Cybersecurity measures and significant incidents for relevant entities

Commission Implementing Regulation (EU) 2024/2690

of 17 October 2024

laying down rules for the application of Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and further specification of the cases in which an incident is considered to be significant with regard to DNS service providers, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers, managed security service providers, providers of online market places, of online search engines and of social networking services platforms, and trust service providers

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)(1)OJ L 333, 27.12.2022, p. 80, ELI: http://data.europa.eu/eli/dir/2022/2555/oj., and in particular Articles 21(5), first subparagraph and 23(11), second subparagraph thereof,

Whereas:

Open full page
Recital 1 Relevant entities and purpose of regulation

With regard to DNS service providers means an entity that provides: publicly available recursive domain name resolution services for internet end-users; or authoritative domain name resolution services for third-party use, with the exception of root name servers;, TLD name registries, cloud computing service means a digital service that enables on-demand administration and broad remote access to a scalable and elastic pool of shareable computing resources, including where such resources are distributed across several locations; providers, data centre service means a service that encompasses structures, or groups of structures, dedicated to the centralised accommodation, interconnection and operation of IT and network equipment providing data storage, processing and transport services together with all the facilities and infrastructures for power distribution and environmental control; providers, content delivery network means a network of geographically distributed servers for the purpose of ensuring high availability, accessibility or fast delivery of digital content and services to internet users on behalf of content and service providers; providers, managed service providers means an entity that provides services related to the installation, management, operation or maintenance of ICT products, networks, infrastructure, applications or any other network and information systems, via assistance or active administration carried out either on customers’ premises or remotely;, managed security service providers means a managed service provider that carries out or provides assistance for activities relating to cybersecurity risk management;, providers of online market places, of online search engines means an online search engine as defined in Article 2, point (5), of Regulation (EU) 2019/1150 of the European Parliament and of the Council (^32^); Regulation (EU) 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services (OJ L 186, 11.7.2019, p. 57). and of social networking services platforms means a platform that enables end-users to connect, share, discover and communicate with each other across multiple devices, in particular via chats, posts, videos and recommendations;, and trust service providers means a trust service provider as defined in Article 3, point (19), of Regulation (EU) No 910/2014; as covered by Article 3 of Directive (EU) 2022/2555 (the relevant entities means a natural or legal person created and recognised as such under the national law of its place of establishment, which may, acting under its own name, exercise rights and be subject to obligations;), this Regulation aims to lay down the technical and the methodological requirements of the measures referred to in Article 21(2) of Directive (EU) 2022/2555 and to further specify the cases in which an incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; should be considered to be significant as referred to in Article 23(3) of Directive (EU) 2022/2555.

Recital 2 Trust service providers

Taking account of the cross-border nature of their activities and in order to ensure a coherent framework for trust service providers means a trust service provider as defined in Article 3, point (19), of Regulation (EU) No 910/2014;, this Regulation should, with respect to trust service providers means a trust service provider as defined in Article 3, point (19), of Regulation (EU) No 910/2014;, further specify the cases in which an incident means an incident as defined in Article 6, point (6), of Directive (EU) 2022/2555; shall be considered to be significant, in addition to laying down the technical and the methodological requirements of the cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; risk-management measures.

Recital 3 Based on standards and technical specifications

Following Article 21(5), third subparagraph of Directive (EU) 2022/2555, the technical and methodological requirements of the cybersecurity means cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881; risk-management measures set out in the Annex to this Regulation are based on European and international standards means an international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012;, such as ISO/IEC 27001, ISO/IEC 27002 and ETSI EN 319401, and technical specifications means a technical specification as defined in Article 2, point (4), of Regulation (EU) No 1025/2012;, such as CEN/TS 18026:2024, relevant to the security of network and information systems means the ability of network and information systems to resist, at a given level of confidence, any event that may compromise the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, those network and information systems;.

HAS ADOPTED THIS REGULATION:

  1. Article 1Subject matter
  2. Article 2Technical and methodological requirements
  3. Article 3Significant incidents
  4. Article 4Recurring incidents
  5. Article 5Significant incidents with regard to DNS service providers
  6. Article 6Significant incidents with regard to TLD name registries
  7. Article 7Significant incidents with regard to cloud computing service providers
  8. Article 8Significant incidents with regard to data centre service providers
  9. Article 9Significant incidents with regard to content delivery network providers
  10. Article 10Significant incidents with regard to managed service providers and managed security service providers
  11. Article 11Significant incidents with regard to providers of online marketplaces
  12. Article 12Significant incidents with regard to providers of online search engines
  13. Article 13Significant incidents with regard to providers of social networking services platforms
  14. Article 14Significant incidents with regard to trust service providers
  15. Article 15Repeal
  16. Article 16Entry into force and application

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 17 October 2024.

For the Commission

Ursula VON DER LEYEN

The President

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod