Financial entities report major ICT-related incidents to their single designated competent authority (significant credit institutions report to the national authority, which passes the report to the ECB), using the Article 20 templates, with an alternative channel where a technical problem blocks the initial notification; Member States may also require copies to NIS2 authorities or CSIRTs. Under Commission Delegated Regulation (EU) 2025/301, Article 5, the clocks are: initial notification as early as possible and within 4 hours of classifying the incident as major, but no later than 24 hours after becoming aware of it (Art. 5(1)(a)); where the incident is classified as major only after that 24-hour point, within 4 hours of classification (Art. 5(2)); intermediate report within 72 hours of submitting the initial notification even if nothing has changed, plus a further updated intermediate report promptly, and at the latest once regular activities are recovered (Art. 5(1)(b)); final report at the latest one month after the intermediate report or, where updates were filed, the latest updated intermediate report (Art. 5(1)(c)). An entity that cannot meet a deadline must tell the authority and give reasons before it expires (Art. 5(3)). A deadline falling on a weekend or bank holiday may move to noon of the next working day (Art. 5(4)), except for initial and intermediate submissions by credit institutions, central counterparties, trading venue operators and NIS2 essential or important entities (Art. 5(5)), and competent authorities may withdraw that relief from other significant or systemic entities (Art. 5(6)). Where a major incident affects the financial interests of clients, they are told without undue delay about it and the mitigation taken (Art. 19(3)). Significant cyber threats may be notified voluntarily. Reporting may be outsourced, but the entity stays responsible (Art. 19(5)).
This control maps to 34 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
DORA DORA-Art.19 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of DORA your existing evidence covers. Hold NIS2 Directive and 17 of 26 DORA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the NIS2 Directive pair alone.
The graph holds this control, the 34 it maps to, and the evidence behind each claim, over MCP and REST.