Source: OJ L, 2024/1772, 25.6.2024

Current language: DE

Artikel 6 Kritikalität der betroffenen Dienste


Summary What does Article 6 of the RTS on incident classification say?

This article specifies how financial entities should determine whether the services affected by an incident are critical, which is one of the criteria listed under Article 18(1) of DORA for classifying incidents.

It provides three distinct angles from which criticality can be established: whether core ICT systems supporting critical or important functions were hit, whether regulated financial services were disrupted, or whether a malicious and unauthorised access to network and information systems took place.

Notably, this article also feeds directly into Article 8, which sets out the conditions for classifying an incident as a major incident — meaning a finding of criticality here is a prerequisite for that classification.

Important points:

  • Assess whether an incident has affected ICT services or network and information systems that support critical or important functions of your organisation.
  • Assess whether the incident has disrupted financial services that are subject to authorisation, registration, or supervisory oversight.
  • Assess whether the incident involved a successful, malicious, and unauthorised access to your network and information systems.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Um die in Artikel 18 Absatz 1 Buchstabe e der Verordnung (EU) 2022/2554 genannte Kritikalität der betroffenen Dienste zu bestimmen, bewerten die Finanzunternehmen, ob der Vorfall

  1. IKT-Dienste oder Netzwerk- und Informationssysteme zur Unterstützung kritischer oder wichtiger Funktionen des Finanzunternehmens beeinträchtigt oder beeinträchtigt hat;

  2. von dem Finanzunternehmen erbrachte Finanzdienstleistungen beeinträchtigt oder beeinträchtigt hat, die einer Zulassung oder Registrierung bedürfen oder von den zuständigen Behörden beaufsichtigt werden;

  3. einen erfolgreichen, böswilligen und unbefugten Zugriff auf die Netzwerk- und Informationssysteme des Finanzunternehmens darstellt oder dargestellt hat.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod