2024-11-06
Added · Updated
The European Supervisory Authorities establish procedures for cooperation and information exchange between the ESAs and competent authorities regarding the oversight of critical ICT third-party service providers under Regulation (EU) 2022/2554. Competent authorities must submit registers of information to the ESAs for criticality assessments and share relevant data with NIS2 authorities, while the Lead Overseer must notify competent authorities of designation decisions, oversight plans, and inspection details within specified timelines. The guidelines mandate the exchange of information concerning the follow-up of recommendations, including remediation plans, penalty payments, and non-compliance notifications, within ten working days of receipt or adoption. Competent authorities are required to notify the respective ESA of their compliance status within two months of the issuance of the translated guidelines.
More like this from ESMA
We email you every new ESMA publication the day it's published.