Commission Implementing Regulation (EU) 2025/2160 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014
as it stood on 2025-10-27, permalink: /eu-eurlex/32025r2160/2025-10-27--3972d66a4d04e1510c4fd99934c0d3077f8b62138810a858beab61a677c5cc8a
Article 1
The reference standards referred to in Article 19a(2) of Regulation (EU) No 910/2014 are set out in the Annex to this Regulation.
Article 2
The risk management policies referred to in Article 19a(1) of Regulation (EU) No 910/2014 shall clearly identify the trust services they apply to, shall be specific to the trust services concerned and shall be approved by the management body of the non-qualified trust service provider.
The risk management policies shall include at least all the following elements:
| (a) | the overall risk tolerance level in accordance with the criticality and required level of security of the trust services, having regard to the latest technological developments; |
|---|
| (b) | the relevant risk criteria, including at least the likelihood, impact and level of the risk, taking into account cyber threat intelligence and vulnerabilities; |
|---|
| (c) | an approach for the identification and documentation of the risks to the provision of the trust services, taking into account the complete scope of the information system used by the non-qualified trust service provider, including risks associated with the components of the system as well as with any active or passive parties involved in the implementation of the system or in the provision of the trust services; |
|---|
| (d) | a process for the evaluation of the identified risks based on the risk criteria referred to in point (b); |
|---|
| (e) | a process for the identification, prioritisation and continuous monitoring of the implementation of appropriate risk treatment measures; |
|---|
| (f) | a process for continuous monitoring of the implementation of the risk management policies. |
|---|
Non-qualified trust service providers shall establish appropriate procedures and maintain documents to ensure that the requirements set out in the applicable legislation are implemented.
Non-qualified trust service providers shall establish appropriate documented procedures ensuring the monitoring of Union and national legislative and regulatory changes that may impact the provision of trust services.
Article 3
Non-qualified trust service providers shall identify, document and evaluate all risks referred to in Article 19a(1) of Regulation (EU) No 910/2014 in accordance with the risk management policies referred to in Article 2, and shall in particular:
| (a) | identify risks in relation to third parties; |
|---|
| (b) | identify potential single point of failure in the provision of the trust services; |
|---|
| (c) | evaluate the identified risks based on the risk criteria referred to in Article 2(2), point (b). |
|---|
Article 4
- In accordance with the policies referred to in Article 2, non-qualified trust service providers shall plan, document and implement risk treatment measures, and shall, in particular, carry out the following tasks:
| (a) | identify and prioritise appropriate risk treatment measures; |
|---|
| (b) | select, approve and document the chosen risk treatment measures, including their security requirements and operational procedures, in a risk treatment plan, identify who is responsible for implementing the risk treatment measures and when they are to be implemented; |
|---|
| (c) | continuously monitor the implementation of the risk treatment measures. |
|---|
The risk treatment plan set out in paragraph 1, point (b), shall provide reasons justifying the acceptance of residual risks in a comprehensible manner.
As part of the risk treatment measures referred to in paragraph 1, non-qualified trust service providers shall also:
| (a) | verify, where applicable, the identity of the users of the trust service directly or by means of a third party and publish information on the identity verification methods used; |
|---|
| (b) | for the purposes of providing evidence in legal proceedings and of ensuring service continuity, record and securely retain for as long as necessary in accordance with Union or national laws, including after the activities of the non-qualified trust service provider have ceased, the following information:—all relevant information collected in the process of registration and onboarding of the trust service users, including, where applicable, the identity verification of the users,—authentication data assigned to the user of the trust service, where applicable, and—any change of the status of public key certificates or other cryptographic material used in the provision of the trust service. |
|---|---|
| — | all relevant information collected in the process of registration and onboarding of the trust service users, including, where applicable, the identity verification of the users, |
| — | authentication data assigned to the user of the trust service, where applicable, and |
| — | any change of the status of public key certificates or other cryptographic material used in the provision of the trust service. |
| (c) | ensure, where applicable, that authentication data assigned to the user of the trust service are unique. |
|---|
- When identifying, selecting, approving and prioritising appropriate risk treatment measures, non-qualified trust service providers shall take into account the following elements:
| (a) | the results of the risk evaluation referred to in Article 3; |
|---|
| (b) | the effectiveness of the risk treatment measures; |
|---|
| (c) | conformity assessments; |
|---|
| (d) | significant incidents; |
|---|
| (e) | the cost of implementation in relation to the expected benefit; |
|---|
| (f) | the applicable appropriate asset classification; |
|---|
| (g) | the analysis of any business impact of the risks identified in accordance with Article 3. |
|---|
The management bodies of non-qualified trust service providers shall approve the residual risks remaining after the implementation of the risk treatment measures as set out in the risk treatment plan.
Non-qualified trust service providers shall review, document and, where appropriate, update the risk evaluation results and the risk treatment plan at planned intervals, and at least annually, and when significant changes to the infrastructure, operations or risks, or significant incidents, occur.
Non-qualified trust service providers shall ensure the availability, integrity and confidentiality of the information referred to in paragraph 3, point (b).
Article 5
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2025-10-27 → this publisher state was selected |
| publisher state | publisher version 2025-10-27 → latest held publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2025/2160 of 27 October 2025 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards reference standards, specifications and procedures for the management of risks to the provision of non-qualified trust services |
| language | en |
| published | 2025-10-27 |
| lex_id | eu-eurlex:32025r2160:2025-10-27--3972d66a4d04e1510c4fd99934c0d3077f8b62138810a858beab61a677c5cc8a |
| record sha256 | c78beb1fc0b73ba7a153f1da97f90109243cd95543d1321c03596be96bbc66b3 |
New here? What am I looking at?
This is an official consolidated text: the original act with later amendments merged by EUR-Lex for the date shown above.
The consolidation date is not an entry-into-force or application date. It identifies a publisher wording state. The authentic legal acts remain those published in the Official Journal; Lex preserves the consolidated wording, source and hashes as a reading and comparison aid.
Each displayed provision carries its own hash so you can verify that Lex served the indexed text unchanged, here is how.
| tier | A, publisher-supplied consolidated wording-state dates |
| history begins | publisher |
| index built | 2026-08-15T09:01:06Z · corpus e9c4df0981c855855a1a28218cf086ddeb5bb691 |
| stamp signature | valid (ECDSA-P256) |