Source: OJ L, 2025/302, 20.2.2025

Current language: DE

Artikel 5 Rückstufung schwerwiegender IKT-bezogener Vorfälle


Summary What does Article 5 of the ITS on templates for incident reporting say?

This article addresses the scenario where a financial entity, upon further review, determines that an ICT-related incident it previously reported as major never actually met the classification criteria for being major in the first place.

It sets out the procedure for correcting that classification by formally notifying the competent authority of the reclassification from major to non-major.

This article acts as a corrective mechanism that sits alongside the broader reporting framework established in earlier articles of this regulation.

Important points:

  • If you previously reported an incident as major but later conclude it never met the threshold, notify the competent authority of the reclassification.
  • Use the template in Annex II, specifically the fields 'type of report' and 'other information', to communicate the reclassification.
  • The trigger is a conclusion that the incident never fulfilled the classification criteria at any point in time, not merely that it ceased to qualify after the fact.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Kommt das Finanzunternehmen nach eingehender Prüfung zu dem Schluss, dass der zuvor als „schwerwiegend“ gemeldete IKT-bezogene Vorfall zu keinem Zeitpunkt die in Artikel 8 der Delegierten Verordnung (EU) 2024/1772 festgelegten Einstufungskriterien und Schwellenwerte erfüllte, so teilt es der zuständigen Behörde mit, dass es den IKT-bezogenen Vorfall von „schwerwiegend“ auf „nicht schwerwiegend“ zurückgestuft hat, und macht in der Vorlage in Anhang II dieser Verordnung in den Feldern „Art der Meldung“ und „Sonstige Informationen“ entsprechende Angaben zu dieser Rückstufung.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod