2024-01-05
Added · Updated
Credit institutions and market infrastructures designated as operators of essential services must classify incidents and notify the CSSF without undue delay of those having a significant impact on essential service continuity. Support PFS acting as digital service providers must classify incidents and notify the CSSF without undue delay of those having a substantial impact on digital service provision within the European Union. Incident classification and notification arrangements must comply with specifications detailed in a CSSF circular. This regulation enters into force on 1 April 2024.
CSSF Regulation No 24-01 of 5 January 2024
In case of discrepancies between the French and the English texts, the French text shall prevail. CSSF REGULATION NO 24-01 OF 5 JANUARY 2024 2/3 CSSF Regulation No 24-01 of 5 January 2024 relating to the notification of incidents according to the Law of 28 May 2019 transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union. (Mém. A 2024, No 3) The Executive Board of the Commission de Surveillance du Secteur Financier, Having regard to Article 129(2) of the Constitution; Having regard to the Law of 23 December 1998 establishing a financial sector supervisory commission (“Commission de surveillance du secteur financier”), as amended, and in particular Article 9(2) thereof; Having regard to the Law of 28 May 2019 transposing Directive (EU) 2016/1148 of the European Parliament and of the Council of 6 July 2016 concerning measures for a high common level of security of network and information systems across the European Union (the “NIS Law”) and amending the Law of 20 April 2009 establishing the Government IT Centre, as amended, and the Law of 23 July 2016 establishing a High Commission for National Protection; Having regard to Article 3 of the NIS Law designating the Commission de Surveillance du Secteur Financier (hereinafter, the “CSSF”), as the competent authority for the security of network and information systems covering the sectors of credit institutions and financial market infrastructures as defined in points (3) and (4) of the Annex to the NIS Law, as well as the digital services provided by an entity under the supervision of the CSSF; Having regard to Article 8(5) of the NIS Law under which the competent authority may specify, by way of a regulation, the parameters, modalities and timeframes for notifications of incidents having a significant impact on the continuity of the essential services that operators of essential services provide; Having regard to Article 11(3) of the NIS Law under which the competent authority shall determine, by way of a regulation, the modalities, format and timeframe for the notifications of incidents having a substantial impact on the provision of a digital service that digital service providers offer within the European Union; Having regard to the opinion of the of the Consultative Committee for Prudential Regulation; Decides: Article 1 Definitions
CSSF REGULATION NO 24-01 OF 5 JANUARY 2024 3/3 e. “Essential service” means a service which is essential for the maintenance of critical societal and/or economic activities and which is listed as essential service in Article 2 of CSSF Regulation No 20-04 of 15 July 2020. f. “Digital service provider” means, in accordance with point (5) of Article 2 of the NIS Law, a legal person that provides a digital service as defined in point (4) of Article 2 of the NIS Law2. Article 2 Incident classification and major incident notification requirements
More like this from CSSF
We email you every new CSSF publication the day it's published.