Information-security, cyber-risk and incident-reporting requirements for financial institutions. 27 publications, summarized in English and updated same-day.
Final report on amending Guidelines on ICT risk and security management
European Union
EBA
Warning of the European Systemic Risk Board on systemic cyber risks from frontier AI models
European Union
ESRB
Consolidated version of EBA amending Guidelines on ICT and security risk management
European Union
EBA
Opinion of the European Central Bank on the proposed Digital Omnibus regulation
European Union
ECB
Final report on guidelines on internal controls for benchmark administrators, credit rating agencies and market transparency infrastructures
European Union
ESMA
Commission Delegated Regulation (EU) 2025/532 on ICT subcontracting for financial entities
European Union
EC
Guidelines on maintenance of systems and security access protocols under MiCA
European Union
ESMA
Commission Delegated Regulation (EU) 2025/1190 on threat-led penetration testing standards
European Union
EC
Final Report on Guidelines specifying Union standards on systems and security access protocols for crypto-asset offerors
European Union
ESMA
Commission Implementing Regulation (EU) 2024/2956 laying down implementing technical standards for standard templates for the register of information
European Union
EC
Commission Implementing Regulation (EU) 2025/302 on standard forms and procedures for reporting major ICT incidents and cyber threats
European Union
EC
Commission Delegated Regulation (EU) 2025/301 on regulatory technical standards for major ICT-related incident notifications
European Union
EC
Final report on draft regulatory technical standards for ICT subcontracting under DORA
European Union
ESMA
Final Report on Joint Guidelines on oversight cooperation and information exchange between ESAs and competent authorities under DORA
European Union
ESMA
Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents
European Union
ESMA
Final Report on Draft RTS on Harmonisation of Conditions for Oversight of Critical ICT Third-Party Service Providers
European Union
ESMA
Final Report on draft RTS specifying elements related to threat led penetration tests
European Union
ESMA
Final Report on draft RTS on the harmonisation of conditions enabling the conduct of the oversight activities
European Union
ESMA
Final Report on Draft RTS and ITS on Incident Reporting under DORA
European Union
ESMA
Commission Delegated Regulation (EU) 2024/1774 on ICT risk management standards
European Union
EC
Commission Delegated Regulation (EU) 2024/1773 on ICT third-party risk policy standards
European Union
EC
Commission Delegated Regulation (EU) 2024/1772 on ICT incident classification and reporting standards
European Union
EC
Final report on draft RTS to specify the policy on ICT services supporting critical or important functions
European Union
ESMA
Final report on draft RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework
European Union
ESMA
Showing the 24 most recent of 27. Browse the full catalogue