Commission Delegated Regulation (EU) 2024/1502of 22 February 2024supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities(Text with EEA relevance)
32024R1502
European Union
§ Article 2
Article 2(1) of Regulation (EU) 2022/2554,
for which no alternative ICT third party service provider is available
which has the required capacity to provide the same ICT services
that support critical or important functions of financial entities
as the one provided by the relevant ICT third party service provider
total number of financial entities of that category of financial entities
as set out in Article 2(1)of Regulation 2022/2554
- The sub-criterion set out in paragraph 1, point (b), shall be calculated as follows:
number of financial entities of a category of financial entities as set out in
Article 2(1) of Regulation (EU) 2022/2554,
for which it is highly difficult to migrate or reintegrate an ICT service provided
by the ICT third party provider that support
critical or important functions to another ICT third party provider
total number of EU financial entities of that category of financial entities
as set out in Article 2(1) of Regulation (EU) 2022/2554
- An ICT third-party service provider shall be considered as having fulfilled both sub-criteria 4.1 and 4.2 where either of the following is met:
(a) the share of the total number of financial entities referred to in paragraph 1, point (a), is of at least 10 % of the total number of financial entities for a category of financial entities as set out in Article 2(1) of Regulation (EU) 2022/2554;
(b) the share of the total number of financial entities referred to in paragraph 1, point (b), is of at least 10 % of the total number of financial entities or a category of financial entities as set out in Article 2(1) of Regulation (EU) 2022/2554.
- When considering the criterion set out in Article 31(2), point (d), of Regulation (EU) 2022/2554 and where the ICT third-party service provider fulfils the step 1 sub-criteria referred to in paragraph 1 of this Article, the ESAs shall carry out their assessment in the light of the step two sub-criterion specified in Article 31(2), point (d)(i) of Regulation (EU) 2022/2554.
Article 6
Information sources to enable criticality assessment
- The ESAs shall use the data provided by the registers of information referred to in Article 28(3) of Regulation (EU) 2022/2554, for the assessment of the sub-criteria listed in Articles 2 to 5. The ESAs may also use additional available data they have at their disposal from all sources of information to perform the criticality assessment.
- The ESAs shall take into account the most recent data available to them during the assessment year, or where applicable, the data that has been made available to them at the latest by 31 December of the year preceding the criticality assessment.
Article 7
Entry into force and application
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
However, the Lead Overseer shall apply the sub-criterion 1.4 referred to in Article 2, paragraph 5, point (b) as of 16 January 2025.
This Regulation shall be binding in its entirety and directly applicable in all Member States.
Done at Brussels, 22 February 2024.
For the Commission
The President
Ursula von der Leyen
Metadata
- Type
- Forordning
- År
- 2024
- Ikrafttrædelsesdato
- 1. januar 1970