Recital 28
NIS2 Recital 28
Regulation (EU) 2022/2554 of the European Parliament and of the Council (10) should be considered to be a sector-specific Union legal act in relation to this Directive with regard to financial entities. The provisions of Regulation (EU) 2022/2554 relating to information and communication technology (ICT) risk management, management of ICT-related incidents and, in particular, major ICT-related inc
269 words in the official text.
Across the acts
- This provision citesDORA
Regulation (EU) 2022/2554 of the European Parliament and of the Council (10) should be considered to be a sector-specific Union legal act in relation to this Directive with regard to financial entities.
See it on the crossover map - This provision citesDORA
The provisions of Regulation (EU) 2022/2554 relating to information and communication technology (ICT) risk management, management of ICT-related incidents and, in particular, major ICT-related incident reporting, as well as on digital operational resilience testing, information-sharing arrangements and ICT third-party risk should apply instead of those provided for in this Directive.
See it on the crossover map - This provision citesDORA
Member States should therefore not apply the provisions of this Directive on cybersecurity risk-management and reporting obligations, and supervision and enforcement, to financial entities covered by Regulation (EU) 2022/2554.
See it on the crossover map - This provision citesDORA
To that end, Regulation (EU) 2022/2554 allows the European Supervisory Authorities (ESAs) and the competent authorities under that Regulation to participate in the activities of the Cooperation Group and to exchange information and cooperate with the single points of contact, as well as with the CSIRTs and the competent authorities under this Directive.
See it on the crossover map - This provision citesDORA
The competent authorities under Regulation (EU) 2022/2554 should also transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, the competent authorities or the single points of contact under this Directive.
See it on the crossover map
Recitals matched by wording (1)
These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Directive (EU) 2022/2555. Study aid, not legal advice.
See how NIS2 sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.