EU amends financial services directives to add digital operational resilience requirements

Original title: Directive (EU) 2022/2556 of the European Parliament and of the Council of 14 December 2022 amending Directives 2009/65/EC, 2009/138/EC, 2011/61/EU, 2013/36/EU, 2014/59/EU, 2014/65/EU, (EU) 2015/2366 and (EU) 2016/2341 as regards digital operational resilience for the financial sector (Text with EEA relevance)

The European Union adopted Directive (EU) 2022/2556 on 14 December 2022, which amends eight key financial services directives to establish digital operational resilience requirements for the financial sector. The directive introduces new rules on ICT risk management, incident reporting, and third-party service providers' oversight. Payment service providers under PSD2 and other financial institutions must now implement comprehensive measures to manage digital risks, report major ICT incidents to competent authorities, and assess their dependencies on critical third-party service providers.

What changed

  • Directive (EU) 2022/2556 amends Directive (EU) 2015/2366 (PSD2) and seven other financial services directives (on UCITS, insurance, alternative investment funds, credit institutions, insurance guarantee schemes, and market abuse)
  • Introduces binding digital operational resilience requirements for financial institutions, including ICT risk management, incident reporting obligations, and third-party service provider oversight
  • Establishes entry into force on 16 January 2023, with application periods varying by requirement type for financial entities to achieve compliance

Who is affected

Payment service providers, banks, insurance companies, investment firms, fund managers, and other financial institutions operating in the EU; primarily affects larger institutions and those with significant digital operations

Summary generated by a language model; the official text prevails. Not legal advice.