Overview
The ESMA Minimum Standard IT Security Controls is a security requirements framework developed by the European Securities and Markets Authority (ESMA) to assess and ensure that service providers, platforms, applications, and third-party solutions meet minimum cybersecurity, operational security, and compliance expectations when handling ESMA information and services. The framework defines mandatory controls across key security domains including identity and access management, authentication, cryptographic protection, data-in-transit security, security operations, vulnerability management, business continuity, auditability, compliance, supply chain security, and secure software development. It also establishes requirements for certifications, penetration testing, incident reporting, logging, backup and recovery, encryption, and security governance to help protect ESMA information assets and support regulatory security assurance.