Back to playbooks
    Playbook

    The first 90 days as a security leader

    A ninety-day method: inventory the mandate, the obligations and the risk picture, decide appetite and operating model, then take one decision to the board.

    Governance5 Sept 202622 min read

    Directive (EU) 2022/2555ISO 31000:2018ISO/IEC 27001:2022ISO/IEC 27002:2022NIST CSWP 29Regulation (EU) 2022/2554
    On this page

    Scope: arrival to the first governed decision · Who: whoever now owns security · Prerequisites: a named sponsor and access to the calendar · First result: ninety days

    1. Why this exists (the failure mode it prevents)

    Ninety days is not enough to fix a security programme. It is enough to establish what the organisation is trying to do, what it is obliged to do, and what it carries. Most of the damage comes from spending the quarter elsewhere.

    Three openings recur, and each answers before listening. The tool purchase buys a capability the risk picture never asked for, and spends the credibility a first budget request carries. The reorganisation moves reporting lines before anyone has written down which decisions those lines exist to carry. The framework programme starts a certification effort against a standard nobody has shown to be in scope.

    A fourth is quieter. The quarter goes into a maturity assessment nobody asked for, producing a heat map, a score and no decision. The board then receives a paper listing activities: workshops held, policies drafted, scans run. Activity is not a position, and a governing body cannot act on one.

    How it surfaces

    An assessment finds the gap in artefacts rather than in intent. Clause 4.1 is Understanding the organization and its context, clause 4.2 Understanding the needs and expectations of interested parties 1 2. Where neither is answerable, the scope at clause 4.3 rests on nothing 3.

    The obligations inventory is the second absence. Control 5.31 of ISO/IEC 27002:2022 asks that legal, statutory, regulatory and contractual requirements relevant to information security are identified, documented and kept up to date 4. The approach to meeting them is documented alongside them. Where no such list exists, an audit date is discovered in week eleven rather than week two.

    The third is a management review that produces observations instead of decisions. Clause 9.3 is Management review, with 9.3.2 inputs and 9.3.3 results 5. A quarter that never puts a decision in front of that body has not started the loop.

    One loop, not three silos

    The ninety days run governance, risk and compliance as one loop, not three programmes at once.

    The governance decision is what the role may decide alone, and what belongs to the body above it. ISO 31000:2018 asks top management and oversight bodies to demonstrate leadership by assigning authority, responsibility and accountability at appropriate levels 6. That decision is inherited on day one, written down or not.

    The risk instruments are what those decisions run on: the criteria, the appetite, the register with named owners, and the acceptances on record. ISO 31000:2018 asks the organisation to specify the amount and type of risk it may or may not take, relative to objectives 7.

    What compliance later demonstrates is that the loop closed: obligations identified, the decision taken by someone entitled to take it, the evidence filed. Protection is ensured through governance and demonstrated through compliance, and both exist to manage risk.

    The legal frame is inherited too. Directive (EU) 2022/2555 has Member States ensure that management bodies of essential and important entities approve cybersecurity risk-management measures taken to comply with Article 21 8. Those bodies also oversee implementation, and can be held liable for infringements of that Article. Their members are required to follow training, so they gain the knowledge to identify risks and assess risk-management practices 9.

    Regulation (EU) 2022/2554 is more specific again. The management body defines, approves, oversees and is responsible for implementing all arrangements related to the ICT risk management framework 10. It sets clear roles and responsibilities for all ICT-related functions 11. Its members keep their knowledge current, including by following specific training 12.

    2. Definitions (only the ones that cause disputes)

    Six terms decide what the ninety days produce. Requirement text is paraphrased; only titles are quoted.

    TermWorking definitionSource
    Mandate and decision rightsThe written list of decisions the role takes alone, takes jointly, recommends, or escalates. Anything absent is escalated. The shape is in The security operating model.Method, against clause 5.3 13
    Context and interested partiesThe internal and external issues relevant to the purpose, and the parties whose requirements the organisation must satisfy, each recorded with its own requirement.ISO/IEC 27001:2022 clauses 4.1 and 4.2 2
    Obligations inventoryOne list of legal, statutory, regulatory and contractual security requirements, each with the approach that meets it, kept up to date.Annex A / ISO/IEC 27002:2022 control 5.31 Legal, statutory, regulatory and contractual requirements 4
    The risk pictureThe register, the criteria in force and the acceptances on record, read as one view. The method is in The risk register other people trust.Method, against clause 6.1.2 14
    Current and Target ProfileA Current Profile states the Core outcomes being achieved and to what extent, a Target Profile those selected and prioritised. The gap becomes an action plan.NIST CSWP 29 §3.1 15
    The first decision itemOne item taken to the governing body inside ninety days, phrased as a decision with options and a recommendation, not a status report.Method, against clause 9.3.3 5

    3. The method — three thirties

    Fourteen steps across three blocks of thirty days, and the blocks are the three disciplines in order. Days 1–30 read what risk already holds and what compliance already owes. Days 31–60 take the governance decisions those instruments need. Days 61–90 return the decision to the body that owns it, and fix the evidence compliance will later show. Every step names its output; a step without an artefact is a conversation.

    3.1 Hold the mandate conversation

    The first meeting settles what the role may decide. Ask for four things in writing: the decisions taken alone, the decisions recommended, the escalation path with a maximum time to answer, and the budget authority. Clause 5.3 is Organizational roles, responsibilities and authorities 13.

    Where a sector instrument applies, read the duties it places on the body above the role first. NIS2 Article 20 and DORA Article 5 set the agenda: the body's own obligation is what the role exists to serve.

    • Input: the appointment terms; the delegation of authority; the applicable instruments.
    • Activity: ask the four questions; write the answers on one page; return it for signature inside a fortnight.
    • Output: mandate note, one page, signed by the sponsor.
    • Owner: the leader drafts; the sponsor approves.

    3.2 Build the obligations inventory

    One list, not several: every legal, statutory, regulatory and contractual security requirement, each with the approach that meets it 4. CSF 2.0 states the same outcome at GV.OC-03, where legal, regulatory and contractual requirements regarding cybersecurity are understood and managed 16.

    Two columns matter most in a first quarter: the fixed date, and who owes it. Certification surveillance, reporting windows and audit clauses are constraints on the plan rather than items in it. Turning an obligation into control requirements is a separate method, in From regulation to controls.

    • Input: contracts with security clauses; certificates and their cycles; the instruments; supervisory correspondence.
    • Activity: list each requirement with its source, owner and next fixed date; mark those with no owner.
    • Output: obligations inventory, with a dated calendar view.
    • Owner: the leader owns the list; each requirement has a named owner.

    3.3 Map the assets and services at board altitude

    The map exists to make later conversations short. Name the services the organisation delivers, the systems each depends on, and the data classes they hold. Stop at the level a board can hold in mind, usually a dozen entries rather than an inventory.

    CSF 2.0 places these outcomes in Organizational Context. GV.OC-04 has the critical objectives, capabilities and services that external stakeholders depend on understood and communicated 17. GV.OC-05 covers the outcomes, capabilities and services the organisation itself depends on 18.

    • Input: the service catalogue; the application inventory; the supplier register; the data classification, if any.
    • Activity: draw services against supporting systems and data; mark dependencies with no alternative; record what is unknown as unknown.
    • Output: service and dependency map, one page.
    • Owner: the leader draws it; each service owner confirms their row.

    3.4 Read the risk picture as it stands

    Read, do not rebuild. Three questions answer it. Does a register exist, and are its entries owned by people entitled to accept them? Are there written criteria and an appetite, or only adjectives? What has been accepted, by whom, and when does it expire?

    Those methods are published separately and are not repeated here. The register is in The risk register other people trust, the criteria in Risk appetite and criteria that decisions can use. Acceptances are in Risk acceptance and residual risk. Clause 6.1.2 is Information security risk assessment 14.

    • Input: the register; the criteria, if any; exception and acceptance records; the last assessment.
    • Activity: sample ten entries end to end; check owner entitlement and expiry; list what the picture cannot answer.
    • Output: risk picture v0, with an explicit list of gaps.
    • Owner: the leader assembles; existing risk owners keep their own entries.

    3.5 Establish the control reality

    The question is not how many controls exist. It is which have an owner who knows it, and which produce a result somebody reads. Where a catalogue exists, sample it; where none does, record the absence rather than building one this quarter.

    Control 5.36 asks that compliance with the organisation's own policies and standards be reviewed regularly 19. Non-compliance is traced to its causes, and corrective actions are recorded. The catalogue method is in Control ownership and the control catalogue.

    • Input: the control catalogue or its nearest equivalent; the last internal audit; monitoring output; the policies.
    • Activity: sample controls across the service map; ask each named owner to describe the control; record which produce evidence.
    • Output: control reality note, listing owned, unowned and unevidenced controls.
    • Owner: the leader samples; control owners answer for their own.

    3.6 Learn the people and the rhythm

    Governance runs on meetings that already exist. Find which bodies meet, what each decides, and which the role may attend. Clause 5.1 is Leadership and commitment 20, and the calendar is where commitment becomes visible.

    Control 5.4 places a duty on management: everyone applies information security in line with the organisation's policy and procedures 21. That duty is exercised in forums, so the forums are the first thing to map.

    • Input: the governance calendar; committee terms of reference; the change and procurement processes.
    • Activity: list each body with its decisions and next date; note where security has a standing seat.
    • Output: forum map, with the seats requested and granted.
    • Owner: the leader maps; each committee chair confirms the seat.

    3.7 Write or repair the appetite

    The second thirty days begin with the boundary. Appetite written as decisions is what lets everyone else decide without asking. ISO 31000:2018 asks that risk criteria are aligned with the framework and customised to the purpose and scope of the activity 7. CSF 2.0 states the outcome at GV.RM-02, where risk appetite and tolerance statements are established, communicated and maintained 22.

    Where a statement already exists, repair rather than replace: test it against ten known risks and fix what it cannot decide. The full method is in Risk appetite and criteria that decisions can use.

    • Input: risk picture v0; the objectives; the obligations inventory; existing criteria.
    • Activity: draft or amend the appetite as decision rules; test on ten entries; take it for approval.
    • Output: appetite statement, approved and dated.
    • Owner: the leader drafts; the governing body approves.

    3.8 Draw the operating model and the decision rights

    With a boundary in place, the model says who applies it. Name the functions, say which discipline each serves, and write decision rights before reporting lines. ISO 31000:2018 asks top management to identify those holding accountability and authority for managing risk 23.

    Control 5.2 asks that information security roles and responsibilities are defined and allocated according to the organisation's needs 24. Each area of responsibility is documented, and authorisation levels are defined. The method is in The security operating model. Where the mandate sits per business unit, it is in The BISO operating model.

    • Input: the mandate note; the forum map; the control reality note; any independence requirements.
    • Activity: map functions to roles; write the decision-rights table; mark where a role assures its own work.
    • Output: operating model on a page, with a decision-rights table.
    • Owner: the leader drafts; top management approves.

    3.9 Write the one-page strategy as a gap

    Current to Target, stated as a gap rather than a score. A Current Profile specifies the Core outcomes currently achieved and to what extent; a Target Profile the desired outcomes selected and prioritised 15. The gap analysis between them produces a prioritised action plan 15.

    Tiers are a conversation device rather than a grade. They characterise the rigor of risk governance and management practices as Partial, Risk Informed, Repeatable and Adaptive, and complement a methodology rather than replacing it 25. Clause 6.2 is Information security objectives and planning to achieve them 26. The page is built in Security strategy on one page.

    • Input: the risk picture; the obligations inventory; the appetite statement; the service map.
    • Activity: write the Current Profile, then the Target; state the gap; attach five to seven measured objectives.
    • Output: one-page strategy, with Current, Target and the gap.
    • Owner: the leader writes; the governing body approves.

    3.10 Name the three things that cannot wait

    Everything else is sequenced. Three categories cannot be, and each comes from the first thirty days rather than from instinct.

    A regulatory or certification clock already running, taken from the obligations inventory. An unaccepted risk above tolerance, in the register with no decision and no compensating control. An unowned critical control on a service the organisation cannot deliver without. Where more qualify, the appetite statement picks three; the rest are scheduled.

    • Input: the obligations calendar; risk picture v0; the control reality note; the appetite statement.
    • Activity: shortlist candidates; test each against the appetite; name three, each with an owner and a date.
    • Output: cannot-wait list, three entries, dated.
    • Owner: the leader proposes; the governing body confirms it at the first decision item.

    3.11 Take one decision item to the governing body

    The last thirty days close the loop. The first paper carries one decision, not a tour of the estate. Give the body a question, the options with their consequences, a recommendation, and the record it signs. Clause 9.3.3 is Management review results 5, and results are decisions, not observations.

    The pack, the risk selection and the cadence are in Board and management reporting for security. CSF 2.0 states the accountability at GV.RR-01, where organisational leadership is responsible and accountable for cybersecurity risk 27. That leadership also fosters a risk-aware, ethical and continually improving culture.

    • Input: the appetite statement; the one-page strategy; the cannot-wait list; the risk picture.
    • Activity: write one decision item with options and a recommendation; circulate it ahead; record the outcome with an owner and a date.
    • Output: first decision item; the decision recorded in the review record.
    • Owner: the leader tables it; the governing body decides.

    3.12 Switch the operating calendar on

    A calendar turns the ninety days into a system. Fix the dates for risk reviews, control reporting, the management review and the obligations refresh, and publish them ahead. ISO 31000:2018 asks top management to articulate continual commitment through a policy or statement conveying objectives and commitment 28.

    Clause 5.2 is Policy 29. Control 5.1 asks that the information security policy and topic-specific policies are defined, approved by management, published and communicated 30. They are reviewed at planned intervals, and when significant changes occur.

    • Input: the forum map; the obligations calendar; the operating model; the objectives.
    • Activity: place each recurring item on a date; name its owner and the input it needs; publish the calendar.
    • Output: operating calendar, published for the coming cycle.
    • Owner: the leader owns the calendar; each item carries an owner.

    3.13 Define the measures that will show movement

    Measures set now make the second quarter arguable. Clause 9.1 is Monitoring, measurement, analysis and evaluation 31. Define each measure once, with its source record, and hold the definition when results disappoint.

    Four carry a first year. Obligations with a named owner and a next date. Register entries whose owner is entitled to accept them. Critical controls with an owner and a recent result. Decisions closed on time. CSF 2.0 places the review outcome at GV.OV-03, where risk management performance is evaluated and reviewed for adjustments needed 32.

    • Input: the obligations inventory; the register; the control reality note; the decision record.
    • Activity: define four measures with their source records; take a baseline this quarter; set the reporting date.
    • Output: measure definitions; day-90 baseline.
    • Owner: the leader defines; the security function keeps the definitions stable.

    3.14 Write down what deliberately waits

    What is not being done is part of the plan, and it stops the plan being reopened monthly. Tools wait until the risk picture asks for one. Reorganisations wait until decision rights are written and tested. Certifications wait unless a date binds them; the approach is then in Running the external audit.

    Competence is the exception that does not wait, because it takes the longest. Clause 7.2 is Competence 33. Control 5.2 adds that a person taking a specific security role should be competent in the knowledge and skills that role requires 24.

    • Input: the cannot-wait list; the one-page strategy; the requests received this quarter.
    • Activity: list each deferred item with the trigger that would start it; publish it alongside the strategy.
    • Output: deferred list, each entry with a named trigger.
    • Owner: the leader owns the list; the governing body sees it alongside the strategy.

    4. Deliverables

    Eight artefacts, each produced by a step above. Retention periods are organisational choices rather than requirements of any standard.

    DeliverableProduced byFormatRetention
    Mandate noteStep 3.1one page, signedevery version, whole cycle
    Obligations inventoryStep 3.2table plus calendar viewcurrent, kept up to date
    Risk picture v0Step 3.4register view plus gap listcurrent plus one cycle
    Appetite statementStep 3.7document, approvedevery version, whole cycle
    Operating model on a pageStep 3.8page plus decision-rights tableevery version, whole cycle
    One-page strategyStep 3.9CSF Current and Target Profileevery version, whole cycle
    First decision itemStep 3.11paper plus the decision recordwhole cycle
    Operating calendarStep 3.12calendar plus one-page summarycurrent period

    Templates for the register, the criteria and the acceptance record ship with their own playbooks. Mandate note and obligations inventory: template pending.

    5. What the board (and later the auditor) will ask

    Both audiences open the same way: a record is requested, then the decision behind it.

    A first quarter that answers all six from artefacts has done the work. One that answers from memory has not started.

    6. Failure modes and how they surface as findings

    Four patterns account for most lost quarters, each given as the pattern, the wording it produces, and the smallest change that removes it.

    The root is the same in all four: a position stated in prose rather than recorded as a decision with an owner and date.

    7. Mapping the ninety days to the standards

    Clause numbers and titles come from the ISO/IEC 27001:2022 contents listing, control numbers and titles from ISO/IEC 27002:2022. Category and Subcategory identifiers come from the CSF 2.0 Core in Appendix A. Requirement text is paraphrased.

    Day blockArtefactISO/IEC 27001:2022ISO/IEC 27002:2022 or ISO 31000:2018CSF 2.0Evidence sampled
    1–30Mandate note5.3 Organizational roles, responsibilities and authorities 13ISO 31000:2018 clause 5.2 6GV.RR-02Signed page, dated
    1–30Obligations inventory4.2 Understanding the needs and expectations of interested parties 2Control 5.31 4GV.OC-03Rows with owner and next date
    1–30Service and dependency map4.1 Understanding the organization and its context 1ISO 31000:2018 clause 5.4.1 34GV.OC-04Services traced to systems
    1–30Risk picture v06.1.2 Information security risk assessment 14ISO 31000:2018 clause 6.3.3 35GV.RM-06Ten entries sampled end to end
    1–30Control reality note9.1 Monitoring, measurement, analysis and evaluation 31Control 5.36 19GV.OV-03Owner named, result recent
    31–60Appetite statement6.1 Actions to address risks and opportunities 36ISO 31000:2018 clause 6.3.4 7GV.RM-02Approval record, dated
    31–60One-page strategy6.2 Information security objectives and planning to achieve them 26ISO 31000:2018 clause 5.4.2 28Profiles, §3.1Current, Target and the gap
    61–90First decision item9.3 Management review 5Control 5.1 30GV.OV-01Decision with owner and date
    61–90Operating calendar5.1 Leadership and commitment 20Control 5.4 21GV.RR-01Published dates, owners named
    61–90Corrective actions from the quarter10.2 Nonconformity and corrective action 37Control 5.36 as aboveGV.OV-02Cause examined, action reviewed
    Day-block to artefact, clause, CSF outcome and evidence

    8. Checklist

    Each item is observable. "Understood" is not; a dated artefact is.

    References

    Primary sources only. ISO/IEC 27001:2022 clause titles come from the publisher's own contents listing; ISO/IEC 27002:2022 and ISO 31000:2018 numbers and titles from licensed copies, with requirement text paraphrased.

    1. ISO/IEC. Information security management systems — Requirements. ISO/IEC 27001:2022. Contents and clause titles read at https://www.iso.org/obp/ui/#iso:std:iso-iec:27001:ed-3:v1:en 38
    2. ISO/IEC. Information security controls. ISO/IEC 27002:2022. Controls 5.1, 5.2, 5.4, 5.31 and 5.36 read in a licensed copy; catalogue entry at https://www.iso.org/standard/75652.html 39
    3. ISO. Risk management — Guidelines. ISO 31000:2018. Clauses 5.2, 5.4.1, 5.4.2, 5.4.3, 6.3.3 and 6.3.4 read in a licensed copy; catalogue entry at https://www.iso.org/standard/65694.html 40
    4. National Institute of Standards and Technology. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29, 26 February 2024. Sections 3.1 and 3.2 and Appendix A read at https://doi.org/10.6028/NIST.CSWP.29 41
    5. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. Article 20 read at https://publications.europa.eu/resource/celex/32022L2555 42
    6. European Parliament and Council. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. OJ L 333, 27.12.2022, p. 1. Article 5 read at https://publications.europa.eu/resource/celex/32022R2554 43

    Cadences, retention periods, sample sizes and the four measures are organisational choices rather than requirements of any standard or instrument named here.

    Sources

    1. 1ISO/IEC 27001:2022 clause 4.1, iso.org/obp · verified 2026-09-03
    2. 2ISO/IEC 27001:2022 clause 4.2, iso.org/obp · verified 2026-09-03
    3. 3ISO/IEC 27001:2022 clause 4.3, iso.org/obp · verified 2026-09-03
    4. 4ISO/IEC 27002:2022 control 5.31, licensed copy · verified 2026-09-05
    5. 5ISO/IEC 27001:2022 clause 9.3, iso.org/obp · verified 2026-09-03
    6. 6ISO 31000:2018 clause 5.2, licensed copy · verified 2026-09-05
    7. 7ISO 31000:2018 clause 6.3.4, licensed copy · verified 2026-09-05
    8. 8EU Publications Office CELEX 32022L2555 Art. 20(1) · verified 2026-09-05
    9. 9EU Publications Office CELEX 32022L2555 Art. 20(2) · verified 2026-09-05
    10. 10EU Publications Office CELEX 32022R2554 Art. 5(2) · verified 2026-09-05
    11. 11EU Publications Office CELEX 32022R2554 Art. 5(2), point (c) · verified 2026-09-05
    12. 12EU Publications Office CELEX 32022R2554 Art. 5(4) · verified 2026-09-05
    13. 13ISO/IEC 27001:2022 clause 5.3, iso.org/obp · verified 2026-09-03
    14. 14ISO/IEC 27001:2022 clause 6.1.2, iso.org/obp · verified 2026-09-03
    15. 15NIST CSWP 29 §3.1, nvlpubs.nist.gov · verified 2026-09-05
    16. 16NIST CSWP 29 Appendix A GV.OC-03, nvlpubs.nist.gov · verified 2026-09-05
    17. 17NIST CSWP 29 Appendix A GV.OC-04, nvlpubs.nist.gov · verified 2026-09-05
    18. 18NIST CSWP 29 Appendix A GV.OC-05, nvlpubs.nist.gov · verified 2026-09-05
    19. 19ISO/IEC 27002:2022 control 5.36, licensed copy · verified 2026-09-05
    20. 20ISO/IEC 27001:2022 clause 5.1, iso.org/obp · verified 2026-09-03
    21. 21ISO/IEC 27002:2022 control 5.4, licensed copy · verified 2026-09-05
    22. 22NIST CSWP 29 Appendix A GV.RM-02, nvlpubs.nist.gov · verified 2026-09-05
    23. 23ISO 31000:2018 clause 5.4.3, licensed copy · verified 2026-09-05
    24. 24ISO/IEC 27002:2022 control 5.2, licensed copy · verified 2026-09-05
    25. 25NIST CSWP 29 §3.2, nvlpubs.nist.gov · verified 2026-09-05
    26. 26ISO/IEC 27001:2022 clause 6.2, iso.org/obp · verified 2026-09-03
    27. 27NIST CSWP 29 Appendix A GV.RR-01, nvlpubs.nist.gov · verified 2026-09-05
    28. 28ISO 31000:2018 clause 5.4.2, licensed copy · verified 2026-09-05
    29. 29ISO/IEC 27001:2022 clause 5.2, iso.org/obp · verified 2026-09-03
    30. 30ISO/IEC 27002:2022 control 5.1, licensed copy · verified 2026-09-05
    31. 31ISO/IEC 27001:2022 clause 9.1, iso.org/obp · verified 2026-09-03
    32. 32NIST CSWP 29 Appendix A GV.OV-03, nvlpubs.nist.gov · verified 2026-09-05
    33. 33ISO/IEC 27001:2022 clause 7.2, iso.org/obp · verified 2026-09-03
    34. 34ISO 31000:2018 clause 5.4.1, licensed copy · verified 2026-09-05
    35. 35ISO 31000:2018 clause 6.3.3, licensed copy · verified 2026-09-05
    36. 36ISO/IEC 27001:2022 clause 6.1, iso.org/obp · verified 2026-09-03
    37. 37ISO/IEC 27001:2022 clause 10.2, iso.org/obp · verified 2026-09-03
    38. 38ISO/IEC 27001:2022 contents, iso.org/obp · verified 2026-09-03
    39. 39ISO/IEC 27002:2022 controls 5.1, 5.2, 5.4, 5.31 and 5.36, licensed copy · verified 2026-09-05
    40. 40ISO 31000:2018 clauses 5.2, 5.4.1, 5.4.2, 5.4.3, 6.3.3 and 6.3.4, licensed copy · verified 2026-09-05
    41. 41NIST CSWP 29 §3.1, §3.2 and Appendix A, nvlpubs.nist.gov · verified 2026-09-05
    42. 42EU Publications Office CELEX 32022L2555 Art. 20 · verified 2026-09-05
    43. 43EU Publications Office CELEX 32022R2554 Art. 5 · verified 2026-09-05