Archives: Documents

10 Results

  • Public consultation
    Document date: 6 March 2025
    Archived since 13 March 2026

    The European Banking Authority consults on new rules related to the anti-money laundering and countering the financing of terrorism package

    AMLA
    due by 6 June 2025

  • RTS
    Document date: 13 February 2025

    Commission Delegated Regulation (EU) 2025/295 of 24 October 2024

    supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards on harmonisation of conditions enabling the conduct of the oversight activities

  • RTS
    Document date: 13 February 2025

    Commission Delegated Regulation

    supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition

  • ITS
    Document date: 20 February 2025

    Commission Implementing Regulation (EU) 2025/302 of 23 October 2024

    laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat

  • RTS
    Document date: 20 February 2025

    Commission Delegated Regulation (EU) 2025/301 of 23 October 2024

    supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats