Regulation (EU) 2022/2554, in application since 17 January 2025, establishing a harmonised ICT risk management framework for over 22,000 financial entities and their critical ICT third-party providers across the EU. Article 11’s Business continuity obligation, covered under B, is one strand of a wider framework that also covers incident reporting, resilience testing and direct EU-level oversight of critical ICT providers such as major cloud vendors.