Source: OJ L, 2024/1772, 25.6.2024

Current language: EN

Article 6 Criticality of services affected


For the purpose of determining the criticality of the services affected as referred to in Article 18(1), point (e), of Regulation (EU) 2022/2554, financial entities shall assess whether the incident:

  1. affects or has affected ICT services or network and information systems that support critical or important functions of the financial entity;

  2. affects or has affected financial services provided by the financial entity that require authorisation, registration or that are supervised by competent authorities;

  3. constitutes or has constituted a successful, malicious and unauthorised access to the network and information systems of the financial entity.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod