Added · Updated

Final report on amending Guidelines on ICT risk and security management

The European Banking Authority amends its 2019 ICT and security risk management guidelines to align with the Digital Operational Resilience Act, which now covers most financial entities. The EBA repeals the majority of the original guidelines, retaining only requirements for payment service user relationship management to address entities excluded from DORA. Competent authorities must notify compliance by 20 May 2025, with the amended guidelines applying from that date.

European Banking Authority logo

European Union

European Banking Authority

Scan of the document's first page
Share

EBA published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: Amended

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: European Banking Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EBA

EBA published 1 document in the last 30 days. We email you each new one the day it's published.