article 6 separately covers voluntary notifications of significant cyber threats.

2. Recitals: Why the Reporting Design Looks This Way

Harmonisation

Recital (1) says "the time limits for reporting major ICT-related incidents should follow a consistent approach for all types of financial entities".

Lean initial notification

Recital (2) says "the content of the initial notification should be limited to the most significant information" while the entity is managing the incident.

Proportionality and voluntary notices

Recital (5) addresses microenterprises, non-significant entities, weekends, and bank holidays. Recital (6) frames voluntary threat notifications as more limited.

3. Article 1: General Information in Every Report

A common information layer

Article 1 applies to all three mandatory submissions: the initial notification, intermediate report, and final report.

Identity fields

Every submission includes "the name of the financial entity, its LEI code, and the type of financial entity, as referred to in Article 2(1) of Regulation (EU) 2022/2554".

Keep the qualifiers

Aggregation, parent-undertaking identification, and currency fields retain Article 1's conditions: "where applicable" and "where there is monetary impact".

4. Article 2: Building the Initial Notification

Initial-notification content

Article 2 requires the entity's incident code, detection and classification timing, description, classification basis, affected Member States, discovery method, and other specified fields.

Classification must be explained

The notice includes "the criteria, laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772, on the basis of which the financial entity classified the ICT-related incident as major".

Example

A payment-system outage may be described quickly in the initial notification, but a full investigation of why it occurred is reserved for the final report.

5. Quiz: Initial Notification Scope

Choose the best answer based on Article 2.

Which item is expressly required only "where available" in Article 2?

  1. Information about the origin of the ICT-related incident
  2. The incident reference code assigned by the financial entity
  3. The Member States impacted by the ICT-related incident
  4. Information on whether a business continuity plan was activated
Show Answer

Answer: A) Information about the origin of the ICT-related incident

Article 2(g) requires information about the incident's origin "where available". The incident reference code, impacted Member States, and business-continuity-plan information are listed without that qualifier.

6. Article 3: The Intermediate Report

From alert to operational detail

Article 3 moves beyond the first alert. It covers occurrence, affected functions, supporting infrastructure, client financial interests, reporting to other authorities, and recovery.

Recovery actions

The intermediate report includes "temporary actions or measures taken or planned to be taken by the financial entity to recover from the ICT-related incident".

Conditional information remains conditional

Competent-authority codes, recovery time, threat-actor information, and indicators of compromise are included "where applicable".

7. Article 4: The Final Report

Root cause and resolution

The final report includes "information about the root causes of the ICT-related incident" and the dates and times of resolution and root-cause remediation.

Financial consequences

Article 4 requires "information about direct and indirect costs and losses stemming from the ICT-related incident and information about financial recoveries".

What Article 4 does not add

Article 4 requires the listed information, but this provision does not itself set a method for calculating costs, losses, or recoveries.

8. Article 5: Calculate the Reporting Deadlines

Initial deadline

Submit as early as possible and, in any event, "within four hours from the classification of the ICT-related incident as a major ICT-related incident and no later than 24 hours from the moment the financial entity has become aware of the ICT-related incident".

Intermediate and updated reports

The intermediate report is due within 72 hours of the initial notification even if nothing has changed. An updated intermediate report is required without undue delay and when regular activities recover.

Final deadline

The final report is due no later than one month after the intermediate report, or, where applicable, the latest updated intermediate report.

Delay notice

If submission is impossible within time, the entity must inform the competent authority without undue delay, by the relevant deadline at the latest, and explain why.

Weekend rule is conditional

A noon-next-working-day option may apply when a deadline falls on a weekend or bank holiday, but Article 5(5) and Article 5(6) create important exclusions.

9. Timeline Exercise: Apply Article 5

Build the reporting timeline

A financial entity becomes aware of an ICT-related incident at 08:00 on Monday. It classifies the incident as major at 11:00 on Monday. It submits its initial notification at 13:30 on Monday. Regular activities recover at 09:00 on Thursday.

Work through these questions before revealing your answer:

  1. What is the latest initial-notification deadline under Article 5(1)(a)?
  2. What is the latest intermediate-report deadline under Article 5(1)(b)?
  3. Does recovery trigger an updated intermediate report?
  4. From which submission is the final-report deadline calculated in this scenario?

Suggested answer

  1. The four-hour deadline from classification is 15:00 Monday. The 24-hour outer limit from awareness is 08:00 Tuesday. The earlier applicable limit is 15:00 Monday. The 13:30 submission is timely.
  2. The intermediate report is due no later than 13:30 Thursday, 72 hours after the initial notification.
  3. Yes. Article 5(1)(b) says: "Financial entities shall submit an updated intermediate report without undue delay, and in any case when the regular activities have been recovered".
  4. The final report is due no later than one month after the latest updated intermediate report, where applicable. The scenario does not state exactly when the updated intermediate report was submitted, so it does not permit calculation of a calendar deadline beyond that rule.

10. Article 6: Voluntary Notifications of Significant Cyber Threats

A voluntary notification

Article 6 covers a voluntary notification of a significant cyber threat under DORA Article 19(2), rather than the mandatory three-report sequence for a major incident.

Potential impact and counterfactual test

The notice includes potential impact and the criteria that would have triggered a major incident report if the cyber threat had materialised.

Prevention and indicators

Where applicable, the entity describes preventive actions and includes indicators of compromise. Other relevant information is included where available.

11. Key Rules to Recall

Flip each card and test whether you can connect the requirement to the correct Article.

Article 1
Applies general information to initial notifications, intermediate reports, and final reports, including entity identity, LEI code, submitter, contacts, and conditional aggregation, group, and currency details.
Initial notification deadline
As early as possible and, in any event, within four hours from classification as major and no later than 24 hours from awareness of the ICT-related incident.
Intermediate report deadline
At the latest within 72 hours from submission of the initial notification, even if the status or handling of the incident has not changed.
Updated intermediate report
Submit without undue delay and, in any case, when regular activities have been recovered.
Final report deadline
No later than one month after the intermediate report or, where applicable, the latest updated intermediate report.
Delay notice
Inform the competent authority without undue delay, no later than the relevant reporting deadline, and explain the reasons for the delay.
Article 6 counterfactual
Identify the criteria in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 that would have triggered a major incident report if the cyber threat had materialised.
Article 7
This Regulation shall enter into force on the twentieth day following publication in the Official Journal and shall be binding in its entirety and directly applicable in all Member States.

Key Terms

DORA
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.
LEI code
Legal Entity Identifier code used to identify a legal entity.
Document ELI
ELI: http://data.europa.eu/eli/reg_del/2025/301/oj
Final report
The report under Article 19(4)(c) of DORA and Article 4 of Regulation 2025/301, including causes, resolution, costs, losses, and recoveries.
DORA citation
OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.
NIS 2 Directive
Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union.
Financial entity
An entity within the scope referred to in Article 2(1) of Regulation (EU) 2022/2554.
Intermediate report
The more detailed report under Article 19(4)(b) of DORA and Article 3 of Regulation 2025/301.
Initial notification
The first, time-critical submission on a major ICT-related incident under Article 19(4)(a) of DORA and Article 2 of Regulation 2025/301.
Publication identifier
ISSN 1977-0677 (electronic edition)
Indicators of compromise
Information that may indicate that a system, account, device, or environment has been compromised; Articles 3 and 6 require it where applicable.
Significant cyber threat
A cyber threat that may be voluntarily notified under Article 19(2) of DORA, using the content requirements in Article 6 of Regulation 2025/301.
Major ICT-related incident
An ICT-related incident that a financial entity has classified as major using the relevant criteria, including those in Delegated Regulation (EU) 2024/1772.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself