- Classification criteria and materiality thresholds for major ICT-related incidents and significant cyber threats.
References and citations
- Criteria for identifying financial entities required to perform threat-led penetration testing.
- Content and time limits for initial and subsequent incident reports under DORA.
- Defines standard templates (B_01-B_07) for the register of information and its relational structure.
- Defines the actual reporting forms and procedures used for major ICT incident submissions.
- Confirms the first published list of designated critical ICT third-party providers on 18 November 2025.
- Primary DORA legal text (application date in Article 64; register of information in Article 28; enforcement framework in Articles 50-55).