Skip to content

Article Index (EU) 2022/2554

Chapter I – General Provisions (Art. 1–4)

ArticleTopic
Art. 1Subject matter
Art. 2Scope of application
Art. 3Definitions
Art. 4Relationship to NIS2 (lex specialis)

Chapter II – ICT Risk Management (Art. 5–16)

ArticleTopicRTS
Art. 5Governance and organisation
Art. 6ICT risk management framework2024/1774
Art. 7ICT systems, protocols, and tools2024/1774
Art. 8Identification (asset inventory)2024/1774
Art. 9Protection and prevention2024/1774
Art. 10Detection2024/1774
Art. 11Response and recovery2024/1774
Art. 12Backup policies2024/1774
Art. 13Learning and evolving
Art. 14Communication
Art. 15Empowerment for RTS2024/1774
Art. 16Simplified framework

Chapter III – Incident Management (Art. 17–23)

ArticleTopicRTS/ITS
Art. 17General requirements
Art. 18Classification2024/1772
Art. 19Reporting of major incidents2025/301, 2025/302
Art. 20Empowerment for RTS/ITS2025/301, 2025/302
Art. 21–23Centralisation, feedback, cross-border

Chapter IV – Resilience Testing (Art. 24–27)

ArticleTopicRTS
Art. 24–25General, baseline tests
Art. 26–27TLPT2025/1190

Chapter V – Third-Party Risk (Art. 28–44)

ArticleTopicRTS/ITS
Art. 28Principles, registerITS 2024/2956
Art. 29Concentration risk
Art. 30Contracts2024/1773, 2025/532
Art. 31CTPP designationDel. Reg. 2024/1502
Art. 32–39Oversight2025/295
Art. 40JET2025/420
Art. 43FeesDel. Reg. 2024/1505

Chapter VI – Information Sharing (Art. 45)

ArticleTopic
Art. 45Voluntary sharing

Chapters VII–IX (Art. 46–64)

Authorities, transitional and final provisions.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT