My bookmarksSign up free

Commission Delegated Regulation (EU) 2025/1190 ANNEX II

Commission Delegated Regulation (EU) 2025/1190 ANNEX II

Content of the scope specification document (Article 9(6))

ANNEX IISupplementary provisions

ANNEX II Content of the scope specification document (Article 9(6)) 1.    The scope specification document shall contain a list of all critical or important functions identified by the financial entity. 2.    For each identified critical or important function, the following information shall be included: (a) where the critical or important function is not included in the scope of the TLPT, the explanation of the reasons for which it is not included; (b) where the critical or important function is included in the scope of the TLPT: (i) the explanation of the reasons for its inclusion; (ii) the identified ICT system(s) supporting that critical or important function; (iii) for each identified ICT system: 1. whether it is outsourced and if so, the name of the ICT third party service provider; 2. the jurisdictions in which the ICT system is used; 3. a high-level description of preliminary flag(s), indicating which security aspect of confidentiality, integrity, authenticity or availability is covered by each flag.

Read the full instrument →

Other provisions in Commission Delegated Regulation (EU) 2025/1190

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationANNEX II of Commission Delegated Regulation (EU) 2025/1190 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next