Article 3 Specific information to be provided in intermediate reports

Intermediate reports as referred to in Article 19(4), point (b), of Regulation (EU) 2022/2554 shall contain at least all of the following specific information:

  1. (a)
    where applicable, the incident reference code provided by the competent authority;
  2. (b)
    the date and time of occurrence of the ICT-related incident;
  3. (c)
    where applicable, the date and time when the financial entity has recovered its regular activities;
  4. (d)
    information about how the criteria laid down in Articles 1 to 8 of Delegated Regulation (EU) 2024/1772 have been fulfilled, on the basis of which the financial entity classified the ITC-related incident as major;
  5. (e)
    the type of ICT-related incident;
  6. (f)
    where applicable, the threats and techniques used by the threat actor;
  7. (g)
    affected functional areas and business processes;
  8. (h)
    affected infrastructure components supporting business processes;
  9. (i)
    impact on the financial interest of clients;
  10. (j)
    information about reporting about the ICT-related incident to other authorities;
  11. (k)
    temporary actions or measures taken or planned to be taken by the financial entity to recover from the ICT-related incident;
  12. (l)
    where applicable, information on indicators of compromise.