Lex Browse everything
For developers

Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554

as it stood on 2024-06-25, permalink: /eu-eurlex/32024r1774/2024-06-25--7976c10f47484571b4f5427be672c24c35bf30ff004eb69564dbb0fa9534d85d

2024-03-132024-06-25
Browse 2 dated versions

2 versions · choose a date to read the law as it stood that day · the one you are reading

Official publisher wording state selected for 2024-06-25. This is the consolidated version dated 2024-06-25. Its interval on Lex's publisher-version axis is publisher version 2024-06-25 → latest held; that is not a claim about entry into force or application.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each displayed provision carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 42 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38 Article 39 Article 40 Article 41 Article 42

Article 1, Overall risk profile and complexity #art_1
Article 2, General elements of ICT security policies, procedures, protocols, and tools #art_2
Article 3, ICT risk management #art_3
Article 4, ICT asset management policy #art_4
Article 5, ICT asset management procedure #art_5
Article 6, Encryption and cryptographic controls #art_6
Article 7, Cryptographic key management #art_7
Article 8, Policies and procedures for ICT operations #art_8
Article 9, Capacity and performance management #art_9
Article 10, Vulnerability and patch management #art_10
Article 11, Data and system security #art_11
Article 12, Logging #art_12
Article 13, Network security management #art_13
Article 14, Securing information in transit #art_14
Article 15, ICT project management #art_15
Article 16, ICT systems acquisition, development, and maintenance #art_16
Article 17, ICT change management #art_17
Article 18, Physical and environmental security #art_18
Article 19, Human resources policy #art_19
Article 20, Identity management #art_20
Article 21, Access control #art_21
Article 22, ICT-related incident management policy #art_22
Article 23, Anomalous activities detection and criteria for ICT-related incidents detection and response #art_23
Article 24, Components of the ICT business continuity policy #art_24
Article 25, Testing of the ICT business continuity plans #art_25
Article 26, ICT response and recovery plans #art_26
Article 27, Format and content of the report on the review of the ICT risk management framework #art_27
Article 28, Governance and organisation #art_28
Article 29, Information security policy and measures #art_29
Article 30, Classification of information assets and ICT assets #art_30
Article 31, ICT risk management #art_31
Article 32, Physical and environmental security #art_32
Article 33, Access Control #art_33
Article 34, ICT operations security #art_34
Article 35, Data, system and network security #art_35
Article 36, ICT security testing #art_36
Article 37, ICT systems acquisition, development, and maintenance #art_37
Article 38, ICT project and change management #art_38
Article 39, Components of the ICT business continuity plan #art_39
Article 40, Testing of business continuity plans #art_40
Article 41, Format and content of the report on the review of the simplified ICT risk management framework #art_41
Article 42, Entry into force #art_42
Provenance and validity dates, identifier, hash
as of2024-06-25 → this publisher state was selected
publisher statepublisher version 2024-06-25 → latest held publisher-asserted
typeREG_DEL Commission Delegated Regulation (EU) 2024/1774 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework (Text with EEA relevance)
languageen
published2024-06-25
lex_ideu-eurlex:32024r1774:2024-06-25--7976c10f47484571b4f5427be672c24c35bf30ff004eb69564dbb0fa9534d85d
record sha25616ee9cf09b11370cdfe066e23bf42539d9711ed062facb503c071478b7fa3e8c
New here? What am I looking at?

This is an official consolidated text: the original act with later amendments merged by EUR-Lex for the date shown above.

The consolidation date is not an entry-into-force or application date. It identifies a publisher wording state. The authentic legal acts remain those published in the Official Journal; Lex preserves the consolidated wording, source and hashes as a reading and comparison aid.

Each displayed provision carries its own hash so you can verify that Lex served the indexed text unchanged, here is how.

← previous version (2024-03-13)   what changed?   timeline

tierA, publisher-supplied consolidated wording-state dates
history beginspublisher
index built2026-08-15T09:01:06Z · corpus e9c4df0981c855855a1a28218cf086ddeb5bb691
stamp signaturevalid (ECDSA-P256)