Article 2 Systemic impact of ICT third-party service providers on the stability, continuity or quality of the provision of financial services


    1. When considering the criterion set out in Article 31(2), point (a), of Regulation (EU) 2022/2554, the ESAsEuropean Supervisory Authority shall assess whether the ICT third-party service provider means an undertaking providing ICT services; fulfils the following ‘step 1’ sub-criteria:

      1. sub-criterion 1.1: share of the number of financial entitiesas defined in Article 2, points (a) to (t), broken down by categories of financial entitiesas defined in Article 2, points (a) to (t) as listed in Article 2(1) of Regulation (EU) 2022/2554, to which ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; are provided by the same ICT third-party service provider means an undertaking providing ICT services; where the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; support critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law;;

      2. sub-criterion 1.2: share of the total value of assets of financial entitiesas defined in Article 2, points (a) to (t), broken down by categories of financial entitiesas defined in Article 2, points (a) to (t) as listed in Article 2(1) of Regulation (EU) 2022/2554, to which ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; are provided by the same ICT third-party provider where the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; support critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of financial entitiesas defined in Article 2, points (a) to (t).

    1. The sub-criterion 1.1 set out in paragraph 1, point (a), shall be calculated as follows:

      number of financial entitiesas defined in Article 2, points (a) to (t) of a category of financial entitiesas defined in Article 2, points (a) to (t)

      as set out in Article 2(1) of Regulation (EU) 2022/2554,

      to which ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; are provided by the same ICT third party services provider

      where the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; support critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of financial entitiesas defined in Article 2, points (a) to (t)

      total number of financial entitiesas defined in Article 2, points (a) to (t) of a category of financial entitiesas defined in Article 2, points (a) to (t)

      as set out in Article 2(1) of Regulation (EU) 2022/2554

    1. The sub-criterion 1.2 set out in paragraph 1, point (b), shall be calculated as follows:

      total value of assets of financial entitiesas defined in Article 2, points (a) to (t) of a category of financial entitiesas defined in Article 2, points (a) to (t)

      as listed in Article 2(1) of Regulation (EU) 2022/2554,

      to which ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; are provided by the same ICT third party provider

      where the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; support critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of financial entitiesas defined in Article 2, points (a) to (t)

      total value of assets of all EU financial entitiesas defined in Article 2, points (a) to (t) of the same category

      as set out in Article 2(1) of Regulation (EU) 2022/2554

    1. An ICT third-party service provider means an undertaking providing ICT services; shall be considered as having fulfilled the ‘step 1’ sub-criteria referred to in paragraph 1 where both of the shares as calculated in accordance with paragraphs 2 and 3 are of at least 10 % of the total number for at least one category of financial entitiesas defined in Article 2, points (a) to (t) as set out in Article 2(1) of Regulation (EU) 2022/2554.

    1. When considering the criterion set out in Article 31(2), point (a), of Regulation (EU) 2022/2554 and where the ICT third-party service provider means an undertaking providing ICT services; fulfils the ‘step 1’ sub-criteria referred to in paragraph 1 of this Article, the ESAsEuropean Supervisory Authority shall carry out their assessment in the light of the following ‘step 2’ sub-criteria:

      1. sub-criterion 1.3: the intensity of the impact of discontinuing the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; provided by the ICT third-party service provider means an undertaking providing ICT services; on the activities and operations of financial entitiesas defined in Article 2, points (a) to (t) identified in the ‘step 1’ sub-criteria referred to in paragraph 1 of this Article and the number of those financial entitiesas defined in Article 2, points (a) to (t) affected;

      2. sub-criterion 1.4: the dependence of the critical ICT third-party service provider means an ICT third-party service provider designated as critical in accordance with Article 31; on the same subcontractors providing ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; supporting critical or important functions means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of financial entitiesas defined in Article 2, points (a) to (t).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod