Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011Text with EEA relevance.
32022R2554
European Union
Article 27
§ Article 45
Article 45 of Regulation (EU) No 909/2014 is amended as follows:
(1) paragraph 1 is replaced by the following:
- A CSD shall identify sources of operational risk, both internal and external, and minimise their impact also through the deployment of appropriate ICT tools, processes and policies set up and managed in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the Council
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1).;
, as well as through any other relevant appropriate tools, controls and procedures for other types of operational risk, including for all the securities settlement systems it operates.
(2) paragraph 2 is deleted;
(3) paragraphs 3 and 4 are replaced by the following:
- For services that it provides as well as for each securities settlement system that it operates, a CSD shall establish, implement and maintain an adequate business continuity policy and disaster recovery plan, including ICT business continuity policy and ICT response and recovery plans established in accordance with Regulation (EU) 2022/2554, to ensure the preservation of its services, the timely recovery of operations and the fulfilment of the CSD’s obligations in the case of events that pose a significant risk to disrupting operations.
- The plan referred to in paragraph 3 shall provide for the recovery of all transactions and participants’ positions at the time of disruption to allow the participants of a CSD to continue to operate with certainty and to complete settlement on the scheduled date, including by ensuring that critical IT systems can resume operations from the time of disruption as provided for in Article 12(5) and (7) of Regulation (EU) 2022/2554.;
(4) paragraph 6 is replaced by the following:
- A CSD shall identify, monitor and manage the risks that key participants in the securities settlement systems it operates, as well as service and utility providers, and other CSDs or other market infrastructures might pose to its operations. It shall, upon request, provide competent and relevant authorities with information on any such risk identified. It shall also inform the competent authority and relevant authorities without delay of any operational incidents, other than in relation to ICT risk, resulting from such risks.;
(5) in paragraph 7, the first subparagraph is replaced by the following:
- ESMA shall, in close cooperation with the members of the ESCB, develop draft regulatory technical standards to specify the operational risks referred to in paragraphs 1 and 6, other than ICT risk, and the methods to test, to address or to minimise those risks, including the business continuity policies and disaster recovery plans referred to in paragraphs 3 and 4 and the methods of assessment thereof..
Article 62
Amendments to Regulation (EU) No 600/2014
Regulation (EU) No 600/2014 is amended as follows:
(1) Article 27g is amended as follows:
(a) paragraph 4 is replaced by the following:
- An APA shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554 of the European Parliament and of the Council
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1).;
.
(b) in paragraph 8, point (c) is replaced by the following:
(c) the concrete organisational requirements laid down in paragraphs 3 and 5.;
(2) Article 27h is amended as follows:
(a) paragraph 5 is replaced by the following:
- A CTP shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554..
(b) in paragraph 8, point (e) is replaced by the following:
(e) the concrete organisational requirements laid down in paragraph 4.;
(3) Article 27i is amended as follows:
(a) paragraph 3 is replaced by the following:
- An ARM shall comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554.;
(b) in paragraph 5, point (b) is replaced by the following:
(b) the concrete organisational requirements laid down in paragraphs 2 and 4..
Article 63
Amendment to Regulation (EU) 2016/1011
In Article 6 of Regulation (EU) 2016/1011, the following paragraph is added:
- For critical benchmarks, an administrator shall have sound administrative and accounting procedures, internal control mechanisms, effective procedures for risk assessment, and effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the Council
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1)..
.
Article 64
Entry into force and application
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from 17 January 2025.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Strasbourg, 14 December 2022.
For the European Parliament
The President
R. Metsola
For the Council
The President
M. Bek
Metadata
- Type
- Forordning
- År
- 2022
- Ikrafttrædelsesdato
- 1. januar 1970