EIOPA finalises Guidelines on Information and Communication Technology Security and Governance

Published By Europa [English], Mon, Oct 12, 2020 2:35 AM


Today, the European Insurance and Occupational Pensions Authority (EIOPA) finalised the Guidelines on Information and Communication Technology (ICT) Security and Governance.

These guidelines shall provide guidance to national supervisory authorities and market participants on how regulation regarding operational risks set forth in Directive 2009/138/EC and in the Commission's Delegated Regulation 2015/35 is applied in the case of ICT security and governance, considering as well EIOPA's Guidelines on System of Governance.

The objective of the guidelines is to promote the increase of the operational resilience of the digital operations of insurance and reinsurance undertakings against the risks they face. Operational resilience is key to protect insurance and reinsurance undertakings’ digital assets, including their systems and data from policyholders and beneficiaries. In particular, the guidelines:

EIOPA consulted on the guidelines between December 2019 and March 2020 and took into account the views of stakeholders wherever possible.

National supervisory authorities are expected to apply these guidelines from 1 July 2021.

Go to the Guidelines and the resolution of comments

Press release distributed by Media Pigeon on behalf of Europa, on Oct 12, 2020. For more information subscribe and follow


Eric Mamer

Chief Spokesperson
[email protected]
+32 2 299 40 73

Dana Spinant

Deputy Chief Spokesperson
[email protected]
+32 2 299 01 50

Elisaveta Dimitrova

Head of Unit
[email protected]
+32 2 295 88 38

Johannes Bahrke

Coordinating Spokesperson
[email protected]
+32 2 295 86 15

Vivian Loonela

Coordinating Spokesperson
[email protected]
+32 2 296 67 12