ATCO.AR.E.010A Changes to the
information security management system
Regulation (EU) 2023/203
(a) With regard to changes managed and notified to the competent
authority in accordance with the procedure set out in point IS.I.OR.255(a) of
Annex II (Part-IS.I.OR) to Implementing Regulation (EU) 2023/203, the competent authority shall include the review of
such changes in its continuing oversight in accordance with the principles
laid down in point ATCO.AR.C.001. If any non-compliance is found, the
competent authority shall notify the organisation thereof, request further
changes and act in accordance with point ATCO.AR.C.010.
(b) With regard to other changes requiring an application for
approval in accordance with point IS.I.OR.255(b) of Annex II (Part-IS.I.OR) to
Implementing Regulation (EU) 2023/203:
(1) upon receiving the application for the change, the competent
authority shall check the organisation’s compliance with the applicable
requirements before issuing the approval;
(2) the competent authority shall establish the conditions under
which the organisation may operate during the implementation of the change;
(3) if it is satisfied that the organisation complies with the
applicable requirements, the competent authority shall approve the change.
[Applicable from 22
February 2026 – Regulation (EU) 2023/203]
Loading collections...