Skip to content

RTS (EU) 2025/301 – Incident Reporting

PropertyValue
NumberDelegated Regulation (EU) 2025/301
DORA ArticleArt. 20(1)(a)
PillarP2 – Incident Reporting
Adoption23.10.2024
Publication20.02.2025
Applicable since17.01.2025
EUR-LexLink

Content

Defines the content and deadlines of the 3-stage reporting chain:

StageDeadlineMandatory Content
Initial notification4h after classification (max. 24h after detection)Who, what, when, initial assessment
Intermediate report72h after initial notificationStatus update, impact analysis, action plan
Final report1 month after initial notificationRoot cause, lessons learned, measures

As well as voluntary reporting of significant cyber threats.

Missing a deadline = DORA violation → sanctions per Art. 50–52 DORA in conjunction with national implementation (FinmadiG).

→ Details: P2: Incident Reporting | Incident Pipeline

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT