It looks like you're a bot or automated crawler (sorry if you're not).
We don't generate full content for automated requests.
For the full experience, please visit with a regular browser.
Article 1: Subject matter
Article 2: Scope
Article 3: Definitions
Article 4: Proportionality principle
Article 5: Governance and organisation
Article 6: ICT risk management framework
Article 7: ICT systems, protocols and tools
Article 8: Identification
Article 9: Protection and prevention
Article 10: Detection
Article 11: Response and recovery
Article 12: Backup policies and procedures, restoration and recovery procedures and methods
Article 13: Learning and evolving
Article 14: Communication
Article 15: Further harmonisation of ICT risk management tools, methods, processes and policies
Article 16: Simplified ICT risk management framework
Article 17: ICT-related incident management process
Article 18: Classification of ICT-related incidents and cyber threats
Article 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
Article 20: Harmonisation of reporting content and templates
Article 21: Centralisation of reporting of major ICT-related incidents
Article 22: Supervisory feedback
Article 23: Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Article 24: General requirements for the performance of digital operational resilience testing
Article 25: Testing of ICT tools and systems
Article 26: Advanced testing of ICT tools, systems and processes based on TLPT
Article 27: Requirements for testers for the carrying out of TLPT
Article 28: General principles
Article 29: Preliminary assessment of ICT concentration risk at entity level
Article 30: Key contractual provisions
Article 31: Designation of critical ICT third-party service providers
Article 32: Structure of the Oversight Framework
Article 33: Tasks of the Lead Overseer
Article 34: Operational coordination between Lead Overseers
Article 35: Powers of the Lead Overseer
Article 36: Exercise of the powers of the Lead Overseer outside the Union
Article 37: Request for information
Article 38: General investigations
Article 39: Inspections
Article 40: Ongoing oversight
Article 41: Harmonisation of conditions enabling the conduct of the oversight activities
Article 42: Follow-up by competent authorities
Article 43: Oversight fees
Article 44: International cooperation
Article 45: Information-sharing arrangements on cyber threat information and intelligence
Article 46: Competent authorities
Article 47: Cooperation with structures and authorities established by Directive (EU) 2022/2555
Article 48: Cooperation between authorities
Article 49: Financial cross-sector exercises, communication and cooperation
Article 50: Administrative penalties and remedial measures
Article 51: Exercise of the power to impose administrative penalties and remedial measures
Article 52: Criminal penalties
Article 53: Notification duties
Article 54: Publication of administrative penalties
Article 55: Professional secrecy
Article 56: Data Protection
Article 57: Exercise of the delegation
Article 58: Review clause
Article 59: Amendments to Regulation (EC) No 1060/2009
Article 60: Amendments to Regulation (EU) No 648/2012
Article 61: Amendments to Regulation (EU) No 909/2014
Article 62: Amendments to Regulation (EU) No 600/2014
Article 63: Amendment to Regulation (EU) 2016/1011
Article 64: Entry into force and application
Recitals
Recital 1
Recital 2
Recital 3
Recital 4
Recital 5
Recital 6
Recital 7
Recital 8
Recital 9
Recital 10
Recital 11
Recital 12
Recital 13
Recital 14
Recital 15
Recital 16
Recital 17
Recital 18
Recital 19
Recital 20
Recital 21
Recital 22
Recital 23
Recital 24
Recital 25
Recital 26
Recital 27
Recital 28
Recital 29
Recital 30
Recital 31
Recital 32
Recital 33
Recital 34
Recital 35
Recital 36
Recital 37
Recital 38
Recital 39
Recital 40
Recital 41
Recital 42
Recital 43
Recital 44
Recital 45
Recital 46
Recital 47
Recital 48
Recital 49
Recital 50
Recital 51
Recital 52
Recital 53
Recital 54
Recital 55
Recital 56
Recital 57
Recital 58
Recital 59
Recital 60
Recital 61
Recital 62
Recital 63
Recital 64
Recital 65
Recital 66
Recital 67
Recital 68
Recital 69
Recital 70
Recital 71
Recital 72
Recital 73
Recital 74
Recital 75
Recital 76
Recital 77
Recital 78
Recital 79
Recital 80
Recital 81
Recital 82
Recital 83
Recital 84
Recital 85
Recital 86
Recital 87
Recital 88
Recital 89
Recital 90
Recital 91
Recital 92
Recital 93
Recital 94
Recital 95
Recital 96
Recital 97
Recital 98
Recital 99
Recital 100
Recital 101
Recital 102
Recital 103
Recital 104
Recital 105
Recital 106
Definitions
account information service provider
administrator of critical benchmarks
central counterparty
central securities depository
credit institution
critical ICT third-party service provider
critical or important function
crypto-asset service provider
cyber-attack
data reporting service provider
digital operational resilience
electronic money institution exempted pursuant to Directive 2009/110/EC
group
ICT asset
ICT concentration risk
ICT intra-group service provider
ICT risk
ICT services
ICT subcontractor established in a third country
ICT third-party risk
ICT third-party service provider
ICT third-party service provider established in a third country
information asset
institution exempted pursuant to Directive 2013/36/EU
institution for occupational retirement provision
insurance undertaking
issuer of asset-referenced tokens
Joint Committee
Lead Overseer
legacy ICT system
management body
management company
manager of alternative investment funds
medium-sized enterprise
microenterprise
network and information system
parent undertaking
payment institution exempted pursuant to Directive (EU) 2015/2366
reinsurance undertaking
significant cyber threat
small and non-interconnected investment firm
small enterprise
small institution for occupational retirement provision
subsidiary
threat intelligence
threat-led penetration testing
vulnerability
Footnote p0: This Regulation shall be binding in its entirety and directly applicable in all Member States.