Oversight fees

Commission Delegated Regulation (EU) 2024/1505

of 22 February 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council

by determining the amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers and the way in which those fees are to be paid

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience means the ability of a financial entity to build, assure and review its operational integrity and reliability by ensuring, either directly or indirectly through the use of services provided by ICT third-party service providers, the full range of ICT-related capabilities needed to address the security of the network and information systems which a financial entity uses, and which support the continued provision of financial services and their quality, including throughout disruptions; for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011(1)OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj, and in particular Article 43(2) thereof,

Whereas:

Open full page
Recital 1 Annual oversight fee

An annual oversight fee should be established to fully cover the Lead Overseer means the European Supervisory Authority appointed in accordance with Article 31(1), point (b) of this Regulation;’s and the other European Supervisory Authorities’ necessary expenditure when performing oversight tasks in the context of Regulation (EU) 2022/2554. The annual oversight fee should also cover the estimated costs by competent authoritiesas defined in Article 46 to whom tasks are delegated by the European Supervisory Authorities.

Recital 2 Principles of annuality and full cost recovery

In line with the principle of annuality and the principle of full cost recovery, the annual oversight fees should be calculated on the basis of the direct and indirect costs estimated by the ESAsEuropean Supervisory Authority to perform their oversight tasks. The annual oversight fees should be adjusted every year to match the estimated costs.

Recital 3 Fee proportionate to applicable turnover

To ensure the fair allocation of oversight fees which, at the same time, reflects the actual administrative effort devoted to each overseen provider, the annual oversight fee should be proportionate to the turnover generated by the ICT third-party service provider means an undertaking providing ICT services; in the Union from the provision of the ICT services means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; to financial services clients.

HAS ADOPTED THIS REGULATION:

  1. Article 1Estimation of the expenditures of the Lead Overseers when performing their oversight duties
  2. Article 2Applicable turnover of critical ICT third-party service providers for the calculation of the oversight fees
  3. Article 3Calculation of the oversight fees
  4. Article 4Oversight fees in year of designation and opt-in requests
  5. Article 5Payment of the oversight fees
  6. Article 6Communication between the Lead Overseer and critical ICT third-party service providers
  7. Article 7Entry into force and date of application

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 22 February 2024.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod