My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1774 Article 7

Commission Delegated Regulation (EU) 2024/1774 Article 7

Cryptographic key management

Article 7

1.   Financial entities shall include in the cryptographic key management policy referred to in Article 6(2), point (d), requirements for managing cryptographic keys through their whole lifecycle, including generating, renewing, storing, backing up, archiving, retrieving, transmitting, retiring, revoking, and destroying those cryptographic keys. 2.   Financial entities shall identify and implement controls to protect cryptographic keys through their whole lifecycle against loss, unauthorised access, disclosure, and modification. Financial entities shall design those controls on the basis of the results of the approved data classification and the ICT risk assessment. 3.   Financial entities shall develop and implement methods to replace the cryptographic keys in the case of loss, or where those keys are compromised or damaged. 4.   Financial entities shall create and maintain a register for all certificates and certificate-storing devices for at least ICT assets supporting critical or important functions. Financial entities shall keep that register up to date. 5.   Financial entities shall ensure the prompt renewal of certificates in advance of their expiration.

Read the full instrument → · Read this in context: Section 4 — Encryption and cryptography →

Other provisions in Section 4 — Encryption and cryptography

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 7 of Commission Delegated Regulation (EU) 2024/1774 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next