Criticality of services affected


For the purpose of determining the criticality of the services affected as referred to in Article 18(1), point (e), of Regulation (EU) 2022/2554, financial entitiesas defined in Article 2, points (a) to (t) shall assess whether the incident:

  1. affects or has affected ICT servicesmeans digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services; or network and information systemsmeans a network and information system as defined in Article 6, point 1, of Directive (EU) 2022/2555; that support critical or important functionsmeans a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law; of the financial entity;

  2. affects or has affected financial services provided by the financial entity that require authorisation, registration or that are supervised by competent authoritiesas defined in Article 46;

  3. constitutes or has constituted a successful, malicious and unauthorised access to the network and information systemsmeans a network and information system as defined in Article 6, point 1, of Directive (EU) 2022/2555; of the financial entity.