MiFID II / MiFIR
Scope and Authority - MiFID II / MiFIR

MiFID II / MiFIR MiFID-II-Scope-Directive-2014-65-MiFIR-Regulation-600-2014-Effective-3-January-2018-ESMA-NCAs-Authorisation: MiFID II + MiFIR Scope + Directive 2014/65 + Regulation 600/2014 + 3 January 2018 + ESMA + NCAs + Authorisation

Establish the legal foundation of EU MiFID II (Directive 2014/65/EU) and MiFIR (Regulation 600/2014) adopted 15 May 2014 + published OJ 12 June 2014 + effective 3 January 2018 (delayed from 3 January 2017 by Directive 2016/1034 + Regulation 2016/1033). Replaced MiFID I 2007 (Directive 2004/39/EC). Foundational EU framework for investment services + trading venues + transparency + investor protection. Implementing measures include Commission Delegated Regulation (EU) 2017/565 (organisational requirements) + 2017/567 (MiFIR supplements) + Commission Delegated Directive (EU) 2017/593 (client funds + product governance + inducements) + 30+ ESMA RTS/ITS. Scope: investment firms (Article 4(1)(1)) + market operators + data reporting service providers + third-country firms. Authorisation Articles 5-10 + passporting Article 34 enabling cross-border services across EEA. ESMA (European Securities and Markets Authority) coordination + 27 EU National Competent Authorities (NCAs) including BaFin + AMF + Consob + CNMV + AFM. MIFID II REVIEW 2024-2025: Listing Act 2024 + RTS 27 best execution reports abolished + consolidated tape revival + research unbundling reversed for SMEs + payment for order flow ban + retail investor strategy + FIDA Regulation 2024 financial data access.

What else in your programme already covers this

This control maps to 32 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-3 Broken Object Property Level Authorization (BOPLA)

OWASP Top 10:2025 · 2 controls

FDA 21 CFR Part 11 · 1 control

  • Part11.AccessAndAuth Access control + authority + device checks (21 CFR §11.10(d) + (f) + (g) + (h))

FISMA · 1 control

FedRAMP Rev 5 · 1 control

HITECH Act · 1 control

  • 62351-8 Role-based access control (RBAC)

ISMAP (Japan) · 1 control

ISO/IEC 27011:2024 · 1 control

ISO/IEC 27400:2022 · 1 control

MARS-E · 1 control

  • 3.7.1 Key-management policies and procedures are implemented to include generation of strong cryptographic keys used to protect stored account data

OWASP ASVS · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 32 it maps to, and the evidence behind each claim, over MCP and REST.