2025-06-27
The Prudential Control and Resolution Authority (ACPR) has declared its compliance with the Joint Guidelines issued by European supervisory authorities regarding the estimation of annual aggregated costs and losses from major ICT-related incidents under Regulation (EU) 2022/2554. These guidelines apply to financial entities within the ACPR's competence, as defined in Article 2 of the Digital Operational Resilience Act. The ACPR mandates that these entities must take all necessary measures to ensure full compliance with the guidelines, in accordance with Articles 16 of the founding regulations of the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority.
ADVICE ACPR Compliance with the Joint Guidelines of the European Supervisory Authorities on the Estimation of Annual Aggregated Costs and Losses Occasioned by Major ICT-Related Incidents under Regulation (EU) 2022/2554 (JC 2024 34)
The Prudential Control and Resolution Authority (ACPR) has declared itself compliant with the Joint Guidelines of the European Supervisory Authorities on the estimation of annual aggregated costs and losses occasioned by major ICT-related incidents under Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector (JC 2024 34).
These guidelines are applicable to financial entities as defined in Article 2 of Regulation (EU) 2022/2554 mentioned above, which fall under the competence of the ACPR, and which must do everything in their power to comply with them, in accordance with the provisions of Article 16 of Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing respectively the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority.