2024-09-12
Added · Updated
The European Commission adopted five Commission Delegated Regulations supplementing Regulation (EU) 2022/2554, which were published in the EU Official Journal. These regulations specify regulatory technical standards for ICT third-party service provider contractual arrangements, ICT risk management tools and simplified frameworks, ICT incident classification criteria and materiality thresholds, criteria for designating critical ICT third-party service providers, and the calculation and payment of oversight fees. The Malta Financial Services Authority issued this circular to update Authorized Persons regarding these published standards.
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Commission Delegated Regulations under Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector Published in the EU Official Journal (Update 1) This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. As detailed by the latter circular, Regulation (EU) 2022/2554 (“the Regulation”) is to be supplemented by, inter alia, a series of Technical Standards and Guidelines. Following an interinstitutional drafting process by the European Supervisory Authorities (”ESAs”), the following were adopted by the European Commission and have now been published in the EU Official Journal:
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt 5. Commission Delegated Regulation (EU) 2024/1505 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by determining the amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers and the way in which those fees are to be paid (access here). The remaining Technical Standards and Guidelines are expected to be adopted and published in the EU Official Journal in due course. Authorised Persons may request further information by sending an email to the Supervisory ICT Risk and Cybersecurity function on sirc@mfsa.mt.
More like this from MFSA
MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.