REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL | 32022R2554 — European Union law | Esheria

REGULATION (EU) 2022/2554 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

This part explains the purpose and scope of the EU digital operational resilience regime for financial entities, ICT services, incident reporting, testing, third-party risk, and information sharing.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
European Union
Instrument
Regulation
Citation
32022R2554
Status
In force
Version
Undated source snapshot
Language
en
Official source
View official record ↗
ICT risk management ICT third-party risk administrative penalties backup and recovery business continuity competent authorities cybersecurity digital operational resilience financial entities incident management incident reporting information requests information sharing inspections internal controls major ICT-related incident reporting operational resilience outsourcing oversight testing third-party risk

Publicly available, excluded from search-engine indexing

This page remains available for direct access and API use, but this release emits noindex,follow for the following reason:

  • The record does not meet this release's canonical indexing criteria. (market-indexing-disabled)

Statute overview

About this statute

This part explains the purpose and scope of the EU digital operational resilience regime for financial entities, ICT services, incident reporting, testing, third-party risk, and information sharing. Financial entities must report major ICT incidents to the relevant competent authority, with a single addressee where multiple national authorities supervise them; significant credit institutions report via national authorities, which then pass the report to the ECB. This Regulation sets uniform ICT risk and digital resilience requirements for financial entities, including governance, incident detection, continuity, and backup/recovery. Financial entities covered by this text must maintain ICT resilience, incident management, testing, reporting, and recovery controls; microenterprises get some lighter treatment in a few places. Financial entities must manage ICT third-party risk, keep records, report to competent authorities, prepare exit strategies, and meet information-security and contracting conditions for ICT outsourcing.