My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1774 Article 2

Commission Delegated Regulation (EU) 2024/1774 Article 2

General elements of ICT security policies, procedures, protocols, and tools

Article 2

1.   Financial entities shall ensure that their ICT security policies, information security, and related procedures, protocols, and tools as referred to in Article 9(2) of Regulation (EU) 2022/2554 are embedded in their ICT risk management framework. Financial entities shall establish the ICT security policies, procedures, protocols, and tools laid down in this Chapter that: (a) ensure the security of networks; (b) contain safeguards against intrusions and data misuse; (c) preserve the availability, authenticity, integrity, and confidentiality of data, including via the use of cryptographic techniques; (d) guarantee an accurate and prompt data transmission without major disruptions and undue delays. 2.   Financial entities shall ensure that the ICT security policies referred to in paragraph 1: (a) are aligned to the financial entity’s information security objectives included in the digital operational resilience strategy referred to in Article 6(8) of Regulation (EU) 2022/2554; (b) indicate the date of the formal approval of the ICT security policies by the management body; (c) contain indicators and measures to: (i) monitor the implementation of the ICT security policies, procedures, protocols, and tools; (ii) record exceptions from that implementation; (iii) ensure that the digital operational resilience of the financial entity is ensured in case of exceptions as referred to in point (ii); (d) specify the responsibilities of staff at all levels to ensure the financial entity’s ICT security; (e) specify the consequences of non-compliance by staff of the financial entity with the ICT security policies, where provisions to that effect are not laid down in other policies of the financial entity; (f) list the documentation to be maintained; (g) specify the segregation of duties arrangements in the context of the three lines of defence model or other internal risk management and control model, as applicable, to avoid conflicts of interest; (h) consider leading practices and, where applicable, standards as defined in Article 2, point (1), of Regulation (EU) No 1025/2012; (i) identify the roles and responsibilities for the development, implementation and maintenance of ICT security policies, procedures, protocols, and tools; (j) are reviewed in accordance with Article 6(5) of Regulation (EU) 2022/2554; (k) take into account material changes concerning the financial entity, including material changes to the activities or processes of the financial entity, to the cyber threat landscape, or to applicable legal obligations.

Read the full instrument → · Read this in context: Section 1 →

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 2 of Commission Delegated Regulation (EU) 2024/1774 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next