The European Securities and Markets Authority (ESMA), the EU’s financial markets regulator and supervisor, is changing its Union Strategic Supervisory Priorities (USSPs) to focus on cyber risk and digital resilience alongside ESG disclosures.
With this new priority, EU supervisors will put greater emphasis on reinforcing firms’ ICT risk management through close monitoring and supervisory actions, building new supervisory capacity and expertise.
ESMA says that the aim is to keep pace with market and technological developments, and closely monitor potential contagion effects of attacks and disruptions across markets and firms.
The new USSP will come into force in 2025, at the same time as the Digital Operational Resilience Act (DORA). This timeline is intended to provide supervisors and firms in Member States with sufficient time to prepare for compliance with the new regulatory requirements. Meanwhile, ESMA and national competent authorities (NCAs) will carry out preparatory work planning and shaping the supervisory activities to undertake under this priority.
The new USSP on cyber risk and digital resilience will replace the USSP on market data quality.






