Critical or important functions: making the determination defensible
The determination that feeds both obligations.
Read the guide →Two obligations, one dependency map. The register is an annual dataset; incident reporting is a clock that starts the moment an incident is classified. What connects them is the function and provider data underneath both.
Delegated Regulation (EU) 2024/1772 sets out the criteria for classifying ICT-related incidents and the materiality thresholds attached to them. The criteria cover clients, financial counterparts and transactions affected; reputational impact; duration and service downtime; geographical spread; data losses affecting availability, authenticity, integrity or confidentiality; and the criticality of the services disrupted.
The determination is quantitative rather than impressionistic, which has a practical consequence: the measurements have to be available during an incident, not reconstructed afterwards. A firm that cannot count affected clients while the incident is running cannot classify it on time.
| Stage | Purpose |
|---|---|
| Initial notification | Tells the authority an incident has been classified as major, with what is known at that point. Estimates are permitted where precise data is not yet available. |
| Intermediate report | Updates the picture. Required even where the status and handling have not changed — silence is not an option. |
| Final report | Root cause analysis, full impact assessment and the remediation completed. |
Content and time limits are set out in Commission Delegated Regulation (EU) 2025/301, and the templates in the corresponding implementing standards. Significant cyber threats can be notified voluntarily under a separate, lighter template.
Across the three stages the reports draw on: the affected functions and whether they are critical or important; the ICT third-party service providers involved; the clients, counterparties and transactions affected; the duration and downtime against recovery objectives; the member states affected; the classification criteria met and the values behind them; and, by the final report, root cause and remediation.
The first two of those are exactly what the register holds. The rest are operational measurements that no annual dataset can supply.
The register is a periodic supervisory dataset with fixed templates and an annual rhythm. Incident reporting is event-driven, runs on hours and days, and asks for measurements the register does not hold. Building one process to serve both fails in the same way combining EMIR and MiFIR does: the shared part is the reference data, not the workflow.
Primary instruments only. Each is named in full so the reference remains traceable even if a link moves.
Yes. The intermediate report is required within its time limit even where the status or handling of the incident has not changed since the initial notification. Teams that treat it as conditional on new information miss it routinely.
Yes, where precise data is not yet available — that is the point of a staged cycle. What matters is that estimates are identified as such and updated in the later reports rather than left standing.
If it is an ICT-related incident affecting your functions, the reporting obligation is yours regardless of where it originated. This is why the register's provider and supply-chain data is operationally useful during an incident, not just annually.
Not because of the incident itself. It needs updating when the arrangement, the provider, the supply chain or the criticality of a function changes — which an incident sometimes causes but does not automatically mean.
REGREP is an independent software provider. This record explains a reporting framework in plain language and is not legal, tax or regulatory advice. Confirm scope, thresholds and submission dates with your competent authority before you file.
More on this framework, and the module that produces the filing.
The determination that feeds both obligations.
Read the guide →The dataset an incident response draws on.
Read the guide →Scope, obligations and supervisory powers.
Read the requirements →A maintained register is the fastest source of provider identity and function impact when the clock is already running.