Article 6 Notification of outsourcing of the reporting obligations


    1. Financial entitiesas defined in Article 2, points (a) to (t) that have outsourced the obligation to report major ICT-related incidents means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity; in accordance with Article 19(5) of Regulation (EU) 2022/2554 shall inform their competent authorityas defined in Article 46 of that outsourcing arrangement as soon as the outsourcing arrangement has been concluded and at the latest prior to the first notification or reporting.

    1. Financial entitiesas defined in Article 2, points (a) to (t) shall provide the competent authorityas defined in Article 46 with the name, contact details, and identification code of the third-party that will submit the major ICT-related incident means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions of the financial entity; notifications or reports for them.

    1. Financial entitiesas defined in Article 2, points (a) to (t) shall inform their competent authorityas defined in Article 46 as soon as they no longer outsource their reporting obligations as referred to in Article 19(5) of Regulation (EU) 2022/2554.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod