Open navigation
Search
Offices – Italy
Explore all Offices
Global Reach

Apart from offering expert legal consultancy for local jurisdictions, CMS partners up with you to effectively navigate the complexities of global business and legal environments.

Explore our reach
Insights – Italy
Explore all insights
Search
Expertise
Insights

CMS lawyers can provide future-facing advice for your business across a variety of specialisms and industries, worldwide.

Explore topics
Offices
Global Reach

Apart from offering expert legal consultancy for local jurisdictions, CMS partners up with you to effectively navigate the complexities of global business and legal environments.

Explore our reach
CMS Italy
Insights
Trending Topics
About CMS

Select your region

Newsletter 20 Feb 2025 · Italy

IVASS Letter to the Market no. 31644/2025: Reports of Major Cyber Incidents and Cyber Threats pursuant to EU Regulation 2022/2554 (DORA)

3 min read

On this page

With Letter to the Market no. 31644 dated 14.02.2025, IVASS communicates the operational procedures by which

  • insurers and reinsurers with registered offices in Italy;
  • insurers with registered offices in a third country (outside the EEA) with a branch in Italy;
  • insurance, reinsurance and ancillary intermediaries (excluding SMEs, i.e. intermediaries with (i) fewer than 250 employees and (ii) annual turnover of less than EUR 50 million or (iii) a balance sheet total of less than EUR 43 million);

will have to send, in accordance with EU Regulation 2022/2554 (i.e., the “Digital Operational Resilience Act” or “DORA”), applicable from 17.01.2025, to IVASS the reports relating to:
 

  • to major cyber incidents
    (i.e., incidents related to Information and Communication Technologies (ICT) that have a high adverse impact on the network and information systems that support critical or important functions of the financial entity); and
  • on a voluntary basis, to significant cyber threats relevant to the financial system, service users or customers

(i.e., cyber threats whose the technical characteristics of which indicate that it could have the potential to result in a major ICT-related incident or a major operational or security payment-related incident);

as provided for and defined in the Dora Regulation, and governed by Commission Delegated Regulation EU 2024/1772 and the related Delegated Acts (RTS and ITS) (the “Delegated Acts”).

In particular, the Delegated Acts have established the following deadlines for the completion of the three phases required for notification to IVASS (in this case, the competent Authorities of reference):

  1. an initial notification, within 24 hours of the identification of the incident;
  2. an interim report, within 72 hours of the initial notification, with the possibility of sending subsequent updates;
  3. a final report, within one month of sending the last update of the interim report.

The content of the notifications is increasingly detailed and is specified in the Delegated Acts themselves.

Finally, IVASS provides a template to be filled in according to the procedures set out in the Delegated Acts and the certified email addresses (PEC) to which, within the above deadlines, insurers and intermediaries subject to DORA must send reports of major cyber incidents and significant cyber threats; in particular:

The Letter to the Market is available – for the time being – only in Italian at the following link: https://www.ivass.it/normativa/nazionale/secondaria-ivass/lettere/2025/lm-14-02-2025/Lettera_al_mercato_14_02_2025.pdf

Back to top