IRImplementing rule
IS.AR.230Record-keeping
(a)The competent authority shall keep records of its information security management activities
(1)The competent authority shall ensure that the following records are archived and traceable:
(i)contracts for activities referred to in point IS.AR.200(a)(5);
(ii)records of the key processes referred to in point IS.AR.200(d);
(iii)records of the risks identified in the risk assessment referred to in point IS.AR.205 along with the associated risk treatment measures referred to in point IS.AR.210;
(iv)records of information security events which may need to be reassessed to reveal undetected information security incidents or vulnerabilities.
(2)The records referred to in point (1)(i) shall be retained at least until 5 years after the contract has been amended or terminated.
(3)The records referred to in point (1)(ii) and (iii) shall be retained at least for a period of 5 years.
(4)The records referred to in point (1)(iv) shall be retained until those information security events have been reassessed in accordance with a periodicity defined in a procedure established by the competent authority.
(b)The competent authority shall keep records of qualification and experience of its own staff involved in information security management activities
(1)The personnel’s qualification and experience records shall be retained for as long as the person works for the competent authority, and for at least 3 years after the person has left the competent authority.
(2)Members of the staff shall, upon their request, be given access to their individual records. In addition, upon their request, the competent authority shall provide them with a copy of their individual records on leaving the competent authority.
(c)The format of the records shall be specified in the competent authority’s procedures.
(d)Records shall be stored in a manner that ensures protection from damage, alteration and theft, with information being identified, when required, according to its security classification level. The competent authority shall ensure that the records are stored using means to ensure integrity, authenticity and authorised access.
IR · IS.AR.230 — Regulations (EU) 2023/203 and 2022/1645 · Regulation (EU) 2023/203 · Part-IS Easy Access Rules · EAR revision 5 Dec 2025