SkarpSkarp
Commission Implementing Regulation (EU) 2024/2690: Cybersecurity Measures and Significant-Incident Thresholds
⚖️ LegalAdvanced2h5 modules

Commission Implementing Regulation (EU) 2024/2690: Cybersecurity Measures and Significant-Incident Thresholds

Deep DiveCertificateNew

This advanced course walks section by section through Commission Implementing Regulation (EU) 2024/2690, from its recitals and operative incident thresholds to the detailed controls in its Annex. Learners will be able to interpret the Regulation’s proportional, risk-based requirements, determine when incidents are significant for covered entities, and map its governance, technical, personnel and physical-security obligations to organizational practices.

Listen free

The first lecture plays free — no account needed.

by Skarp_officialen

What you'll learn

  • Students will be able to identify the purpose, issuing authority, legal context and overall structure of Commission Implementing Regulation (EU) 2024/2690.
  • Students will be able to distinguish the categories of entities covered by the Regulation and relate them to the implementation of Directive (EU) 2022/2555.
  • Students will be able to interpret proportionality, international standards and documented compensating measures as foundations for applying the requirements.
  • Students will be able to trace the recitals’ rationale across governance, risk treatment, monitoring, continuity, supply-chain controls, secure acquisition and patching.
  • Students will be able to relate access control, personnel security, asset management and physical resilience to the Regulation’s all-hazards approach.
  • Students will be able to interpret how awareness, duration, affected users, financial loss, health damage and service availability contribute to significance determinations.
  • Students will be able to apply the horizontal criteria in Articles 3 and 4, including affected-user counting and the aggregation of recurring incidents.
  • Students will be able to distinguish complete unavailability, limited availability, degraded response and data compromise across different provider categories.
  • Students will be able to compare the thresholds for DNS, TLD, cloud, data centre, content delivery and managed service providers.
  • Students will be able to assess significance criteria for online marketplaces, search engines, social networking platforms and trust service providers.

Prerequisites

  • Basic familiarity with cybersecurity risk management
  • General awareness of Directive (EU) 2022/2555
  • Covered entity categories
  • Proportional and risk-based implementation
  • Regulatory role of recitals and operative articles
  • Cybersecurity policy hierarchy

Course Content

5 modules · 2h total

1

Regulatory Foundations and the Cybersecurity Control Rationale

Why does this directly applicable EU Regulation combine legal thresholds with a detailed security-control framework? The opening chapter situates Commission Implementing Regulation (EU) 2024/2690, identifies its covered entities and follows the recitals from proportionality and standards through governance, technical safeguards, personnel and physical resilience.

27 min
2

From Legal Interpretation to Significant-Incident Decisions

When does disruption, compromise or unauthorized access cross the legal line into a significant incident? This chapter connects the final interpretive recitals to Articles 1–16 and applies both horizontal and service-specific thresholds across the full range of covered providers.

24 min
3

The Annex in Action: Governance, Incidents, Continuity and Suppliers

The Annex turns the Regulation’s policy rationale into auditable organizational duties. This chapter follows the control system from management-approved security policies and risk treatment through incident response, crisis management, tested recovery and continuous oversight of direct suppliers.

26 min
4

Securing the ICT Lifecycle, Networks and Workforce

Security must persist from acquisition and development to configuration, change, testing, patching and eventual vulnerability disclosure. This chapter examines that lifecycle alongside network architecture, segmentation, malware defense, control-effectiveness measurement, cyber hygiene, cryptography and human-resources security.

22 min
5

Controlling Access, Assets and the Physical Operating Environment

The Regulation closes the control chain by asking who can reach systems, what assets must be protected and whether facilities can withstand disruption. This final chapter consolidates the document through identity and privileged-access safeguards, traceable asset lifecycles, utility resilience, security perimeters and continuous physical monitoring.

21 min

Read the Textbook

Read every chapter for free, right here in your browser.

Start with the regulatory problem

Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 translates parts of Directive (EU) 2022/2555, the NIS 2 Directive, into detailed technical and methodological requirements. Its opening recitals explain why cybersecurity oversight needs both legal thresholds and a control framework: the Regulation identifies the entities concerned, describes the intended level of technical specificity, and connects cybersecurity controls to recognised standards.

Who is covered?

Study Flashcards

Key concepts from this course as flashcard pairs.

Regulatory Foundations and the Cybersecurity Control Rationale

Relevant entities

The covered DNS, TLD registry, cloud, data-centre, CDN, managed-service, managed-security-service, online platform, search-engine, social-networking-platform, and trust-service entities identified in Recital (1).

Proportionality

Recital (4) says account should be taken of criticality, risk exposure, size and structure, and incident likelihood, severity, and societal and economic impact.

Compensating measures

Where requirements cannot be implemented due to size, Recital (5) says entities should be able to use suitable alternatives that achieve the purpose of the requirements.

Risk treatment plan

A plan that entities should establish, implement, and monitor as part of their risk management framework; it may identify and prioritise treatment options and measures.

Asset inventory

A record of tangible and intangible assets that supports classification, tracking, lifecycle protection, risk analysis, and business continuity.

All-hazards approach

An approach protecting network and information systems and their physical environment from cyber, physical, environmental, utility, human, and natural threats.

From Legal Interpretation to Significant-Incident Decisions

When is a relevant entity 'aware' of a significant incident according to recital (31)?

When, after the initial assessment, it has a reasonable degree of certainty that a significant incident has occurred.

What is Article 3(1)(a)'s financial-loss threshold?

Direct financial loss that exceeds EUR 500,000 or 5% of total annual turnover in the preceding financial year, whichever is lower.

What three conditions must Article 4 recurring incidents meet?

They occurred at least twice within 6 months; they have the same apparent root cause; and they collectively meet Article 3(1)(a).

What is the Article 5 complete-unavailability threshold for DNS resolution?

A recursive or authoritative domain name resolution service is completely unavailable for more than 30 minutes.

What is the Article 7 cloud limited-availability test?

More than 5% of Union users or more than 1 million Union users, whichever number is smaller, for more than one hour.

What physical-security event independently qualifies under Article 8?

Physical access to a data centre operated by the provider is compromised.

+2 more flashcards

The Annex in Action: Governance, Incidents, Continuity and Suppliers

Policy review frequency

The policy is reviewed and, where appropriate, updated by management bodies at least annually and when significant incidents or significant changes to operations or risks occur. The result is documented.

Residual risk

Risk assessment results and residual risks are accepted by management bodies or, where applicable, authorised accountable persons, provided adequate reporting to management bodies is ensured.

Monitoring automation

To the extent feasible, monitoring is automated and continuous or periodic, subject to business capabilities, while minimising false positives and false negatives.

Incident response stages

Containment to stop spread; eradication to stop continuation or recurrence; and recovery where necessary.

Business impact analysis

It assesses the potential impact of severe disruptions to business operations and supports continuity requirements for network and information systems.

Supplier registry

A current registry of direct suppliers and service providers, including contact points and the ICT products, ICT services, and ICT processes each provides.

Securing the ICT Lifecycle, Networks and Workforce

Acquisition lifecycle

For critical components, entities shall set and implement processes to manage acquisition risks from suppliers or service providers throughout the ICT service or product life cycle, based on point 2.1 risk assessment.

Patch exception

An entity may choose not to apply a patch only when its disadvantages outweigh cybersecurity benefits. It shall duly document and substantiate the reasons.

Segmentation rule

Systems shall be segmented into networks or zones according to the point 2.1 risk assessment, and the entity's systems and networks shall be segmented from third parties' systems and networks.

Awareness audience

Employees, including management bodies, and direct suppliers and service providers must be aware of risks, informed of cybersecurity importance and apply cyber-hygiene practices.

Cryptographic agility

Protocols, algorithms, cipher strength, solutions and usage practices are approved and required following, where appropriate, a cryptographic agility approach.

Annual personnel review

Assignments of personnel to the roles in point 1.2, and their human-resource commitment, shall be reviewed at planned intervals and at least annually, then updated where necessary.

Controlling Access, Assets and the Physical Operating Environment

Need-to-know

An access-right principle required by point 11.2.2(a). Rights are assigned and revoked based on the information or system access needed for the relevant role or task.

Least privilege

An access-right principle required by point 11.2.2(a). Access should not exceed what is needed for the authorised purpose.

Separation of duties

An access-right principle required by point 11.2.2(a). Duties and access should be arranged so that incompatible actions are not concentrated without appropriate separation.

Shared identity

An identity assigned to multiple persons. Point 11.5.3 permits it only where necessary for business or operational reasons and subject to explicit approval and documentation.

System administration account

A specific account used exclusively for system administration operations. It must only be used to connect to system administration systems.

Continuous authentication mechanism

An alternative to multiple authentication factors in point 11.7.1, where appropriate and in accordance with the classification of the asset to be accessed.

More in Legal

See all →