Data & Privacy
AI & Trust
Cybersecurity
Digital Services & Media
CHAPTER I
General provisionsArticles 1 — 4
CHAPTER II
ICT risk managementArticles 5 — 16
CHAPTER III
ICT-related incident management, classification and reportingArticles 17 — 23
CHAPTER IV
Digital operational resilience testingArticles 24 — 27
CHAPTER V
Managing of ICT third-party riskArticles 28 — 44
CHAPTER VI
Information-sharing arrangementsArticles 45 — 45
CHAPTER VII
Competent authoritiesArticles 46 — 56
CHAPTER VIII
Delegated actsArticles 57 — 57
CHAPTER IX
Transitional and final provisionsArticles 58 — 64
ARTICLE 28
General principles
ARTICLE 29
Preliminary assessment of ICT concentration risk at entity level
ARTICLE 30
Key contractual provisions
ARTICLE 31
Designation of critical ICT third-party service providers
ARTICLE 32
Structure of the Oversight Framework
ARTICLE 33
Tasks of the Lead Overseer
ARTICLE 34
Operational coordination between Lead Overseers
ARTICLE 35
Powers of the Lead Overseer
ARTICLE 36
Exercise of the powers of the Lead Overseer outside the Union
ARTICLE 37
Request for information
ARTICLE 38
General investigations
ARTICLE 39
Inspections
ARTICLE 40
Ongoing oversight
ARTICLE 41
Harmonisation of conditions enabling the conduct of the oversight activities
ARTICLE 42
Follow-up by competent authorities
ARTICLE 43
Oversight fees
ARTICLE 44
International cooperation