2024-02-22

Added · Updated

Commission Delegated Regulation (EU) 2024/1502 on criteria for designating ICT third-party service providers as critical

The European Commission adopts a two-step assessment framework for the European Supervisory Authorities to designate ICT third-party service providers as critical for financial entities under Regulation (EU) 2022/2554. The regulation establishes specific quantitative thresholds, including a 10% share of financial entities or assets, and qualitative criteria involving global systemically important institutions to determine systemic impact and substitutability. The Lead Overseer must apply sub-criterion 1.4 regarding subcontractor dependence starting from 16 January 2025, while the regulation enters into force on the twentieth day following its publication.

European Commission logo

European Union

European Commission

Click to view full text