Resiliencestopped beinga policy andbecame a duty.
- In force
- 16 January 2023
- Applies from
- 17 January 2025
- Binds
- 21 types of financial entity
- Reaches
- Their ICT third-party providers
Twenty-one kinds of financial entity, and the providers behind them.
What it requires
An ICT risk framework the board owns
The management body carries the responsibility and cannot delegate it away. The framework has to be documented, reviewed, and tested against the entity's own dependencies rather than a template.
A major incident is reported on the clock
Major ICT-related incidents are classified and notified to the competent authority. The technical standards set the timing: an initial notification within four hours of the incident being classified as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of that notification, and a final report within one month.
Threat-led penetration testing, at least every three years
Entities identified by their authority carry out advanced testing on live production systems. Significant institutions use external red team testers; an entity testing with its own people has to bring external testers in every third test.
The testers themselves must be insured
Testers must be certified, possess the necessary expertise and suitability, and hold professional indemnity insurance. It is one of the few places where a European regulation names insurance as a condition of doing the work at all.
A register of every ICT arrangement
A register of information on all contractual arrangements with ICT third-party service providers, maintained at entity, sub-consolidated and consolidated level, in the format set by Commission Implementing Regulation (EU) 2024/2956. It is the document that turns 'we use a cloud provider' into a supervisable fact.
Critical providers are supervised directly
ICT third-party providers designated critical fall under a Union oversight framework with a lead overseer, alongside the supervision of the entities using them. Concentration in a handful of providers became a regulatory subject rather than a market observation.