2023-09-05
Added · Updated
Regulation (EU) 2022/2554 applies from 17 January 2025, imposing requirements on financial entities regarding ICT risk management, incident reporting, digital operational resilience testing, and ICT third-party risk. The MFSA expects management bodies of these entities to have informed the management body and key function holders, kept abreast of Technical Standards developments, and identified new reporting requirements. Entities must also discuss compliance costs, carry out a gap analysis between current procedures and the Regulation, and formally adopt a transition plan approved by the management body. Additionally, where applicable, entities are expected to engage with external auditors or consultants and ICT Third Party Service Providers regarding the Regulation.
More like this from MFSA
MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.