EU Payment Services Directive (PSD2)
PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

EU Payment Services Directive (PSD2) PSD2-Art.96: Incident reporting to competent authority (PSD2 Article 96)

Article 96 requires PSPs to notify, without undue delay, the home Member State competent authority of any major operational or security incident. Where the incident has or may have an impact on the financial interests of its PSUs, the PSP shall, without undue delay, inform its PSUs of the incident and of all measures that they can take to mitigate the adverse effects of the incident. The home competent authority shall, without undue delay, provide the EBA + the ECB with the relevant details of the incident; after assessment of the relevance of the incident to other relevant authorities in the Member State, the home competent authority shall notify them accordingly. The EBA + the ECB shall assess in cooperation with the home authority the relevance of the incident to other relevant Union authorities and shall notify them accordingly. EBA Guidelines EBA/GL/2017/10 (revised by EBA/GL/2021/03) operationalise Article 96, including initial / intermediate / final report templates + classification criteria.

Maintained by Gerard BlokdykVerified against the published standard

What else in your programme already covers this

This control maps to 4 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

DORA · 3 controls

  • DORA-Art.17 ICT-related incident management process
  • DORA-Art.18 Classification of ICT-related incidents and cyber threats
  • DORA-Art.19 Reporting of major ICT-related incidents

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.