← Back to Guidance Portal

Legal Compliance Registry

A detailed breakdown of legislative mandates transposed for the European Telecom Sector.

Article 21: Cybersecurity Risk-Management Measures

Legal Mandate
21(2)(a)

Policies on risk analysis and information system security

Entities must maintain written policies covering how they identify and manage risks to their specific assets.

Practical Impl: Implementation of ISO 27001 or equivalent risk assessment frameworks.
21(2)(c)

Business continuity & crisis management

Backup management, disaster recovery, and crisis management plans must be established and tested.

Practical Impl: Redundant core network elements and periodic failover drills.
21(2)(e)

Supply chain security

Entities must assess the security of their suppliers and ensure contractual compliance.

Practical Impl: Security audits for vendors of 5G RAN and signaling equipment.

Article 23: Reporting Obligations

Operational mandate
23(4)(a)

Early Warning (24h)

Notification without undue delay of any significant incident or threat.

Practical Impl: Automated triggers from SIEM/SOC to compliance dashboard.
23(4)(b)

Incident Notification (72h)

Update with severity impact and indicators of compromise.

Practical Impl: Standardized TEMPLATE-23-B for CSIRT submission.