REGULATIONS
on digital operational resilience for the financial sector and amending Regulations (EC)
I
(Legislative acts)
REGULATIONS
REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
of 14 December 2022
on digital operational resilience for the financial sector and amending Regulations (EC)
No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/
(Text with EEA relevance)
THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
Having regard to the proposal from the European Commission,
After transmission of the draft legislative act to the national parliaments,
Having regard to the opinion of the European Central Bank(^1 ),
Having regard to the opinion of the European Economic and Social Committee(^2 ),
Acting in accordance with the ordinary legislative procedure(^3 ),
Whereas:
(1) In the digital age, information and communication technology (ICT) supports complex systems used for everyday
activities. It keeps our economies running in key sectors, including the financial sector, and enhances the
functioning of the internal market. Increased digitalisation and interconnectedness also amplify ICT risk, making
society as a whole, and the financial system in particular, more vulnerable to cyber threats or ICT disruptions. While
the ubiquitous use of ICT systems and high digitalisation and connectivity are today core features of the activities of
Union financial entities, their digital resilience has yet to be better addressed and integrated into their broader
operational frameworks.
(2) The use of ICT has in the past decades gained a pivotal role in the provision of financial services, to the point where it
has now acquired a critical importance in the operation of typical daily functions of all financial entities.
Digitalisation now covers, for instance, payments, which have increasingly moved from cash and paper-based
methods to the use of digital solutions, as well as securities clearing and settlement, electronic and algorithmic
trading, lending and funding operations, peer-to-peer finance, credit rating, claim management and back-office
operations. The insurance sector has also been transformed by the use of ICT, from the emergence of insurance
(^1 ) OJ C 343, 26.8.2021, p. 1.
(^2 ) OJ C 155, 30.4.2021, p. 38.
(^3 ) Position of the European Parliament of 10 November 2022 (not yet published in the Official Journal) and decision of the Council of
28 November 2022.
27.12.2022 EN Official Journal of the European Union L 333/
intermediaries offering their services online operating with InsurTech, to digital insurance underwriting. Finance has
not only become largely digital throughout the whole sector, but digitalisation has also deepened interconnections
and dependencies within the financial sector and with third-party infrastructure and service providers.
(3) The European Systemic Risk Board (ESRB) reaffirmed in a 2020 report addressing systemic cyber risk how the
existing high level of interconnectedness across financial entities, financial markets and financial market
infrastructures, and particularly the interdependencies of their ICT systems, could constitute a systemic vulnerability
because localised cyber incidents could quickly spread from any of the approximately 22 000 Union financial
entities to the entire financial system, unhindered by geographical boundaries. Serious ICT breaches that occur in
the financial sector do not merely affect financial entities taken in isolation. They also smooth the way for the
propagation of localised vulnerabilities across the financial transmission channels and potentially trigger adverse
consequences for the stability of the Union’s financial system, such as generating liquidity runs and an overall loss
of confidence and trust in financial markets.
(4) In recent years, ICT risk has attracted the attention of international, Union and national policy makers, regulators and
standard-setting bodies in an attempt to enhance digital resilience, set standards and coordinate regulatory or
supervisory work. At international level, the Basel Committee on Banking Supervision, the Committee on Payments
and Market Infrastructures, the Financial Stability Board, the Financial Stability Institute, as well as the G7 and G
aim to provide competent authorities and market operators across various jurisdictions with tools to bolster the
resilience of their financial systems. That work has also been driven by the need to duly consider ICT risk in the
context of a highly interconnected global financial system and to seek more consistency of relevant best practices.
(5) Despite Union and national targeted policy and legislative initiatives, ICT risk continues to pose a challenge to the
operational resilience, performance and stability of the Union financial system. The reforms that followed the 2008
financial crisis primarily strengthened the financial resilience of the Union financial sector and aimed to safeguard
the competitiveness and stability of the Union from economic, prudential and market conduct perspectives.
Although ICT security and digital resilience are part of operational risk, they have been less in the focus of the post-
financial crisis regulatory agenda and have developed in only some areas of the Union’s financial services policy and
regulatory landscape, or in only a few Member States.
(6) In its Communication of 8 March 2018 entitled ‘FinTech Action plan: For a more competitive and innovative
European financial sector’, the Commission highlighted the paramount importance of making the Union financial
sector more resilient, including from an operational perspective to ensure its technological safety and good
functioning, its quick recovery from ICT breaches and incidents, ultimately enabling the effective and smooth
provision of financial services across the whole Union, including under situations of stress, while also preserving
consumer and market trust and confidence.
(7) In April 2019, the European Supervisory Authority (European Banking Authority), (EBA) established by Regulation
(EU) No 1093/2010 of the European Parliament and of the Council(^4 ), the European Supervisory Authority
(European Insurance and Occupational Pensions Authority), (‘EIOPA’) established by Regulation (EU)
No 1094/2010 of the European Parliament and of the Council(^5 )and the European Supervisory Authority
(European Securities and Markets Authority), (‘ESMA’) established by Regulation (EU) No 1095/2010 of the
(^4 ) Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision
2009/78/EC (OJ L 331, 15.12.2010, p. 12).
(^5 ) Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and
repealing Commission Decision 2009/79/EC (OJ L 331, 15.12.2010, p. 48).
L 333/2 EN Official Journal of the European Union 27.12.
European Parliament and of the Council(^6 )(known collectively as ‘European Supervisory Authorities’ or ‘ESAs’)
jointly issued technical advice calling for a coherent approach to ICT risk in finance and recommending to
strengthen, in a proportionate way, the digital operational resilience of the financial services industry through a
sector-specific initiative of the Union.
(8) The Union financial sector is regulated by a Single Rulebook and governed by a European system of financial
supervision. Nonetheless, provisions tackling digital operational resilience and ICT security are not yet fully or
consistently harmonised, despite digital operational resilience being vital for ensuring financial stability and market
integrity in the digital age, and no less important than, for example, common prudential or market conduct
standards. The Single Rulebook and system of supervision should therefore be developed to also cover digital
operational resilience, by strengthening the mandates of competent authorities to enable them to supervise the
management of ICT risk in the financial sector in order to protect the integrity and efficiency of the internal market,
and to facilitate its orderly functioning.
(9) Legislative disparities and uneven national regulatory or supervisory approaches with regard to ICT risk trigger
obstacles to the functioning of the internal market in financial services, impeding the smooth exercise of the
freedom of establishment and the provision of services for financial entities operating on a cross-border basis.
Competition between the same type of financial entities operating in different Member States could also be
distorted. This is the case, in particular, for areas where Union harmonisation has been very limited, such as digital
operational resilience testing, or absent, such as the monitoring of ICT third-party risk. Disparities stemming from
developments envisaged at national level could generate further obstacles to the functioning of the internal market
to the detriment of market participants and financial stability.
(10) To date, due to the ICT risk related provisions being only partially addressed at Union level, there are gaps or overlaps
in important areas, such as ICT-related incident reporting and digital operational resilience testing, and
inconsistencies as a result of emerging divergent national rules or cost-ineffective application of overlapping rules.
This is particularly detrimental for an ICT-intensive user such as the financial sector since technology risks have no
borders and the financial sector deploys its services on a wide cross-border basis within and outside the Union.
Individual financial entities operating on a cross-border basis or holding several authorisations (e.g. one financial
entity can have a banking, an investment firm, and a payment institution licence, each issued by a different
competent authority in one or several Member States) face operational challenges in addressing ICT risk and
mitigating adverse impacts of ICT incidents on their own and in a coherent cost-effective way.
(11) As the Single Rulebook has not been accompanied by a comprehensive ICT or operational risk framework, further
harmonisation of key digital operational resilience requirements for all financial entities is required. The
development of ICT capabilities and overall resilience by financial entities, based on those key requirements, with a
view to withstanding operational outages, would help preserve the stability and integrity of the Union financial
markets and thus contribute to ensuring a high level of protection of investors and consumers in the Union. Since
this Regulation aims to contribute to the smooth functioning of the internal market, it should be based on the
provisions of Article 114 of the Treaty on the Functioning of the European Union (TFEU) as interpreted in
accordance with the consistent case law of the Court of Justice of the European Union (Court of Justice).
(12) This Regulation aims to consolidate and upgrade ICT risk requirements as part of the operational risk requirements
that have, up to this point, been addressed separately in various Union legal acts. While those acts covered the main
categories of financial risk (e.g. credit risk, market risk, counterparty credit risk and liquidity risk, market conduct
risk), they did not comprehensively tackle, at the time of their adoption, all components of operational resilience.
The operational risk rules, when further developed in those Union legal acts, often favoured a traditional
quantitative approach to addressing risk (namely setting a capital requirement to cover ICT risk) rather than targeted
qualitative rules for the protection, detection, containment, recovery and repair capabilities against ICT-related
(^6 ) Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European
Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission
Decision 2009/77/EC (OJ L 331, 15.12.2010, p. 84).
27.12.2022 EN Official Journal of the European Union L 333/
incidents, or for reporting and digital testing capabilities. Those acts were primarily meant to cover and update
essential rules on prudential supervision, market integrity or conduct. By consolidating and upgrading the different
rules on ICT risk, all provisions addressing digital risk in the financial sector should for the first time be brought
together in a consistent manner in one single legislative act. Therefore, this Regulation fills in the gaps or remedies
inconsistencies in some of the prior legal acts, including in relation to the terminology used therein, and explicitly
refers to ICT risk via targeted rules on ICT risk-management capabilities, incident reporting, operational resilience
testing and ICT third-party risk monitoring. This Regulation should thus also raise awareness of ICT risk and
acknowledge that ICT incidents and a lack of operational resilience have the possibility to jeopardise the soundness
of financial entities.
(13) Financial entities should follow the same approach and the same principle-based rules when addressing ICT risk
taking into account their size and overall risk profile, and the nature, scale and complexity of their services,
activities and operations. Consistency contributes to enhancing confidence in the financial system and preserving its
stability especially in times of high reliance on ICT systems, platforms and infrastructures, which entails increased
digital risk. Observing basic cyber hygiene should also avoid imposing heavy costs on the economy by minimising
the impact and costs of ICT disruptions.
(14) A Regulation helps reduce regulatory complexity, fosters supervisory convergence and increases legal certainty, and
also contributes to limiting compliance costs, especially for financial entities operating across borders, and to
reducing competitive distortions. Therefore, the choice of a Regulation for the establishment of a common
framework for the digital operational resilience of financial entities is the most appropriate way to guarantee a
homogenous and coherent application of all components of ICT risk management by the Union financial sector.
(15) Directive (EU) 2016/1148 of the European Parliament and of the Council(^7 )was the first horizontal cybersecurity
framework enacted at Union level, applying also to three types of financial entities, namely credit institutions,
trading venues and central counterparties. However, since Directive (EU) 2016/1148 set out a mechanism of
identification at national level of operators of essential services, only certain credit institutions, trading venues and
central counterparties that were identified by the Member States, have been brought into its scope in practice, and
hence required to comply with the ICT security and incident notification requirements laid down in it. Directive
(EU) 2022/2555 of the European Parliament and of the Council(^8 )sets a uniform criterion to determine the entities
falling within its scope of application (size-cap rule) while also keeping the three types of financial entities in its
scope.
(16) However, as this Regulation increases the level of harmonisation of the various digital resilience components, by
introducing requirements on ICT risk management and ICT-related incident reporting that are more stringent in
comparison to those laid down in the current Union financial services law, this higher level constitutes an increased
harmonisation also in comparison with the requirements laid down in Directive (EU) 2022/2555. Consequently, this
Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555. At the same time, it is crucial to
maintain a strong relationship between the financial sector and the Union horizontal cybersecurity framework as
currently laid out in Directive (EU) 2022/2555 to ensure consistency with the cyber security strategies adopted by
Member States and to allow financial supervisors to be made aware of cyber incidents affecting other sectors
covered by that Directive.
(^7 ) Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common
level of security of network and information systems across the Union (OJ L 194, 19.7.2016, p. 1).
(^8 ) Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level
of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive
(EU) 2016/1148 (NIS 2 Directive) (see page 80 of this Official Journal).
L 333/4 EN Official Journal of the European Union 27.12.
(17) In accordance with Article 4(2) of the Treaty on European Union and without prejudice to the judicial review by the
Court of Justice, this Regulation should not affect the responsibility of Member States with regard to essential State
functions concerning public security, defence and the safeguarding of national security, for example concerning the
supply of information which would be contrary to the safeguarding of national security.
(18) To enable cross-sector learning and to effectively draw on experiences of other sectors in dealing with cyber threats,
the financial entities referred to in Directive (EU) 2022/2555 should remain part of the ‘ecosystem’ of that Directive
(for example, Cooperation Group and computer security incident response teams (CSIRTs)).The ESAs and national
competent authorities should be able to participate in the strategic policy discussions and the technical workings of
the Cooperation Group under that Directive, and to exchange information and further cooperate with the single
points of contact designated or established in accordance with that Directive. The competent authorities under this
Regulation should also consult and cooperate with the CSIRTs. The competent authorities should also be able to
request technical advice from the competent authorities designated or established in accordance with Directive (EU)
2022/2555 and establish cooperation arrangements that aim to ensure effective and fast-response coordination
mechanisms.
(19) Given the strong interlinkages between the digital resilience and the physical resilience of financial entities, a
coherent approach with regard to the resilience of critical entities is necessary in this Regulation and Directive (EU)
2022/2557 of the European Parliament and the Council(^9 ). Given that the physical resilience of financial entities is
addressed in a comprehensive manner by the ICT risk management and reporting obligations covered by this
Regulation, the obligations laid down in Chapters III and IV of Directive (EU) 2022/2557 should not apply to
financial entities falling within the scope of that Directive.
(20) Cloud computing service providers are one category of digital infrastructure covered by Directive (EU) 2022/2555.
The Union Oversight Framework (‘Oversight Framework’) established by this Regulation applies to all critical ICT
third-party service providers, including cloud computing service providers providing ICT services to financial
entities, and should be considered complementary to the supervision carried out pursuant to Directive (EU) 2022/
- Moreover, the Oversight Framework established by this Regulation should cover cloud computing service providers in the absence of a Union horizontal framework establishing a digital oversight authority.
(21) In order to maintain full control over ICT risk, financial entities need to have comprehensive capabilities to enable a
strong and effective ICT risk management, as well as specific mechanisms and policies for handling all ICT-related
incidents and for reporting major ICT-related incidents. Likewise, financial entities should have policies in place for
the testing of ICT systems, controls and processes, as well as for managing ICT third-party risk. The digital
operational resilience baseline for financial entities should be increased while also allowing for a proportionate
application of requirements for certain financial entities, particularly microenterprises, as well as financial entities
subject to a simplified ICT risk management framework. To facilitate an efficient supervision of institutions for
occupational retirement provision that is proportionate and addresses the need to reduce administrative burdens on
the competent authorities, the relevant national supervisory arrangements in respect of such financial entities should
take into account their size and overall risk profile, and the nature, scale and complexity of their services, activities
and operations even when the relevant thresholds established in Article 5 of Directive (EU) 2016/2341 of the
European Parliament and of the Council(^10 )are exceeded. In particular, supervisory activities should focus primarily
on the need to address serious risks associated with the ICT risk management of a particular entity.
(^9 ) Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities
and repealing Council Directive 2008/114/EC (see page 164 of this Official Journal).
(^10 ) Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of
institutions for occupational retirement provision (IORPs) (OJ L 354, 23.12.2016, p. 37).
27.12.2022 EN Official Journal of the European Union L 333/
Competent authorities should also maintain a vigilant but proportionate approach in relation to the supervision of
institutions for occupational retirement provision which, in accordance with Article 31 of Directive (EU)
2016/2341, outsource a significant part of their core business, such as asset management, actuarial calculations,
accounting and data management, to service providers.
(22) ICT-related incident reporting thresholds and taxonomies vary significantly at national level. While common ground
may be achieved through the relevant work undertaken by the European Union Agency for Cybersecurity (ENISA)
established by Regulation (EU) 2019/881 of the European Parliament and of the Council(^11 )and the Cooperation
Group under Directive (EU) 2022/2555, divergent approaches on setting the thresholds and use of taxonomies still
exist, or can emerge, for the remainder of financial entities. Due to those divergences, there are multiple
requirements that financial entities must comply with, especially when operating across several Member States and
when part of a financial group. Moreover, such divergences have the potential to hinder the creation of further
uniform or centralised Union mechanisms that speed up the reporting process and support a quick and smooth
exchange of information between competent authorities, which is crucial for addressing ICT risk in the event of
large-scale attacks with potentially systemic consequences.
(23) To reduce the administrative burden and potentially duplicative reporting obligations for certain financial entities,
the requirement for the incident reporting pursuant to Directive (EU) 2015/2366 of the European Parliament and
of the Council(^12 )should cease to apply to payment service providers that fall within the scope of this Regulation.
Consequently, credit institutions, e-money institutions, payment institutions and account information service
providers, as referred to in Article 33(1) of that Directive, should, from the date of application of this Regulation,
report pursuant to this Regulation, all operational or security payment-related incidents which have been previously
reported pursuant to that Directive, irrespective of whether such incidents are ICT-related.
(24) To enable competent authorities to fulfil supervisory roles by acquiring a complete overview of the nature,
frequency, significance and impact of ICT-related incidents and to enhance the exchange of information between
relevant public authorities, including law enforcement authorities and resolution authorities, this Regulation should
lay down a robust ICT-related incident reporting regime whereby the relevant requirements address current gaps in
financial services law, and remove existing overlaps and duplications to alleviate costs. It is essential to harmonise
the ICT-related incident reporting regime by requiring all financial entities to report to their competent authorities
through a single streamlined framework as set out in this Regulation. In addition, the ESAs should be empowered to
further specify relevant elements for the ICT-related incident reporting framework, such as taxonomy, timeframes,
data sets, templates and applicable thresholds. To ensure full consistency with Directive (EU) 2022/2555, financial
entities should be allowed, on a voluntary basis, to notify significant cyber threats to the relevant competent
authority, when they consider that the cyber threat is of relevance to the financial system, service users or clients.
(25) Digital operational resilience testing requirements have been developed in certain financial subsectors setting out
frameworks that are not always fully aligned. This leads to a potential duplication of costs for cross-border financial
entities and makes the mutual recognition of the results of digital operational resilience testing complex which, in
turn, can fragment the internal market.
(^11 ) Regulation (EU) 2019/881 of the European Parliament and of the Council of 17 April 2019 on ENISA (the European Union Agency
for Cybersecurity) and on information and communications technology cybersecurity certification and repealing Regulation (EU)
No 526/2013 (Cybersecurity Act) (OJ L 151, 7.6.2019, p. 15).
(^12 ) Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal
market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing
Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35).
L 333/6 EN Official Journal of the European Union 27.12.
(26) In addition, where no ICT testing is required, vulnerabilities remain undetected and result in exposing a financial
entity to ICT risk and ultimately create a higher risk to the stability and integrity of the financial sector. Without
Union intervention, digital operational resilience testing would continue to be inconsistent and would lack a system
of mutual recognition of ICT testing results across different jurisdictions. In addition, as it is unlikely that other
financial subsectors would adopt testing schemes on a meaningful scale, they would miss out on the potential
benefits of a testing framework, in terms of revealing ICT vulnerabilities and risks, and testing defence capabilities
and business continuity, which contributes to increasing the trust of customers, suppliers and business partners. To
remedy those overlaps, divergences and gaps, it is necessary to lay down rules for a coordinated testing regime and
thereby facilitate the mutual recognition of advanced testing for financial entities meeting the criteria set out in this
Regulation.
(27) Financial entities’ reliance on the use of ICT services is partly driven by their need to adapt to an emerging
competitive digital global economy, to boost their business efficiency and to meet consumer demand. The nature
and extent of such reliance has been continuously evolving in recent years, driving cost reduction in financial
intermediation, enabling business expansion and scalability in the deployment of financial activities while offering a
wide range of ICT tools to manage complex internal processes.
(28) The extensive use of ICT services is evidenced by complex contractual arrangements, whereby financial entities often
encounter difficulties in negotiating contractual terms that are tailored to the prudential standards or other
regulatory requirements to which they are subject, or otherwise in enforcing specific rights, such as access or audit
rights, even when the latter are enshrined in their contractual arrangements. Moreover, many of those contractual
arrangements do not provide for sufficient safeguards allowing for the fully-fledged monitoring of subcontracting
processes, thus depriving the financial entity of its ability to assess the associated risks. In addition, as ICT third-
party service providers often provide standardised services to different types of clients, such contractual
arrangements do not always cater adequately for the individual or specific needs of financial industry actors.
(29) Even though Union financial services law contains certain general rules on outsourcing, monitoring of the
contractual dimension is not fully anchored into Union law. In the absence of clear and bespoke Union standards
applying to the contractual arrangements concluded with ICT third-party service providers, the external source of
ICT risk is not comprehensively addressed. Consequently, it is necessary to set out certain key principles to guide
financial entities’ management of ICT third-party risk, which are of particular importance when financial entities
resort to ICT third-party service providers to support their critical or important functions. Those principles should
be accompanied by a set of core contractual rights in relation to several elements in the performance and
termination of contractual arrangements with a view to providing certain minimum safeguards in order to
strengthen financial entities’ ability to effectively monitor all ICT risk emerging at the level of third-party service
providers. Those principles are complementary to the sectoral law applicable to outsourcing.
(30) A certain lack of homogeneity and convergence regarding the monitoring of ICT third-party risk and ICT third-party
dependencies is evident today. Despite efforts to address outsourcing, such as EBA Guidelines on outsourcing of
2019 and ESMA Guidelines on outsourcing to cloud service providers of 2021 the broader issue of counteracting
systemic risk which may be triggered by the financial sector’s exposure to a limited number of critical ICT third-
party service providers is not sufficiently addressed by Union law. The lack of rules at Union level is compounded
by the absence of national rules on mandates and tools that allow financial supervisors to acquire a good
understanding of ICT third-party dependencies and to monitor adequately risks arising from the concentration of
ICT third-party dependencies.
27.12.2022 EN Official Journal of the European Union L 333/
(31) Taking into account the potential systemic risk entailed by increased outsourcing practices and by the ICT third-
party concentration, and mindful of the insufficiency of national mechanisms in providing financial supervisors
with adequate tools to quantify, qualify and redress the consequences of ICT risk occurring at critical ICT third-party
service providers, it is necessary to establish an appropriate Oversight Framework allowing for a continuous
monitoring of the activities of ICT third-party service providers that are critical ICT third-party service providers to
financial entities, while ensuring that the confidentiality and security of customers other than financial entities is
preserved. While intra-group provision of ICT services entails specific risks and benefits, it should not be
automatically considered less risky than the provision of ICT services by providers outside of a financial group and
should therefore be subject to the same regulatory framework. However, when ICT services are provided from
within the same financial group, financial entities might have a higher level of control over intra-group providers,
which ought to be taken into account in the overall risk assessment.
(32) With ICT risk becoming more and more complex and sophisticated, good measures for the detection and prevention
of ICT risk depend to a great extent on the regular sharing between financial entities of threat and vulnerability
intelligence. Information sharing contributes to creating increased awareness of cyber threats. In turn, this enhances
the capacity of financial entities to prevent cyber threats from becoming real ICT-related incidents and enables
financial entities to more effectively contain the impact of ICT-related incidents and to recover faster. In the absence
of guidance at Union level, several factors seem to have inhibited such intelligence sharing, in particular uncertainty
about its compatibility with data protection, anti-trust and liability rules.
(33) In addition, doubts about the type of information that can be shared with other market participants, or with non-
supervisory authorities (such as ENISA, for analytical input, or Europol, for law enforcement purposes) lead to
useful information being withheld. Therefore, the extent and quality of information sharing currently remains
limited and fragmented, with relevant exchanges mostly being local (by way of national initiatives) and with no
consistent Union-wide information-sharing arrangements tailored to the needs of an integrated financial system. It
is therefore important to strengthen those communication channels.
(34) Financial entities should be encouraged to exchange among themselves cyber threat information and intelligence,
and to collectively leverage their individual knowledge and practical experience at strategic, tactical and operational
levels with a view to enhancing their capabilities to adequately assess, monitor, defend against, and respond to cyber
threats, by participating in information sharing arrangements. It is therefore necessary to enable the emergence at
Union level of mechanisms for voluntary information-sharing arrangements which, when conducted in trusted
environments, would help the community of the financial industry to prevent and collectively respond to cyber
threats by quickly limiting the spread of ICT risk and impeding potential contagion throughout the financial
channels. Those mechanisms should comply with the applicable competition law rules of the Union set out in the
Communication from the Commission of 14 January 2011entitled ‘Guidelines on the applicability of Article 101
of the Treaty on the Functioning of the European Union to horizontal cooperation agreements’, as well as with
Union data protection rules, in particular Regulation (EU) 2016/679 of the European Parliament and of the
Council(^13 ). They should operate based on the use of one or more of the legal bases that are laid down in Article 6
of that Regulation, such as in the context of the processing of personal data that is necessary for the purposes of the
legitimate interest pursued by the controller or by a third party, as referred to in Article 6(1), point (f), of that
Regulation, as well as in the context of the processing of personal data necessary for compliance with a legal
obligation to which the controller is subject, necessary for the performance of a task carried out in the public
interest or in the exercise of official authority vested in the controller, as referred to in Article 6(1), points (c) and (e),
respectively, of that Regulation.
(^13 ) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with
regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data
Protection Regulation) (OJ L 119, 4.5.2016, p. 1).
L 333/8 EN Official Journal of the European Union 27.12.
(35) In order to maintain a high level of digital operational resilience for the whole financial sector, and at the same time
to keep pace with technological developments, this Regulation should address risk stemming from all types of ICT
services. To that end, the definition of ICT services in the context of this Regulation should be understood in a
broad manner, encompassing digital and data services provided through ICT systems to one or more internal or
external users on an ongoing basis. That definition should, for instance, include so called ‘over the top’ services,
which fall within the category of electronic communications services. It should exclude only the limited category of
traditional analogue telephone services qualifying as Public Switched Telephone Network (PSTN) services, landline
services, Plain Old Telephone Service (POTS), or fixed-line telephone services.
(36) Notwithstanding the broad coverage envisaged by this Regulation, the application of the digital operational resilience
rules should take into account the significant differences between financial entities in terms of their size and overall
risk profile. As a general principle, when distributing resources and capabilities for the implementation of the ICT
risk management framework, financial entities should duly balance their ICT-related needs to their size and overall
risk profile, and the nature, scale and complexity of their services, activities and operations, while competent
authorities should continue to assess and review the approach of such distribution.
(37) Account information service providers, referred to in Article 33(1) of Directive (EU) 2015/2366, are explicitly
included in the scope of this Regulation, taking into account the specific nature of their activities and the risks
arising therefrom. In addition, electronic money institutions and payment institutions exempted pursuant to Article
9(1) of Directive 2009/110/EC of the European Parliament and of the Council(^14 )and Article 32(1) of Directive (EU)
2015/2366 are included in the scope of this Regulation even if they have not been granted authorisation in
accordance Directive 2009/110/EC to issue electronic money, or if they have not been granted authorisation in
accordance with Directive (EU) 2015/2366 to provide and execute payment services. However, post office giro
institutions, referred to in Article 2(5), point (3), of Directive 2013/36/EU of the European Parliament and of the
Council(^15 ), are excluded from the scope of this Regulation. The competent authority for payment institutions
exempted pursuant to Directive (EU) 2015/2366, electronic money institutions exempted pursuant to Directive
2009/110/EC and account information service providers as referred to in Article 33(1) of Directive (EU)
2015/2366, should be the competent authority designated in accordance with Article 22 of Directive (EU)
2015/2366.
(38) As larger financial entities might enjoy wider resources and can swiftly deploy funds to develop governance
structures and set up various corporate strategies, only financial entities that are not microenterprises in the sense
of this Regulation should be required to establish more complex governance arrangements. Such entities are better
equipped in particular to set up dedicated management functions for supervising arrangements with ICT third-party
service providers or for dealing with crisis management, to organise their ICT risk management according to the
three lines of defence model, or to set up an internal risk management and control model, and to submit their ICT
risk management framework to internal audits.
(39) Some financial entities benefit from exemptions or are subject to a very light regulatory framework under the
relevant sector-specific Union law. Such financial entities include managers of alternative investment funds referred
to in Article 3(2) of Directive 2011/61/EU of the European Parliament and of the Council(^16 ), insurance and
reinsurance undertakings referred to in Article 4 of Directive 2009/138/EC of the European Parliament and of the
Council(^17 ), and institutions for occupational retirement provision which operate pension schemes which together
(^14 ) Directive 2009/110/EC of the European Parliament and of the Council of 16 September 2009 on the taking up, pursuit and
prudential supervision of the business of electronic money institutions amending Directives 2005/60/EC and 2006/48/EC and
repealing Directive 2000/46/EC (OJ L 267, 10.10.2009, p. 7).
(^15 ) Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions
and the prudential supervision of credit institutions, amending Directive 2002/87/EC and repealing Directives 2006/48/EC
and 2006/49/EC (OJ L 176, 27.6.2013, p. 338).
(^16 ) Directive 2011/61/EU of the European Parliament and of the Council of 8 June 2011 on Alternative Investment Fund Managers and
amending Directives 2003/41/EC and 2009/65/EC and Regulations (EC) No 1060/2009 and (EU) No 1095/2010 (OJ L 174,
1.7.2011, p. 1).
(^17 ) Directive 2009/138/EC of the European Parliament and of the Council of 25 November 2009 on the taking-up and pursuit of the
business of Insurance and Reinsurance (Solvency II) (OJ L 335, 17.12.2009, p. 1).
27.12.2022 EN Official Journal of the European Union L 333/
do not have more than 15 members in total. In light of those exemptions it would not be proportionate to include
such financial entities in the scope of this Regulation. In addition, this Regulation acknowledges the specificities of
the insurance intermediation market structure, with the result that insurance intermediaries, reinsurance
intermediaries and ancillary insurance intermediaries qualifying as microenterprises or as small or medium-sized
enterprises should not be subject to this Regulation.
(40) Since the entities referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU are excluded from the scope
of that Directive, Member States should consequently be able to choose to exempt from the application of this
Regulation such entities located within their respective territories.
(41) Similarly, in order to align this Regulation to the scope of Directive 2014/65/EU of the European Parliament and of
the Council(^18 ), it is also appropriate to exclude from the scope of this Regulation natural and legal persons referred
in Articles 2 and 3 of that Directive which are allowed to provide investment services without having to obtain an
authorisation under Directive 2014/65/EU. However, Article 2 of Directive 2014/65/EU also excludes from the
scope of that Directive entities which qualify as financial entities for the purposes of this Regulation such as, central
securities depositories, collective investment undertakings or insurance and reinsurance undertakings. The exclusion
from the scope of this Regulation of the persons and entities referred to in Articles 2 and 3 of that Directive should
not encompass those central securities depositories, collective investment undertakings or insurance and reinsurance
undertakings.
(42) Under sector-specific Union law, some financial entities are subject to lighter requirements or exemptions for reasons
associated with their size or the services they provide. That category of financial entities includes small and non-
interconnected investment firms, small institutions for occupational retirement provision which may be excluded
from the scope of Directive (EU) 2016/2341 under the conditions laid down in Article 5 of that Directive by the
Member State concerned and operate pension schemes which together do not have more than 100 members in
total, as well as institutions exempted pursuant to Directive 2013/36/EU. Therefore, in accordance with the
principle of proportionality and to preserve the spirit of sector-specific Union law, it is also appropriate to subject
those financial entities to a simplified ICT risk management framework under this Regulation. The proportionate
character of the ICT risk management framework covering those financial entities should not be altered by the
regulatory technical standards that are to be developed by the ESAs. Moreover, in accordance with the principle of
proportionality, it is appropriate to also subject payment institutions referred to in Article 32(1) of Directive (EU)
2015/2366 and electronic money institutions referred to in Article 9 of Directive 2009/110/EC exempted in
accordance with national law transposing those Union legal acts to a simplified ICT risk management framework
under this Regulation, while payment institutions and electronic money institutions which have not been exempted
in accordance with their respective national law transposing sectoral Union law should comply with the general
framework laid down by this Regulation.
(43) Similarly, financial entities which qualify as microenterprises or are subject to the simplified ICT risk management
framework under this Regulation should not be required to establish a role to monitor their arrangements
concluded with ICT third-party service providers on the use of ICT services; or to designate a member of senior
management to be responsible for overseeing the related risk exposure and relevant documentation; to assign the
responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of
independence of such control function in order to avoid conflicts of interest; to document and review at least once
a year the ICT risk management framework; to subject to internal audit on a regular basis the ICT risk management
framework; to perform in-depth assessments after major changes in their network and information system
infrastructures and processes; to regularly conduct risk analyses on legacy ICT systems; to subject the
implementation of the ICT Response and Recovery plans to independent internal audit reviews; to have a crisis
management function, to expand the testing of business continuity and response and recovery plans to capture
switchover scenarios between primary ICT infrastructure and redundant facilities; to report to competent
authorities, upon their request, an estimation of aggregated annual costs and losses caused by major ICT-related
incidents, to maintain redundant ICT capacities; to communicate to national competent authorities implemented
(^18 ) Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and
amending Directive 2002/92/EC and Directive 2011/61/EU (OJ L 173, 12.6.2014, p. 349).
L 333/10 EN Official Journal of the European Union 27.12.
changes following post ICT-related incident reviews; to monitor on a continuous basis relevant technological
developments, to establish a comprehensive digital operational resilience testing programme as an integral part of
the ICT risk management framework provided for in this Regulation, or to adopt and regularly review a strategy on
ICT third-party risk. In addition, microenterprises should only be required to assess the need to maintain such
redundant ICT capacities based on their risk profile. Microenterprises should benefit from a more f lexible regime as
regards digital operational resilience testing programmes. When considering the type and frequency of testing to be
performed, they should properly balance the objective of maintaining a high digital operational resilience, the
available resources and their overall risk profile. Microenterprises and financial entities subject to the simplified ICT
risk management framework under this Regulation should be exempted from the requirement to perform advanced
testing of ICT tools, systems and processes based on threat-led penetration testing (TLPT), as only financial entities
meeting the criteria set out in this Regulation should be required to carry out such testing. In light of their limited
capabilities, microenterprises should be able to agree with the ICT third-party service provider to delegate the
financial entity’s rights of access, inspection and audit to an independent third-party, to be appointed by the ICT
third-party service provider, provided that the financial entity is able to request, at any time, all relevant information
and assurance on the ICT third-party service provider’s performance from the respective independent third-party.
(44) As only those financial entities identified for the purposes of the advanced digital resilience testing should be
required to conduct threat-led penetration tests, the administrative processes and financial costs entailed in the
performance of such tests should be borne by a small percentage of financial entities.
(45) To ensure full alignment and overall consistency between financial entities’ business strategies, on the one hand, and
the conduct of ICT risk management, on the other hand, the financial entities’ management bodies should be
required to maintain a pivotal and active role in steering and adapting the ICT risk management framework and the
overall digital operational resilience strategy. The approach to be taken by management bodies should not only focus
on the means of ensuring the resilience of the ICT systems, but should also cover people and processes through a set
of policies which cultivate, at each corporate layer, and for all staff, a strong sense of awareness about cyber risks and
a commitment to observe a strict cyber hygiene at all levels. The ultimate responsibility of the management body in
managing a financial entity’s ICT risk should be an overarching principle of that comprehensive approach, further
translated into the continuous engagement of the management body in the control of the monitoring of the ICT
risk management.
(46) Moreover, the principle of the management body’s full and ultimate responsibility for the management of the ICT
risk of the financial entity goes hand in hand with the need to secure a level of ICT-related investments and an
overall budget for the financial entity that would enable the financial entity to achieve a high level of digital
operational resilience.
(47) Inspired by relevant international, national and industry best practices, guidelines, recommendations and
approaches to the management of cyber risk, this Regulation promotes a set of principles that facilitate the overall
structure of ICT risk management. Consequently, as long as the main capabilities which financial entities put in
place address the various functions in the ICT risk management (identification, protection and prevention,
detection, response and recovery, learning and evolving and communication) set out in this Regulation, financial
entities should remain free to use ICT risk management models that are differently framed or categorised.
(48) To keep pace with an evolving cyber threat landscape, financial entities should maintain updated ICT systems that are
reliable and capable, not only for guaranteeing the processing of data required for their services, but also for ensuring
sufficient technological resilience to allow them to deal adequately with additional processing needs due to stressed
market conditions or other adverse situations.
27.12.2022 EN Official Journal of the European Union L 333/
(49) Efficient business continuity and recovery plans are necessary to allow financial entities to promptly and quickly
resolve ICT-related incidents, in particular cyber-attacks, by limiting damage and giving priority to the resumption
of activities and recovery actions in accordance with their back-up policies. However, such resumption should in no
way jeopardise the integrity and security of the network and information systems or the availability, authenticity,
integrity or confidentiality of data.
(50) While this Regulation allows financial entities to determine their recovery time and recovery point objectives in a
f lexible manner and hence to set such objectives by fully taking into account the nature and the criticality of the
relevant functions and any specific business needs, it should nevertheless require them to carry out an assessment of
the potential overall impact on market efficiency when determining such objectives.
(51) The propagators of cyber-attacks tend to pursue financial gains directly at the source, thus exposing financial entities
to significant consequences. To prevent ICT systems from losing integrity or becoming unavailable, and hence to
avoid data breaches and damage to physical ICT infrastructure, the reporting of major ICT-related incidents by
financial entities should be significantly improved and streamlined. ICT-related incident reporting should be
harmonised through the introduction of a requirement for all financial entities to report directly to their relevant
competent authorities. Where a financial entity is subject to supervision by more than one national competent
authority, Member States should designate a single competent authority as the addressee of such reporting. Credit
institutions classified as significant in accordance with Article 6(4) of Council Regulation (EU) No 1024/2013(^19 )
should submit such reporting to the national competent authorities, which should subsequently transmit the report
to the European Central Bank (ECB).
(52) The direct reporting should enable financial supervisors to have immediate access to information about major ICT-
related incidents. Financial supervisors should in turn pass on details of major ICT-related incidents to public non-
financial authorities (such as competent authorities and single points of contact under Directive (EU) 2022/2555,
national data protection authorities, and to law enforcement authorities for major ICT-related incidents of a
criminal nature) in order to enhance such authorities awareness of such incidents and, in the case of CSIRTs, to
facilitate prompt assistance that may be given to financial entities, as appropriate. Member States should, in
addition, be able to determine that financial entities themselves should provide such information to public
authorities outside the financial services area. Those information f lows should allow financial entities to swiftly
benefit from any relevant technical input, advice about remedies, and subsequent follow-up from such authorities.
The information on major ICT-related incidents should be mutually channelled: financial supervisors should
provide all necessary feedback or guidance to the financial entity, while the ESAs should share anonymised data on
cyber threats and vulnerabilities relating to an incident, to aid wider collective defence.
(53) While all financial entities should be required to carry out incident reporting, that requirement is not expected to
affect all of them in the same manner. Indeed, relevant materiality thresholds, as well as reporting timelines, should
be duly adjusted, in the context of delegated acts based on the regulatory technical standards to be developed by the
ESAs, with a view to covering only major ICT-related incidents. In addition, the specificities of financial entities
should be taken into account when setting timelines for reporting obligations.
(54) This Regulation should require credit institutions, payment institutions, account information service providers and
electronic money institutions to report all operational or security payment-related incidents – previously reported
under Directive (EU) 2015/2366 – irrespective of the ICT nature of the incident.
(^19 ) Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning
policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63).
L 333/12 EN Official Journal of the European Union 27.12.
(55) The ESAs should be tasked with assessing the feasibility and conditions for a possible centralisation of ICT-related
incident reports at Union level. Such centralisation could consist of a single EU Hub for major ICT-related incident
reporting either directly receiving relevant reports and automatically notifying national competent authorities, or
merely centralising relevant reports forwarded by the national competent authorities and thus fulfilling a
coordination role. The ESAs should be tasked with preparing, in consultation with the ECB and ENISA, a joint
report exploring the feasibility of setting up a single EU Hub.
(56) In order to achieve a high level of digital operational resilience, and in line with both the relevant international
standards (e.g. the G7 Fundamental Elements for Threat-Led Penetration Testing) and with the frameworks applied
in the Union, such as the TIBER-EU, financial entities should regularly test their ICT systems and staff having ICT-
related responsibilities with regard to the effectiveness of their preventive, detection, response and recovery
capabilities, to uncover and address potential ICT vulnerabilities. To reflect differences that exist across, and within,
the various financial subsectors as regards financial entities’ level of cybersecurity preparedness, testing should
include a wide variety of tools and actions, ranging from the assessment of basic requirements (e.g. vulnerability
assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews,
questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests,
compatibility testing, performance testing or end-to-end testing) to more advanced testing by means of TLPT. Such
advanced testing should be required only of financial entities that are mature enough from an ICT perspective to
reasonably carry it out. The digital operational resilience testing required by this Regulation should thus be more
demanding for those financial entities meeting the criteria set out in this Regulation (for example, large, systemic
and ICT-mature credit institutions, stock exchanges, central securities depositories and central counterparties) than
for other financial entities. At the same time, the digital operational resilience testing by means of TLPT should be
more relevant for financial entities operating in core financial services subsectors and playing a systemic role (for
example, payments, banking, and clearing and settlement), and less relevant for other subsectors (for example, asset
managers and credit rating agencies).
(57) Financial entities involved in cross-border activities and exercising the freedoms of establishment, or of provision of
services within the Union, should comply with a single set of advanced testing requirements (i.e. TLPT) in their home
Member State, which should include the ICT infrastructures in all jurisdictions where the cross-border financial
group operates within the Union, thus allowing such cross-border financial groups to incur related ICT testing costs
in one jurisdiction only.
(58) To draw on the expertise already acquired by certain competent authorities, in particular with regard to
implementing the TIBER-EU framework, this Regulation should allow Member States to designate a single public
authority as responsible in the financial sector, at national level, for all TLPT matters, or competent authorities, to
delegate, in the absence of such designation, the exercise of TLPT related tasks to another national financial
competent authority.
(59) Since this Regulation does not require financial entities to cover all critical or important functions in one single
threat-led penetration test, financial entities should be free to determine which and how many critical or important
functions should be included in the scope of such a test.
(60) Pooled testing within the meaning of this Regulation – involving the participation of several financial entities in a
TLPT and for which an ICT third-party service provider can directly enter into contractual arrangements with an
external tester – should be allowed only where the quality or security of services delivered by the ICT third-party
service provider to customers that are entities falling outside the scope of this Regulation, or the confidentiality of
the data related to such services, are reasonably expected to be adversely impacted. Pooled testing should also be
subject to safeguards (direction by one designated financial entity, calibration of the number of participating
financial entities) to ensure a rigorous testing exercise for the financial entities involved which meet the objectives of
the TLPT pursuant to this Regulation.
27.12.2022 EN Official Journal of the European Union L 333/
(61) In order to take advantage of internal resources available at corporate level, this Regulation should allow the use of
internal testers for the purposes of carrying out TLPT, provided there is supervisory approval, no conflicts of
interest, and periodical alternation of the use of internal and external testers (every three tests), while also requiring
the provider of the threat intelligence in the TLPT to always be external to the financial entity. The responsibility for
conducting TLPT should remain fully with the financial entity. Attestations provided by authorities should be solely
for the purpose of mutual recognition and should not preclude any follow-up action needed to address the ICT risk
to which the financial entity is exposed, nor should they be seen as a supervisory endorsement of a financial entity’s
ICT risk management and mitigation capabilities.
(62) To ensure a sound monitoring of ICT third-party risk in the financial sector, it is necessary to lay down a set of
principle-based rules to guide financial entities’ when monitoring risk arising in the context of functions outsourced
to ICT third-party service providers, particularly for ICT services supporting critical or important functions, as well
as more generally in the context of all ICT third-party dependencies.
(63) To address the complexity of the various sources of ICT risk, while taking into account the multitude and diversity of
providers of technological solutions which enable a smooth provision of financial services, this Regulation should
cover a wide range of ICT third-party service providers, including providers of cloud computing services, software,
data analytics services and providers of data centre services. Similarly, since financial entities should effectively and
coherently identify and manage all types of risk, including in the context of ICT services procured within a financial
group, it should be clarified that undertakings which are part of a financial group and provide ICT services
predominantly to their parent undertaking, or to subsidiaries or branches of their parent undertaking, as well as
financial entities providing ICT services to other financial entities, should also be considered as ICT third-party
service providers under this Regulation. Lastly, in light of the evolving payment services market becoming
increasingly dependent on complex technical solutions, and in view of emerging types of payment services and
payment-related solutions, participants in the payment services ecosystem, providing payment-processing activities,
or operating payment infrastructures, should also be considered to be ICT third-party service providers under this
Regulation, with the exception of central banks when operating payment or securities settlement systems, and
public authorities when providing ICT related services in the context of fulfilling State functions.
(64) A financial entity should at all times remain fully responsible for complying with its obligations set out in this
Regulation. Financial entities should apply a proportionate approach to the monitoring of risks emerging at the
level of the ICT third-party service providers, by duly considering the nature, scale, complexity and importance of
their ICT-related dependencies, the criticality or importance of the services, processes or functions subject to the
contractual arrangements and, ultimately, on the basis of a careful assessment of any potential impact on the
continuity and quality of financial services at individual and at group level, as appropriate.
(65) The conduct of such monitoring should follow a strategic approach to ICT third-party risk formalised through the
adoption by the financial entity’s management body of a dedicated ICT third-party risk strategy, rooted in a
continuous screening of all ICT third-party dependencies. To enhance supervisory awareness of ICT third-party
dependencies, and with a view to further supporting the work in the context of the Oversight Framework
established by this Regulation, all financial entities should be required to maintain a register of information with all
contractual arrangements about the use of ICT services provided by ICT third-party service providers. Financial
supervisors should be able to request the full register, or to ask for specific sections thereof, and thus to obtain
essential information for acquiring a broader understanding of the ICT dependencies of financial entities.
(66) A thorough pre-contracting analysis should underpin and precede the formal conclusion of contractual
arrangements, in particular by focusing on elements such as the criticality or importance of the services supported
by the envisaged ICT contract, the necessary supervisory approvals or other conditions, the possible concentration
risk entailed, as well as applying due diligence in the process of selection and assessment of ICT third-party service
providers and assessing potential conflicts of interest. For contractual arrangements concerning critical or
important functions, financial entities should take into consideration the use by ICT third-party service providers of
the most up-to-date and highest information security standards. Termination of contractual arrangements could be
prompted at least by a series of circumstances showing shortfalls at the ICT third-party service provider level, in
L 333/14 EN Official Journal of the European Union 27.12.
particular significant breaches of laws or contractual terms, circumstances revealing a potential alteration of the
performance of the functions provided for in the contractual arrangements, evidence of weaknesses of the ICT
third-party service provider in its overall ICT risk management, or circumstances indicating the inability of the
relevant competent authority to effectively supervise the financial entity.
(67) To address the systemic impact of ICT third-party concentration risk, this Regulation promotes a balanced solution
by means of taking a flexible and gradual approach to such concentration risk since the imposition of any rigid caps
or strict limitations might hinder the conduct of business and restrain the contractual freedom. Financial entities
should thoroughly assess their envisaged contractual arrangements to identify the likelihood of such risk emerging,
including by means of in-depth analyses of subcontracting arrangements, in particular when concluded with ICT
third-party service providers established in a third country. At this stage, and with a view to striking a fair balance
between the imperative of preserving contractual freedom and that of guaranteeing financial stability, it is not
considered appropriate to set out rules on strict caps and limits to ICT third-party exposures. In the context of the
Oversight Framework, a Lead Overseer, appointed pursuant to this Regulation, should, in respect to critical ICT
third-party service providers, pay particular attention to fully grasp the magnitude of interdependences, discover
specific instances where a high degree of concentration of critical ICT third-party service providers in the Union is
likely to put a strain on the Union financial system’s stability and integrity and maintain a dialogue with critical ICT
third-party service providers where that specific risk is identified.
(68) To evaluate and monitor on a regular basis the ability of an ICT third party service provider to securely provide
services to a financial entity without adverse effects on a financial entity’s digital operational resilience, several key
contractual elements with ICT third-party service providers should be harmonised. Such harmonisation should
cover minimum areas which are crucial for enabling a full monitoring by the financial entity of the risks that could
emerge from the ICT third-party service provider, from the perspective of a financial entity’s need to secure its
digital resilience because it is deeply dependent on the stability, functionality, availability and security of the ICT
services received.
(69) When renegotiating contractual arrangements to seek alignment with the requirements of this Regulation, financial
entities and ICT third-party service providers should ensure the coverage of the key contractual provisions as
provided for in this Regulation.
(70) The definition of ‘critical or important function’ provided for in this Regulation encompasses the ‘critical functions’
as defined in Article 2(1), point (35), of Directive 2014/59/EU of the European Parliament and of the Council(^20 ).
Accordingly, functions deemed to be critical pursuant to Directive 2014/59/EU are included in the definition of
critical functions within the meaning of this Regulation.
(71) Irrespective of the criticality or importance of the function supported by the ICT services, contractual arrangements
should, in particular, provide for a specification of the complete descriptions of functions and services, of the
locations where such functions are provided and where data is to be processed, as well as an indication of service
level descriptions. Other essential elements to enable a financial entity’s monitoring of ICT third party risk are:
contractual provisions specifying how the accessibility, availability, integrity, security and protection of personal
data are ensured by the ICT third-party service provider, provisions laying down the relevant guarantees for
enabling the access, recovery and return of data in the case of insolvency, resolution or discontinuation of the
business operations of the ICT third-party service provider, as well as provisions requiring the ICT third-party
service provider to provide assistance in case of ICT incidents in connection with the services provided, at no
additional cost or at a cost determined ex-ante; provisions on the obligation of the ICT third-party service provider
(^20 ) Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014 establishing a framework for the recovery and
resolution of credit institutions and investment firms and amending Council Directive 82/891/EEC, and Directives 2001/24/EC,
2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU)
No 1093/2010 and (EU) No 648/2012, of the European Parliament and of the Council (OJ L 173, 12.6.2014, p. 190).
27.12.2022 EN Official Journal of the European Union L 333/
to fully cooperate with the competent authorities and resolution authorities of the financial entity; and provisions on
termination rights and related minimum notice periods for the termination of the contractual arrangements, in
accordance with the expectations of competent authorities and resolution authorities.
(72) In addition to such contractual provisions, and with a view to ensuring that financial entities remain in full control of
all developments occurring at third-party level which may impair their ICT security, the contracts for the provision
of ICT services supporting critical or important functions should also provide for the following: the specification of
the full service level descriptions, with precise quantitative and qualitative performance targets, to enable without
undue delay appropriate corrective actions when the agreed service levels are not met; the relevant notice periods
and reporting obligations of the ICT third-party service provider in the event of developments with a potential
material impact on the ICT third-party service provider’s ability to effectively provide their respective ICT services; a
requirement upon the ICT third-party service provider to implement and test business contingency plans and have
ICT security measures, tools and policies allowing for the secure provision of services, and to participate and fully
cooperate in the TLPT carried out by the financial entity.
(73) Contracts for the provision of ICT services supporting critical or important functions should also contain provisions
enabling the rights of access, inspection and audit by the financial entity, or an appointed third party, and the right to
take copies as crucial instruments in the financial entities’ ongoing monitoring of the ICT third-party service
provider’s performance, coupled with the service provider’s full cooperation during inspections. Similarly, the
competent authority of the financial entity should have the right, based on notices, to inspect and audit the ICT
third-party service provider, subject to the protection of confidential information.
(74) Such contractual arrangements should also provide for dedicated exit strategies to enable, in particular, mandatory
transition periods during which ICT third-party service providers should continue providing the relevant services
with a view to reducing the risk of disruptions at the level of the financial entity, or to allow the latter effectively to
switch to the use of other ICT third-party service providers or, alternatively, to change to in-house solutions,
consistent with the complexity of the provided ICT service. Moreover, financial entities within the scope of Directive
2014/59/EU should ensure that the relevant contracts for ICT services are robust and fully enforceable in the event of
resolution of those financial entities. Therefore, in line with the expectations of the resolution authorities, those
financial entities should ensure that the relevant contracts for ICT services are resolution resilient. As long as they
continue meeting their payment obligations, those financial entities should ensure, among other requirements, that
the relevant contracts for ICT services contain clauses for non-termination, non-suspension and non-modification
on grounds of restructuring or resolution.
(75) Moreover, the voluntary use of standard contractual clauses developed by public authorities or Union institutions, in
particular the use of contractual clauses developed by the Commission for cloud computing services could provide
further comfort to the financial entities and ICT third-party service providers, by enhancing their level of legal
certainty regarding the use of cloud computing services in the financial sector, in full alignment with the
requirements and expectations set out by the Union financial services law. The development of standard contractual
clauses builds on measures already envisaged in the 2018 Fintech Action Plan that announced the Commission’s
intention to encourage and facilitate the development of standard contractual clauses for the use of cloud
computing services outsourcing by financial entities, drawing on cross-sectorial cloud computing services
stakeholders’ efforts, which the Commission has facilitated with the help of the financial sector’s involvement.
(76) With a view to promoting convergence and efficiency in relation to supervisory approaches when addressing ICT
third-party risk in the financial sector, as well as to strengthening the digital operational resilience of financial
entities which rely on critical ICT third-party service providers for the provision of ICT services that support the
supply of financial services, and thereby to contributing to the preservation of the Union’s financial system stability
and the integrity of the internal market for financial services, critical ICT third-party service providers should be
subject to a Union Oversight Framework. While the set-up of the Oversight Framework is justified by the added
value of taking action at Union level and by virtue of the inherent role and specificities of the use of ICT services in
L 333/16 EN Official Journal of the European Union 27.12.
the provision of financial services, it should be recalled, at the same time, that this solution appears suitable only in
the context of this Regulation specifically dealing with digital operational resilience in the financial sector. However,
such Oversight Framework should not be regarded as a new model for Union supervision in other areas of financial
services and activities.
(77) The Oversight Framework should apply only to critical ICT third-party service providers. There should therefore be a
designation mechanism to take into account the dimension and nature of the financial sector’s reliance on such ICT
third-party service providers. That mechanism should involve a set of quantitative and qualitative criteria to set the
criticality parameters as a basis for inclusion in the Oversight Framework. In order to ensure the accuracy of that
assessment, and regardless of the corporate structure of the ICT third-party service provider, such criteria should, in
the case of a ICT third-party service provider that is part of a wider group, take into consideration the entire ICT
third-party service provider’s group structure. On the one hand, critical ICT third-party service providers, which are
not automatically designated by virtue of the application of those criteria, should have the possibility to opt in to the
Oversight Framework on a voluntary basis, on the other hand, ICT third-party service providers, that are already
subject to oversight mechanism frameworks supporting the fulfilment of the tasks of the European System of
Central Banks as referred to in Article 127(2) TFEU, should be exempted.
(78) Similarly, financial entities providing ICT services to other financial entities, while belonging to the category of ICT
third-party service providers under this Regulation, should also be exempted from the Oversight Framework since
they are already subject to supervisory mechanisms established by the relevant Union financial services law. Where
applicable, competent authorities should take into account, in the context of their supervisory activities, the ICT risk
posed to financial entities by financial entities providing ICT services. Likewise, due to the existing risk monitoring
mechanisms at group level, the same exemption should be introduced for ICT third-party service providers
delivering services predominantly to the entities of their own group. ICT third-party service providers providing
ICT services solely in one Member State to financial entities that are active only in that Member State should also be
exempted from the designation mechanism because of their limited activities and lack of cross-border impact.
(79) The digital transformation experienced in financial services has brought about an unprecedented level of use of, and
reliance upon, ICT services. Since it has become inconceivable to provide financial services without the use of cloud
computing services, software solutions and data-related services, the Union financial ecosystem has become
intrinsically co-dependent on certain ICT services provided by ICT service suppliers. Some of those suppliers,
innovators in developing and applying ICT-based technologies, play a significant role in the delivery of financial
services, or have become integrated into the financial services value chain. They have thus become critical to the
stability and integrity of the Union financial system. This widespread reliance on services supplied by critical ICT
third-party service providers, combined with the interdependence of the information systems of various market
operators, create a direct, and potentially severe, risk to the Union financial services system and to the continuity of
delivery of financial services if critical ICT third-party service providers were to be affected by operational
disruptions or major cyber incidents. Cyber incidents have a distinctive ability to multiply and propagate
throughout the financial system at a considerably faster pace than other types of risk monitored in the financial
sector and can extend across sectors and beyond geographical borders. They have the potential to evolve into a
systemic crisis, where trust in the financial system has been eroded due to the disruption of functions supporting
the real economy, or to substantial financial losses, reaching a level which the financial system is unable to
withstand, or which requires the deployment of heavy shock absorption measures. To prevent these scenarios from
taking place and thereby endangering the financial stability and integrity of the Union, it is essential to provide the
convergence of supervisory practices relating to ICT third-party risk in finance, in particular through new rules
enabling the Union oversight of critical ICT third-party service providers.
27.12.2022 EN Official Journal of the European Union L 333/
(80) The Oversight Framework largely depends on the degree of collaboration between the Lead Overseer and the critical
ICT third-party service provider delivering to financial entities services affecting the supply of financial services.
Successful oversight is predicated, inter alia, upon the ability of the Lead Overseer to effectively conduct monitoring
missions and inspections to assess the rules, controls and processes used by the critical ICT third-party service
providers, as well as to assess the potential cumulative impact of their activities on financial stability and the
integrity of the financial system. At the same time, it is crucial that critical ICT third-party service providers follow
the Lead Overseer’s recommendations and address its concerns. Since a lack of cooperation by a critical ICT third-
party service provider providing services that affect the supply of financial services, such as the refusal to grant
access to its premises or to submit information, would ultimately deprive the Lead Overseer of its essential tools in
appraising ICT third-party risk, and could adversely impact the financial stability and the integrity of the financial
system, it is necessary to also provide for a commensurate sanctioning regime.
(81) Against this background, the need of the Lead Overseer to impose penalty payments to compel critical ICT third-
party service providers to comply with the transparency and access-related obligations set out in this Regulation
should not be jeopardised by difficulties raised by the enforcement of those penalty payments in relation to critical
ICT third-party service providers established in third countries. In order to ensure the enforceability of such
penalties, and to allow a swift roll out of procedures upholding the critical ICT third-party service providers’ rights
of defence in the context of the designation mechanism and the issuance of recommendations, those critical ICT
third-party service providers, providing services to financial entities that affect the supply of financial services,
should be required to maintain an adequate business presence in the Union. Due to the nature of the oversight, and
the absence of comparable arrangements in other jurisdictions, there are no suitable alternative mechanisms
ensuring this objective by way of effective cooperation with financial supervisors in third countries in relation to the
monitoring of the impact of digital operational risks posed by systemic ICT third-party service providers, qualifying
as critical ICT third-party service providers established in third countries. Therefore, in order to continue its
provision of ICT services to financial entities in the Union, an ICT third-party service provider established in a third
country which has been designated as critical in accordance with this Regulation should undertake, within 12
months of such designation, all necessary arrangements to ensure its incorporation within the Union, by means of
establishing a subsidiary, as defined throughout the Union acquis, namely in Directive 2013/34/EU of the European
Parliament and of the Council(^21 ).
(82) The requirement to set up a subsidiary in the Union should not prevent the critical ICT third-party service provider
from supplying ICT services and related technical support from facilities and infrastructure located outside the
Union. This Regulation does not impose a data localisation obligation as it does not require data storage or
processing to be undertaken in the Union.
(83) Critical ICT third-party service providers should be able to provide ICT services from anywhere in the world, not
necessarily or not only from premises located in the Union. Oversight activities should be first conducted on
premises located in the Union and by interacting with entities located in the Union, including the subsidiaries
established by critical ICT third-party service providers pursuant to this Regulation. However, such actions within
the Union might be insufficient to allow the Lead Overseer to fully and effectively perform its duties under this
Regulation. The Lead Overseer should therefore also be able to exercise its relevant oversight powers in third
countries. Exercising those powers in third countries should allow the Lead Overseer to examine the facilities from
which the ICT services or the technical support services are actually provided or managed by the critical ICT third-
party service provider, and should give the Lead Overseer a comprehensive and operational understanding of the
ICT risk management of the critical ICT third-party service provider. The possibility for the Lead Overseer, as a
Union agency, to exercise powers outside the territory of the Union should be duly framed by relevant conditions,
in particular the consent of the critical ICT third-party service provider concerned. Similarly, the relevant authorities
of the third country should be informed of, and not have objected to, the exercise on their own territory of the
activities of the Lead Overseer. However, in order to ensure efficient implementation, and without prejudice to the
respective competences of the Union institutions and the Member States, such powers also need to be fully
anchored in the conclusion of administrative cooperation arrangements with the relevant authorities of the third
(^21 ) Directive 2013/34/EU of the European Parliament and of the Council of 26 June 2013 on the annual financial statements,
consolidated financial statements and related reports of certain types of undertakings, amending Directive 2006/43/EC of the
European Parliament and of the Council and repealing Council Directives 78/660/EEC and 83/349/EEC (OJ L 182, 29.6.2013, p. 19).
L 333/18 EN Official Journal of the European Union 27.12.
country concerned. This Regulation should therefore enable the ESAs to conclude administrative cooperation
arrangements with the relevant authorities of third countries, which should not otherwise create legal obligations in
respect of the Union and its Member States.
(84) To facilitate communication with the Lead Overseer and to ensure adequate representation, critical ICT third-party
service providers which are part of a group should designate one legal person as their coordination point.
(85) The Oversight Framework should be without prejudice to Member States’ competence to conduct their own
oversight or monitoring missions in respect to ICT third-party service providers which are not designated as critical
under this Regulation, but which are regarded as important at national level.
(86) To leverage the multi-layered institutional architecture in the financial services area, the Joint Committee of the ESAs
should continue to ensure overall cross-sectoral coordination in relation to all matters pertaining to ICT risk, in
accordance with its tasks on cybersecurity. It should be supported by a new Subcommittee (the ‘Oversight Forum’)
carrying out preparatory work both for the individual decisions addressed to critical ICT third-party service
providers, and for the issuing of collective recommendations, in particular in relation to benchmarking the
oversight programmes for critical ICT third-party service providers, and identifying best practices for addressing ICT
concentration risk issues.
(87) To ensure that critical ICT third-party service providers are appropriately and effectively overseen on a Union level,
this Regulation provides that any of the three ESAs could be designated as a Lead Overseer. The individual
assignment of a critical ICT third-party service provider to one of the three ESAs should result from an assessment
of the preponderance of financial entities operating in the financial sectors for which that ESA has responsibilities.
This approach should lead to a balanced allocation of tasks and responsibilities between the three ESAs, in the
context of exercising the oversight functions, and should make the best use of the human resources and technical
expertise available in each of the three ESAs.
(88) Lead Overseers should be granted the necessary powers to conduct investigations, to carry out onsite and offsite
inspections at the premises and locations of critical ICT third-party service providers and to obtain complete and
updated information. Those powers should enable the Lead Overseer to acquire real insight into the type,
dimension and impact of the ICT third-party risk posed to financial entities and ultimately to the Union’s financial
system. Entrusting the ESAs with the lead oversight role is a prerequisite for understanding and addressing the
systemic dimension of ICT risk in finance. The impact of critical ICT third-party service providers on the Union
financial sector and the potential issues caused by the ICT concentration risk entailed call for taking a collective
approach at Union level. The simultaneous carrying out of multiple audits and access rights, performed separately
by numerous competent authorities, with little or no coordination among them, would prevent financial
supervisors from obtaining a complete and comprehensive overview of ICT third-party risk in the Union, while also
creating redundancy, burden and complexity for critical ICT third-party service providers if they were subject to
numerous monitoring and inspection requests.
(89) Due to the significant impact of being designated as critical, this Regulation should ensure that the rights of critical
ICT third-party service providers are observed throughout the implementation of the Oversight Framework. Prior
to being designated as critical, such providers should, for example, have the right to submit to the Lead Overseer a
reasoned statement containing any relevant information for the purposes of the assessment related to their
designation. Since the Lead Overseer should be empowered to submit recommendations on ICT risk matters and
suitable remedies thereto, which include the power to oppose certain contractual arrangements ultimately affecting
the stability of the financial entity or the financial system, critical ICT third-party service providers should also be
given the opportunity to provide, prior to the finalisation of those recommendations, explanations regarding the
expected impact of the solutions, envisaged in the recommendations, on customers that are entities falling outside
the scope of this Regulation and to formulate solutions to mitigate risks. Critical ICT third-party service providers
27.12.2022 EN Official Journal of the European Union L 333/
disagreeing with the recommendations should submit a reasoned explanation of their intention not to endorse the
recommendation. Where such reasoned explanation is not submitted or where it is considered to be insufficient, the
Lead Overseer should issue a public notice summarily describing the matter of non-compliance.
(90) Competent authorities should duly include the task of verifying substantive compliance with recommendations
issued by the Lead Overseer in their functions with regard to prudential supervision of financial entities. Competent
authorities should be able to require financial entities to take additional measures to address the risks identified in the
Lead Overseer’s recommendations, and should, in due course, issue notifications to that effect. Where the Lead
Overseer addresses recommendations to critical ICT third-party service providers that are supervised under
Directive (EU) 2022/2555, the competent authorities should be able, on a voluntary basis and before adopting
additional measures, to consult the competent authorities under that Directive in order to foster a coordinated
approach to dealing with the critical ICT third-party service providers in question.
(91) The exercise of the oversight should be guided by three operational principles seeking to ensure: (a) close
coordination among the ESAs in their Lead Overseer roles, through a joint oversight network (JON), (b) consistency
with the framework established by Directive (EU) 2022/2555 (through a voluntary consultation of bodies under that
Directive to avoid duplication of measures directed at critical ICT third-party service providers), and (c) applying
diligence to minimise the potential risk of disruption to services provided by the critical ICT third-party service
providers to customers that are entities falling outside the scope of this Regulation.
(92) The Oversight Framework should not replace, or in any way or for any part substitute for, the requirement for
financial entities to manage themselves the risks entailed by the use of ICT third-party service providers, including
their obligation to maintain an ongoing monitoring of contractual arrangements concluded with critical ICT third-
party service providers. Similarly, the Oversight Framework should not affect the full responsibility of financial
entities for complying with, and discharging, all the legal obligations laid down in this Regulation and in the
relevant financial services law.
(93) To avoid duplications and overlaps, competent authorities should refrain from taking individually any measures
aiming to monitor the critical ICT third-party service provider’s risks and should, in that respect, rely on the
relevant Lead Overseer’s assessment. Any measures should in any case be coordinated and agreed in advance with
the Lead Overseer in the context of the exercise of tasks in the Oversight Framework.
(94) To promote convergence at international level as regards the use of best practices in the review and monitoring of
ICT third-party service providers’ digital risk-management, the ESAs should be encouraged to conclude cooperation
arrangements with relevant supervisory and regulatory third-country authorities.
(95) To leverage the specific competences, technical skills and expertise of staff specialising in operational and ICT risk
within the competent authorities, the three ESAs and, on a voluntary basis, the competent authorities under
Directive (EU) 2022/2555, the Lead Overseer should draw on national supervisory capabilities and knowledge and
set up dedicated examination teams for each critical ICT third-party service provider, pooling multidisciplinary
teams in support of the preparation and execution of oversight activities, including general investigations and
inspections of critical ICT third-party service providers, as well as for any necessary follow-up thereto.
(96) Whereas costs resulting from oversight tasks would be fully funded from fees levied on critical ICT third-party
service providers, the ESAs are. however, likely to incur, before the start of the Oversight Framework, costs for the
implementation of dedicated ICT systems supporting the upcoming oversight, since dedicated ICT systems would
need to be developed and deployed beforehand. This Regulation therefore provides for a hybrid funding model,
whereby the Oversight Framework would, as such, be fully fee-funded, while the development of the ESAs’ ICT
systems would be funded from Union and national competent authorities’ contributions.
L 333/20 EN Official Journal of the European Union 27.12.
(97) Competent authorities should have all required supervisory, investigative and sanctioning powers to ensure the
proper exercise of their duties under this Regulation. They should, in principle, publish notices of the administrative
penalties they impose. Since financial entities and ICT third-party service providers can be established in different
Member States and supervised by different competent authorities, the application of this Regulation should be
facilitated by, on the one hand, close cooperation among relevant competent authorities, including the ECB with
regard to specific tasks conferred on it by Council Regulation (EU) No 1024/2013, and, on the other hand, by
consultation with the ESAs through the mutual exchange of information and the provision of assistance in the
context of relevant supervisory activities.
(98) In order to further quantify and qualify the criteria for the designation of ICT third-party service providers as critical
and to harmonise oversight fees, the power to adopt acts in accordance with Article 290 TFEU should be delegated
to the Commission to supplement this Regulation by further specifying the systemic impact that a failure or
operational outage of an ICT third-party service provider could have on the financial entities it provides ICT services
to, the number of global systemically important institutions (G-SIIs), or other systemically important institutions
(O-SIIs), that rely on the ICT third-party service provider in question, the number of ICT third-party service
providers active on a given market, the costs of migrating data and ICT workloads to other ICT third-party service
providers, as well as the amount of the oversight fees and the way in which they are to be paid. It is of particular
importance that the Commission carry out appropriate consultations during its preparatory work, including at
expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinsti
tutional Agreement of 13 April 2016on Better Law-Making(^22 ). In particular, to ensure equal participation in the
preparation of delegated acts, the European Parliament and the Council should receive all documents at the same
time as Member States’ experts, and their experts should systematically have access to meetings of Commission
expert groups dealing with the preparation of delegated acts.
(99) Regulatory technical standards should ensure the consistent harmonisation of the requirements laid down in this
Regulation. In their roles as bodies endowed with highly specialised expertise, the ESAs should develop draft
regulatory technical standards which do not involve policy choices, for submission to the Commission. Regulatory
technical standards should be developed in the areas of ICT risk management, major ICT-related incident reporting,
testing, as well as in relation to key requirements for a sound monitoring of ICT third-party risk. The Commission
and the ESAs should ensure that those standards and requirements can be applied by all financial entities in a
manner that is proportionate to their size and overall risk profile, and the nature, scale and complexity of their
services, activities and operations. The Commission should be empowered to adopt those regulatory technical
standards by means of delegated acts pursuant to Article 290 TFEU and in accordance with Articles 10 to 14 of
Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010.
(100) To facilitate the comparability of reports on major ICT-related incidents and major operational or security payment-
related incidents, as well as to ensure transparency regarding contractual arrangements for the use of ICT services
provided by ICT third-party service providers, the ESAs should develop draft implementing technical standards
establishing standardised templates, forms and procedures for financial entities to report a major ICT-related
incident and a major operational or security payment-related incident, as well as standardised templates for the
register of information. When developing those standards, the ESAs should take into account the size and the
overall risk profile of the financial entity, and the nature, scale and complexity of its services, activities and
operations. The Commission should be empowered to adopt those implementing technical standards by means of
implementing acts pursuant to Article 291 TFEU and in accordance with Article 15 of Regulations (EU)
No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010.
(^22 ) OJ L 123, 12.5.2016, p. 1.
27.12.2022 EN Official Journal of the European Union L 333/21
(101) Since further requirements have already been specified through delegated and implementing acts based on technical
regulatory and implementing technical standards in Regulations (EC) No 1060/2009(^23 ), (EU) No 648/2012(^24 ),
(EU) No 600/2014(^25 )and (EU) No 909/2014(^26 )of the European Parliament and of the Council, it is appropriate
to mandate the ESAs, either individually or jointly through the Joint Committee, to submit regulatory and
implementing technical standards to the Commission for adoption of delegated and implementing acts carrying
over and updating existing ICT risk management rules.
(102) Since this Regulation, together with Directive (EU) 2022/2556 of the European Parliament and of the Council(^27 ),
entails a consolidation of the ICT risk management provisions across multiple regulations and directives of the
Union’s financial services acquis, including Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014
and (EU) No 909/2014, and Regulation (EU) 2016/1011 of the European Parliament and of the Council(^28 ), in
order to ensure full consistency, those Regulations should be amended to clarify that the applicable ICT risk-related
provisions are laid down in this Regulation.
(103) Consequently, the scope of the relevant articles related to operational risk, upon which empowerments laid down in
Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014, and (EU) 2016/1011
had mandated the adoption of delegated and implementing acts, should be narrowed down with a view to carry
over into this Regulation all provisions covering the digital operational resilience aspects which today are part of
those Regulations.
(104) The potential systemic cyber risk associated with the use of ICT infrastructures that enable the operation of payment
systems and the provision of payment processing activities should be duly addressed at Union level through
harmonised digital resilience rules. To that effect, the Commission should swiftly assess the need for reviewing the
scope of this Regulation while aligning such review with the outcome of the comprehensive review envisaged under
Directive (EU) 2015/2366. Numerous large-scale attacks over the past decade demonstrate how payment systems
have become exposed to cyber threats. Placed at the core of the payment services chain and showing strong
interconnections with the overall financial system, payment systems and payment processing activities acquired a
critical significance for the functioning of the Union financial markets. Cyber-attacks on such systems can cause
severe operational business disruptions with direct repercussions on key economic functions, such as the facilitation
of payments, and indirect effects on related economic processes. Until a harmonised regime and the supervision of
operators of payment systems and processing entities are put in place at Union level, Member States may, with a
view to applying similar market practices, draw inspiration from the digital operational resilience requirements laid
down by this Regulation, when applying rules to operators of payment systems and processing entities supervised
under their own jurisdictions.
(^23 ) Regulation (EC) No 1060/2009 of the European Parliament and of the Council of 16 September 2009 on credit rating agencies
(OJ L 302, 17.11.2009, p. 1).
(^24 ) Regulation (EU) No 648/2012 of the European Parliament and of the Council of 4 July 2012 on OTC derivatives, central
counterparties and trade repositories (OJ L 201, 27.7.2012, p. 1).
(^25 ) Regulation (EU) No 600/2014 of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments
and amending Regulation (EU) No 648/2012 (OJ L 173, 12.6.2014, p. 84).
(^26 ) Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in
the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU)
No 236/2012 (OJ L 257, 28.8.2014, p. 1).
(^27 ) Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022 amending Directives 2009/65/EC,
2009/138/EC, 2011/61/EU, 2013/36/EU, 2014/59/EU, 2014/65/EU, (EU) 2015/2366 and (EU) 2016/2341 as regards digital
operational resilience for the financial sector (see page 153 of this Official Journal).
(^28 ) Regulation (EU) 2016/1011 of the European Parliament and of the Council of 8 June 2016 on indices used as benchmarks in financial
instruments and financial contracts or to measure the performance of investment funds and amending Directives 2008/48/EC
and 2014/17/EU and Regulation (EU) No 596/2014 (OJ L 171, 29.6.2016, p. 1).
L 333/22 EN Official Journal of the European Union 27.12.2022
(105) Since the objective of this Regulation, namely to achieve a high level of digital operational resilience for regulated
financial entities, cannot be sufficiently achieved by the Member States because it requires harmonisation of various
different rules in Union and national law, but can rather, by reason of its scale and effects, be better achieved at Union
level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 of the
Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this
Regulation does not go beyond what is necessary in order to achieve that objective.
(106) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU)
2018/1725 of the European Parliament and of the Council(^29 )and delivered an opinion on 10 May 2021(^30 ),
HAVE ADOPTED THIS REGULATION:
CHAPTER I
General provisions
Article 1
Subject matter
- In order to achieve a high common level of digital operational resilience, this Regulation lays down uniform requirements concerning the security of network and information systems supporting the business processes of financial entities as follows:
(a) requirements applicable to financial entities in relation to:
(i) information and communication technology (ICT) risk management;
(ii) reporting of major ICT-related incidents and notifying, on a voluntary basis, significant cyber threats to the
competent authorities;
(iii)reporting of major operational or security payment-related incidents to the competent authorities by financial
entities referred to in Article 2(1), points (a) to (d);
(iv)digital operational resilience testing;
(v) information and intelligence sharing in relation to cyber threats and vulnerabilities;
(vi)measures for the sound management of ICT third-party risk;
(b) requirements in relation to the contractual arrangements concluded between ICT third-party service providers and
financial entities;
(c) rules for the establishment and conduct of the Oversight Framework for critical ICT third-party service providers when
providing services to financial entities;
(d) rules on cooperation among competent authorities, and rules on supervision and enforcement by competent
authorities in relation to all matters covered by this Regulation.
- In relation to financial entities identified as essential or important entities pursuant to national rules transposing Article 3 of Directive (EU) 2022/2555, this Regulation shall be considered a sector-specific Union legal act for the purposes of Article 4 of that Directive.
- This Regulation is without prejudice to the responsibility of Member States’ regarding essential State functions concerning public security, defence and national security in accordance with Union law.
(^29 ) Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons
with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of
such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39).
(^30 ) OJ C 229, 15.6.2021, p. 16.
27.12.2022 EN Official Journal of the European Union L 333/23
Article 2
Scope
- Without prejudice to paragraphs 3 and 4, this Regulation applies to the following entities:
(a) credit institutions;
(b) payment institutions, including payment institutions exempted pursuant to Directive (EU) 2015/2366;
(c) account information service providers;
(d) electronic money institutions, including electronic money institutions exempted pursuant to Directive 2009/110/EC;
(e) investment firms;
(f) crypto-asset service providers as authorised under a Regulation of the European Parliament and of the Council on
markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives
2013/36/EU and (EU) 2019/1937 (‘the Regulation on markets in crypto-assets’) and issuers of asset-referenced tokens;
(g) central securities depositories;
(h) central counterparties;
(i) trading venues;
(j) trade repositories;
(k) managers of alternative investment funds;
(l) management companies;
(m)data reporting service providers;
(n) insurance and reinsurance undertakings;
(o) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries;
(p) institutions for occupational retirement provision;
(q) credit rating agencies;
(r) administrators of critical benchmarks;
(s) crowdfunding service providers;
(t) securitisation repositories;
(u) ICT third-party service providers.
- For the purposes of this Regulation, entities referred to in paragraph 1, points (a) to (t), shall collectively be referred to as ‘financial entities’.
- This Regulation does not apply to:
(a) managers of alternative investment funds as referred to in Article 3(2) of Directive 2011/61/EU;
(b) insurance and reinsurance undertakings as referred to in Article 4 of Directive 2009/138/EC;
(c) institutions for occupational retirement provision which operate pension schemes which together do not have more
than 15 members in total;
(d) natural or legal persons exempted pursuant to Articles 2 and 3 of Directive 2014/65/EU;
(e) insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries which are microenterprises
or small or medium-sized enterprises;
(f) post office giro institutions as referred to in Article 2(5), point (3), of Directive 2013/36/EU.
L 333/24 EN Official Journal of the European Union 27.12.2022
- Member States may exclude from the scope of this Regulation entities referred to in Article 2(5), points (4) to (23), of Directive 2013/36/EU that are located within their respective territories. Where a Member State makes use of such option, it shall inform the Commission thereof as well as of any subsequent changes thereto. The Commission shall make that information publicly available on its website or other easily accessible means.
Article 3
Definitions
For the purposes of this Regulation, the following definitions shall apply:
(1) ‘digital operational resilience’ means the ability of a financial entity to build, assure and review its operational integrity
and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service
providers, the full range of ICT-related capabilities needed to address the security of the network and information
systems which a financial entity uses, and which support the continued provision of financial services and their
quality, including throughout disruptions;
(2) ‘network and information system’ means a network and information system as defined in Article 6, point 1, of
Directive (EU) 2022/2555;
(3) ‘legacy ICT system’ means an ICT system that has reached the end of its lifecycle (end-of-life), that is not suitable for
upgrades or fixes, for technological or commercial reasons, or is no longer supported by its supplier or by an ICT
third-party service provider, but that is still in use and supports the functions of the financial entity;
(4) ‘security of network and information systems’ means security of network and information systems as defined in
Article 6, point 2, of Directive (EU) 2022/2555;
(5) ‘ICT risk’ means any reasonably identifiable circumstance in relation to the use of network and information systems
which, if materialised, may compromise the security of the network and information systems, of any technology
dependent tool or process, of operations and processes, or of the provision of services by producing adverse effects
in the digital or physical environment;
(6) ‘information asset’ means a collection of information, either tangible or intangible, that is worth protecting;
(7) ‘ICT asset’ means a software or hardware asset in the network and information systems used by the financial entity;
(8) ‘ICT-related incident’ means a single event or a series of linked events unplanned by the financial entity that
compromises the security of the network and information systems, and have an adverse impact on the availability,
authenticity, integrity or confidentiality of data, or on the services provided by the financial entity;
(9) ‘operational or security payment-related incident’ means a single event or a series of linked events unplanned by the
financial entities referred to in Article 2(1), points (a) to (d), whether ICT-related or not, that has an adverse impact
on the availability, authenticity, integrity or confidentiality of payment-related data, or on the payment-related
services provided by the financial entity;
(10) ‘major ICT-related incident’ means an ICT-related incident that has a high adverse impact on the network and
information systems that support critical or important functions of the financial entity;
(11) ‘major operational or security payment-related incident’ means an operational or security payment-related incident
that has a high adverse impact on the payment-related services provided;
(12) ‘cyber threat’ means ‘cyber threat’ as defined in Article 2, point (8), of Regulation (EU) 2019/881;
(13) ‘significant cyber threat’ means a cyber threat the technical characteristics of which indicate that it could have the
potential to result in a major ICT-related incident or a major operational or security payment-related incident;
(14) ‘cyber-attack’ means a malicious ICT-related incident caused by means of an attempt perpetrated by any threat actor to
destroy, expose, alter, disable, steal or gain unauthorised access to, or make unauthorised use of, an asset;
27.12.2022 EN Official Journal of the European Union L 333/25
(15) ‘threat intelligence’ means information that has been aggregated, transformed, analysed, interpreted or enriched to
provide the necessary context for decision-making and to enable relevant and sufficient understanding in order to
mitigate the impact of an ICT-related incident or of a cyber threat, including the technical details of a cyber-attack,
those responsible for the attack and their modus operandi and motivations;
(16) ‘vulnerability’ means a weakness, susceptibility or f law of an asset, system, process or control that can be exploited;
(17) ‘threat-led penetration testing (TLPT)’ means a framework that mimics the tactics, techniques and procedures of real-
life threat actors perceived as posing a genuine cyber threat, that delivers a controlled, bespoke, intelligence-led (red
team) test of the financial entity’s critical live production systems;
(18) ‘ICT third-party risk’ means an ICT risk that may arise for a financial entity in relation to its use of ICT services
provided by ICT third-party service providers or by subcontractors of the latter, including through outsourcing
arrangements;
(19) ‘ICT third-party service provider’ means an undertaking providing ICT services;
(20) ‘ICT intra-group service provider’ means an undertaking that is part of a financial group and that provides
predominantly ICT services to financial entities within the same group or to financial entities belonging to the same
institutional protection scheme, including to their parent undertakings, subsidiaries, branches or other entities that
are under common ownership or control;
(21) ‘ICT services’ means digital and data services provided through ICT systems to one or more internal or external users
on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical
support via software or firmware updates by the hardware provider, excluding traditional analogue telephone
services;
(22) ‘critical or important function’ means a function, the disruption of which would materially impair the financial
performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued,
defective or failed performance of that function would materially impair the continuing compliance of a financial
entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial
services law;
(23) ‘critical ICT third-party service provider’ means an ICT third-party service provider designated as critical in
accordance with Article 31;
(24) ‘ICT third-party service provider established in a third country’ means an ICT third-party service provider that is a
legal person established in a third-country and that has entered into a contractual arrangement with a financial entity
for the provision of ICT services;
(25) ‘subsidiary’ means a subsidiary undertaking within the meaning of Article 2, point (10), and Article 22 of Directive
2013/34/EU;
(26) ‘group’ means a group as defined in Article 2, point (11), of Directive 2013/34/EU;
(27) ‘parent undertaking’ means a parent undertaking within the meaning of Article 2, point (9), and Article 22 of
Directive 2013/34/EU;
(28) ‘ICT subcontractor established in a third country’ means an ICT subcontractor that is a legal person established in a
third-country and that has entered into a contractual arrangement either with an ICT third-party service provider, or
with an ICT third-party service provider established in a third country;
(29) ‘ICT concentration risk’ means an exposure to individual or multiple related critical ICT third-party service providers
creating a degree of dependency on such providers so that the unavailability, failure or other type of shortfall of such
provider may potentially endanger the ability of a financial entity to deliver critical or important functions, or cause it
to suffer other types of adverse effects, including large losses, or endanger the financial stability of the Union as a
whole;
L 333/26 EN Official Journal of the European Union 27.12.2022
(30) ‘management body’ means a management body as defined in Article 4(1), point (36), of Directive 2014/65/EU,
Article 3(1), point (7), of Directive 2013/36/EU, Article 2(1), point (s), of Directive 2009/65/EC of the European
Parliament and of the Council(^31 ), Article 2(1), point (45), of Regulation (EU) No 909/2014, Article 3(1), point (20),
of Regulation (EU) 2016/1011, and in the relevant provision of the Regulation on markets in crypto-assets, or the
equivalent persons who effectively run the entity or have key functions in accordance with relevant Union or
national law;
(31) ‘credit institution’ means a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 of
the European Parliament and of the Council(^32 );
(32) ‘institution exempted pursuant to Directive 2013/36/EU’ means an entity as referred to in Article 2(5), points (4) to
(23), of Directive 2013/36/EU;
(33) ‘investment firm’ means an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU;
(34) ‘small and non-interconnected investment firm’ means an investment firm that meets the conditions laid out in
Article 12(1) of Regulation (EU) 2019/2033 of the European Parliament and of the Council(^33 );
(35) ‘payment institution’ means a payment institution as defined in Article 4, point (4), of Directive (EU) 2015/2366;
(36) ‘payment institution exempted pursuant to Directive (EU) 2015/2366’ means a payment institution exempted
pursuant to Article 32(1) of Directive (EU) 2015/2366;
(37) ‘account information service provider’ means an account information service provider as referred to in Article 33(1)
of Directive (EU) 2015/2366;
(38) ‘electronic money institution’ means an electronic money institution as defined in Article 2, point (1), of Directive
2009/110/EC of the European Parliament and of the Council;
(39) ‘electronic money institution exempted pursuant to Directive 2009/110/EC’ means an electronic money institution
benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC;
(40) ‘central counterparty’ means a central counterparty as defined in Article 2, point (1), of Regulation (EU)
No 648/2012;
(41) ‘trade repository’ means a trade repository as defined in Article 2, point (2), of Regulation (EU) No 648/2012;
(42) ‘central securities depository’ means a central securities depository as defined in Article 2(1), point (1), of Regulation
(EU) No 909/2014;
(43) ‘trading venue’ means a trading venue as defined in Article 4(1), point (24), of Directive 2014/65/EU;
(44) ‘manager of alternative investment funds’ means a manager of alternative investment funds as defined in Article 4(1),
point (b), of Directive 2011/61/EU;
(45) ‘management company’ means a management company as defined in Article 2(1), point (b), of Directive 2009/65/EC;
(46) ‘data reporting service provider’ means a data reporting service provider within the meaning of Regulation (EU)
No 600/2014, as referred to in Article 2(1), points (34) to (36) thereof;
(47) ‘insurance undertaking’ means an insurance undertaking as defined in Article 13, point (1), of Directive 2009/138/EC;
(48) ‘reinsurance undertaking’ means a reinsurance undertaking as defined in Article 13, point (4), of Directive
2009/138/EC;
(^31 ) Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and
administrative provisions relating to undertakings for collective investment in transferable securities (UCITS) (OJ L 302, 17.11.2009,
p. 32).
(^32 ) Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June 2013 on prudential requirements for credit
institutions and amending Regulation (EU) No 648/2012 (OJ L 176, 27.6.2013, p. 1).
(^33 ) Regulation (EU) 2019/2033 of the European Parliament and of the Council of 27 November 2019 on the prudential requirements of
investment firms and amending Regulations (EU) No 1093/2010, (EU) No 575/2013, (EU) No 600/2014 and (EU) No 806/2014
(OJ L 314, 5.12.2019, p. 1).
27.12.2022 EN Official Journal of the European Union L 333/27
(49) ‘insurance intermediary’ means an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU)
2016/97 of the European Parliament and of the Council(^34 );
(50) ‘ancillary insurance intermediary’ means an ancillary insurance intermediary as defined in Article 2(1), point (4), of
Directive (EU) 2016/97;
(51) ‘reinsurance intermediary’ means a reinsurance intermediary as defined in Article 2(1), point (5), of Directive (EU)
2016/97;
(52) ‘institution for occupational retirement provision’ means an institution for occupational retirement provision as
defined in Article 6, point (1), of Directive (EU) 2016/2341;
(53) ‘small institution for occupational retirement provision’ means an institution for occupational retirement provision
which operates pension schemes which together have less than 100 members in total;
(54) ‘credit rating agency’ means a credit rating agency as defined in Article 3(1), point (b), of Regulation (EC)
No 1060/2009;
(55) ‘crypto-asset service provider’ means a crypto-asset service provider as defined in the relevant provision of the
Regulation on markets in crypto-assets;
(56) ‘issuer of asset-referenced tokens’ means an issuer of asset-referenced tokens as defined in the relevant provision of the
Regulation on markets in crypto-assets;
(57) ‘administrator of critical benchmarks’ means an administrator of ‘critical benchmarks’ as defined in Article 3(1), point
(25), of Regulation (EU) 2016/1011;
(58) ‘crowdfunding service provider’ means a crowdfunding service provider as defined in Article 2(1), point (e), of
Regulation (EU) 2020/1503 of the European Parliament and of the Council(^35 );
(59) ‘securitisation repository’ means a securitisation repository as defined in Article 2, point (23), of Regulation (EU)
2017/2402 of the European Parliament and of the Council(^36 );
(60) ‘microenterprise’ means a financial entity, other than a trading venue, a central counterparty, a trade repository or a
central securities depository, which employs fewer than 10 persons and has an annual turnover and/or annual
balance sheet total that does not exceed EUR 2 million;
(61) ‘Lead Overseer’ means the European Supervisory Authority appointed in accordance with Article 31(1), point (b) of
this Regulation;
(62) ‘Joint Committee’ means the committee referred to in Article 54 of Regulations (EU) No 1093/2010, (EU)
No 1094/2010 and (EU) No 1095/2010;
(63) ‘small enterprise’ means a financial entity that employs 10 or more persons, but fewer than 50 persons, and has an
annual turnover and/or annual balance sheet total that exceeds EUR 2 million, but does not exceed EUR 10 million;
(64) ‘medium-sized enterprise’ means a financial entity that is not a small enterprise and employs fewer than 250 persons
and has an annual turnover that does not exceed EUR 50 million and/or an annual balance sheet that does not exceed
EUR 43 million;
(65) ‘public authority’ means any government or other public administration entity, including national central banks.
(^34 ) Directive (EU) 2016/97 of the European Parliament and of the Council of 20 January 2016 on insurance distribution (OJ L 26,
2.2.2016, p. 19).
(^35 ) Regulation (EU) 2020/1503 of the European Parliament and of the Council of 7 October 2020 on European crowdfunding service
providers for business, and amending Regulation (EU) 2017/1129 and Directive (EU) 2019/1937 (OJ L 347, 20.10.2020, p. 1).
(^36 ) Regulation (EU) 2017/2402 of the European Parliament and of the Council of 12 December 2017 laying down a general framework
for securitisation and creating a specific framework for simple, transparent and standardised securitisation, and amending Directives
2009/65/EC, 2009/138/EC and 2011/61/EU and Regulations (EC) No 1060/2009 and (EU) No 648/2012 (OJ L 347, 28.12.2017,
p. 35).
L 333/28 EN Official Journal of the European Union 27.12.2022
Article 4
Proportionality principle
- Financial entities shall implement the rules laid down in Chapter II in accordance with the principle of proportionality, taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations.
- In addition, the application by financial entities of Chapters III, IV and V, Section I, shall be proportionate to their size and overall risk profile, and to the nature, scale and complexity of their services, activities and operations, as specifically provided for in the relevant rules of those Chapters.
- The competent authorities shall consider the application of the proportionality principle by financial entities when reviewing the consistency of the ICT risk management framework on the basis of the reports submitted upon the request of competent authorities pursuant to Article 6(5) and Article 16(2).
Related Documents
LLM Privacy Layer — Complete Research Synthesis
> Compiled from: Secludy website crawl, 4 Medium/blog articles, 10 GitHub repos, 2 deep research reports (85+ sources total), LinkedIn profiles, Google Scholar, web searches.
Regular Expressions (Regex) - A Quick Guide
Regex is a sequence of characters that form a search pattern. It can be used to search, match, or replace strings in text. For example, finding a specific word or validating formats like emails or phone numbers.
sofIA AP2 Protocol Compliance
This document outlines sofIA's full compliance with the official [Agent Payments Protocol (AP2)](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol) specification from Google.
Terms and Conditions for SPIDEY 🕷️
**Last Updated:** November 14, 2025