RTS on joint examination teams

Commission Delegated Regulation (EU) 2025/420

of 16 December 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council

with regard to regulatory technical standards to specify the criteria for determining the composition of the joint examination team ensuring a balanced participation of staff members from the ESAs and from the relevant competent authorities, their designation, tasks and working arrangements

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council, of 14 December 2022 on digital operational resilience means the ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions; for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011(1)OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj., and in particular Article 41(2), second subparagraph, thereof,

Whereas:

Open full page
Recital 1 Cooperation between the ESAs and NCAs

The oversight framework established by Regulation (EU) 2022/2554 should be built on a structured and continuous cooperation between the European Supervisory Authorities (ESAsEuropean Supervisory Authority) and the competent authoritiesas defined in Article 46 through the Oversight Foruma sub-committee of the Joint Committee for the purposes of supporting the work of the Joint Committee and of the Lead Overseer in the area of ICT third-party risk across financial sectors and the joint examination teams.

Recital 2 Technical expertise requirements for JETs

The authorities referred to in Article 40(2) of Regulation (EU) 2022/2554 should ensure that their staff members that are to be appointed as members of the joint examination team referred to in Article 40(1) of that Regulation has the technical expertise required in the profiles needed in the joint examination teams. The demonstration that an authority does not have staff meeting the specific technical expertise needed in the joint examination teams should be considered by the Lead Overseer means the European Supervisory Authority appointed in accordance with Article 31(1), point (b) of this Regulation; as a justification to discharge, at that point in time, the authorities of their obligation to nominate staff members to the joint examination teams. In that case, the authority should nevertheless commit on the best effort basis to address that shortfall of expertise and try to reinforce its capabilities to contribute to the joint examination teams in the context of the next exercise.

Recital 3 Employment status for JET members

Staff members of the authorities referred to in Article 40(2) of Regulation (EU) 2022/2554 that are designated as members of a joint examination team as referred to in Article 40(1) of that Regulation should continue to be employees of the nominating authority and therefore subject to working hours and permanent location of work as included in their employment contracts.

HAS ADOPTED THIS REGULATION:

  1. Article 1Tasks of the members of the joint examination team
  2. Article 2Establishment of the joint examination team
  3. Article 3Members of the joint examination team
  4. Article 4Change of the membership in the joint examination team
  5. Article 5Working arrangements of the members of the joint examination team
  6. Article 6Entry into force

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 16 December 2024.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod