Source: OJ L, 2024/2690, 18.10.2024

Current language: EN

Cybersecurity measures and significant incidents for relevant entities

COMMISSION IMPLEMENTING REGULATION (EU) 2024/2690

of 17 October 2024

laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)(1)OJ L 333, 27.12.2022, p. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj., and in particular Articles 21(5), first subparagraph and 23(11), second subparagraph thereof,

Whereas:

Open full page
Recital 1Relevant entities and purpose of regulation

With regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers as covered by Article 3 of Directive (EU) 2022/2555 (the relevant entities), this Regulation aims to lay down the technical and the methodological requirements of the measures referred to in Article 21(2) of Directive (EU) 2022/2555 and to further specify the cases in which an incident should be considered to be significant as referred to in Article 23(3) of Directive (EU) 2022/2555.

Recital 2Trust service providers

Taking account of the cross-border nature of their activities and in order to ensure a coherent framework for trust service providers, this Regulation should, with respect to trust service providers, further specify the cases in which an incident shall be considered to be significant, in addition to laying down the technical and the methodological requirements of the cybersecurity risk-management measures.

Recital 3Based on standards and technical specifications

Following Article 21(5), third subparagraph of Directive (EU) 2022/2555, the technical and methodological requirements of the cybersecurity risk-management measures set out in the Annex to this Regulation are based on European and international standards, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401, and technical specifications, such as CEN/TS 18026:2024, relevant to the security of network and information systems.

HAS ADOPTED THIS REGULATION:

  1. Article 1Subject matter
  2. Article 2Technical and methodological requirements
  3. Article 3Significant incidents
  4. Article 4Recurring incidents
  5. Article 5Significant incidents with regard to DNS service providers
  6. Article 6Significant incidents with regard to TLD name registries
  7. Article 7Significant incidents with regard to cloud computing service providers
  8. Article 8Significant incidents with regard to data centre service providers
  9. Article 9Significant incidents with regard to content delivery network providers
  10. Article 10Significant incidents with regard to managed service providers and managed security service providers
  11. Article 11Significant incidents with regard to providers of online marketplaces
  12. Article 12Significant incidents with regard to providers of online search engines
  13. Article 13Significant incidents with regard to providers of social networking services platforms
  14. Article 14Significant incidents with regard to trust service providers
  15. Article 15Repeal
  16. Article 16Entry into force and application
Annex
  1. AnnexTechnical and methodological requirements referred to in Article 2 of this Regulation

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 17 October 2024.

For the Commission

Ursula VON DER LEYEN

The President

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod