Skip to content

Guidelines (Level 3)

Joint ESA Guidelines

IdentifierDateTopicBinding Nature
JC/GL/2024/3405.06.2024Estimation of aggregated costs & losses from ICT incidentsComply-or-explain
JC/GL/2024/3617.07.2024ESA cooperation and information sharing in CTPP oversightComply-or-explain

JC/GL/2024/34 – Costs & Losses

Guideline on the standardised estimation of aggregated annual costs and losses from major ICT-related incidents. Relevant for the economic impact analysis in incident reporting (criterion 6).

JC/GL/2024/36 – Oversight Cooperation

Guideline on cooperation and information sharing between the ESAs and national supervisory authorities within the framework of CTPP oversight.

Other Documents

DocumentTopic
ESA Final Report JC 2024-33Explanation of incident reporting RTS/ITS
ESA Final Report TLPTExplanation of TLPT RTS
Joint ESA ReportFeasibility of centralised reporting
ESA Guide on CTPP Oversight (July 2025)Procedures in JETs
CTPP List (November 2025)19 designated critical ICT third-party service providers

Comply-or-Explain

Guidelines are not legally binding, but national supervisory authorities must notify within 2 months of publication whether they comply or intend to comply with the guidelines. In practice, they are treated as binding.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT