The final standards set out oversight expectations for critical ICT third-party providers and introduce requirements for due diligence, ongoing monitoring, sub-outsourcing transparency and exit strategies.
Why it matters
Firms may need to strengthen supplier classification, contract evidence, monitoring and contingency planning.
RelevanceHighImpactHighUrgencyMedium
Key dates
Entry into force17 Jan 2027
Application17 Jul 2027
Review date17 Jul 2028
How priority is determined
Priority combines the selected lens, visible workspace context, event attributes and the nearest relevant regulatory milestone.