acquis · Law · eIDAS 2

eIDAS 2 · CELEX 32024R1183

Article 19

Verbatim text of the current consolidated version (consolidated 2024-10-18) · status: in force. Check it on EUR-Lex ↗

eIDAS 2, Article 19(1) — Security requirements applicable to trust service providers
Qualified and non-qualified trust service providers shall take appropriate technical and organisational measures to manage the risks posed to the security of the trust services they provide. Having regard to the latest technological developments, those measures shall ensure that the level of security is commensurate to the degree of risk. In particular, measures shall be taken to prevent and minimise the impact of security incidents and inform stakeholders of the adverse effects of any such incidents.
eIDAS 2, Article 19(2) — Security requirements applicable to trust service providers
Qualified and non-qualified trust service providers shall, without undue delay but in any event within 24 hours after having become aware of it, notify the supervisory body and, where applicable, other relevant bodies, such as the competent national body for information security or the data protection authority, of any breach of security or loss of integrity that has a significant impact on the trust service provided or on the personal data maintained therein. Where the breach of security or loss of integrity is likely to adversely affect a natural or legal person to whom the trusted service has been provided, the trust service provider shall also notify the natural or legal person of the breach of security or loss of integrity without undue delay. Where appropriate, in particular if a breach of security or loss of integrity concerns two or more Member States, the notified supervisory body shall inform the supervisory bodies in other Member States concerned and ENISA. The notified supervisory body shall inform the public or require the trust service provider to do so, where it determines that disclosure of the breach of security or loss of integrity is in the public interest.
eIDAS 2, Article 19(3) — Security requirements applicable to trust service providers
The supervisory body shall provide ENISA once a year with a summary of notifications of breach of security and loss of integrity received from trust service providers.
eIDAS 2, Article 19(4) — Security requirements applicable to trust service providers
The Commission may, by means of implementing acts,: (a) further specify the measures referred to in paragraph 1; and (b) define the formats and procedures, including deadlines, applicable for the purpose of paragraph 2. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 48(2).
This text is not written by an AI. It is rendered from a corpus built from the official EUR-Lex source, where every fragment is content-hashed and signed at ingestion — which is what lets you cite it and defend the citation. Ask a question about this article →

Other articles of the eIDAS 2

← Article 18 · Article 19a

Acquis returns official sources verbatim with citations; it is not legal advice. Texts © European Union, reuse permitted (Decision 2011/833/EU) — only the EUR-Lex original is authentic. Why legal AI fails · Coverage

eIDAS 2, Article 19 — full text, verified