If my organisation receives a derogation, does this mean that it is exempted from compliance with Part-IS?
If my organisation receives a derogation, does this mean that it is exempted from compliance with Part-IS?
Answer
A derogation is a temporary exemption from the full requirements of the Regulation. The organisation is advised to remain vigilant and, as a minimum, reassess its exposure to cybersecurity threats whenever the scope changes. In particular, the continued validity of that approval will be reviewed by the competent authority following the applicable oversight audit cycle and whenever changes are implemented in the scope of work of the organisation.
There are a few requirements that still apply or partially apply to a derogated organisation. More information on this and the derogation process.
Last updated
22/08/2025