Lex Browse everything How it works For developers

Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554

as it stood on 2024-06-25, permalink: /eu-eurlex/32024r1774/2024-06-25

2024-03-132024-06-25

2 versions · click any mark to read the law as it stood that day · the one you are reading

Point-in-time view as at 2024-06-25. This version has been superseded, it applied 2024-06-25 → open. Jump to the version in force today or see exactly what changed next.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each article carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 42 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38 Article 39 Article 40 Article 41 Article 42

Article 1, Overall risk profile and complexity #art_1
Article 2, General elements of ICT security policies, procedures, protocols, and tools #art_2
Article 3, ICT risk management #art_3
Article 4, ICT asset management policy #art_4
Article 5, ICT asset management procedure #art_5
Article 6, Encryption and cryptographic controls #art_6
Article 7, Cryptographic key management #art_7
Article 8, Policies and procedures for ICT operations #art_8
Article 9, Capacity and performance management #art_9
Article 10, Vulnerability and patch management #art_10
Article 11, Data and system security #art_11
Article 12, Logging #art_12
Article 13, Network security management #art_13
Article 14, Securing information in transit #art_14
Article 15, ICT project management #art_15
Article 16, ICT systems acquisition, development, and maintenance #art_16
Article 17, ICT change management #art_17
Article 18, Physical and environmental security #art_18
Article 19, Human resources policy #art_19
Article 20, Identity management #art_20
Article 21, Access control #art_21
Article 22, ICT-related incident management policy #art_22
Article 23, Anomalous activities detection and criteria for ICT-related incidents detection and response #art_23
Article 24, Components of the ICT business continuity policy #art_24
Article 25, Testing of the ICT business continuity plans #art_25
Article 26, ICT response and recovery plans #art_26
Article 27, Format and content of the report on the review of the ICT risk management framework #art_27
Article 28, Governance and organisation #art_28
Article 29, Information security policy and measures #art_29
Article 30, Classification of information assets and ICT assets #art_30
Article 31, ICT risk management #art_31
Article 32, Physical and environmental security #art_32
Article 33, Access Control #art_33
Article 34, ICT operations security #art_34
Article 35, Data, system and network security #art_35
Article 36, ICT security testing #art_36
Article 37, ICT systems acquisition, development, and maintenance #art_37
Article 38, ICT project and change management #art_38
Article 39, Components of the ICT business continuity plan #art_39
Article 40, Testing of business continuity plans #art_40
Article 41, Format and content of the report on the review of the simplified ICT risk management framework #art_41
Article 42, Entry into force #art_42
Provenance and validity dates, identifier, hash
as of2024-06-25 → this version applied
valid2024-06-25 → open publisher-asserted
typeREG_DEL Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework (Text with EEA relevance)
languageen
published2024-06-25
lex_ideu-eurlex:32024r1774:2024-06-25
record sha256da847b713bc33bddca407a4c7d6fd3679a22012c6c6f486a890b2f3ef2c6ea39
New here? What am I looking at?

This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.

It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.

“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.

← previous version (2024-03-13)   what changed?   timeline   next version (2024-06-25) →

tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)