XML 470 R40.htm IDEA: XBRL DOCUMENT v3.25.4
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2025
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block] We believe ASML’s competitive
edge is grounded in knowledge
and IP built over decades. While
this expertise is developed
collaboratively by our people
and our thriving ecosystem of
suppliers, partners, customers
and knowledge institutions, we
aim to ensure it is systematically
captured, documented and
protected to maintain our
industry leadership.
Our innovation ecosystem is largely based
on the exchange of ideas and insights, which
makes the protection of knowledge a challenge,
but also makes it difficult for others to replicate
our work. This knowledge is captured in our
information management infrastructure.
Our prime objective is to protect the integrity
and confidentiality of our critical information
and data while ensuring continuity of our
operations. This should be embedded in
our processes, people and infrastructure.
However, as we innovate and collaborate
together, our partners inevitably need access
to some parts of our systems’ infrastructure.
We aim to enable this in a secure way, with
best-in-class security functions deployed
across our infrastructure to manage security
threats and risks.
We are also confronted with EU laws such as
the NIS2 Directive and the Cyber Resilience
Act (CRA), and with Cyber Incident Reporting
for Critical Infrastructure (Cybersecurity and
Infrastructure Security Agency) in the US,
which highlight regulations seeking to ensure
critical infrastructure organizations are
securing themselves effectively.
As perpetrators make use of more advanced
methods, implementing adequate responses
becomes more complex – so we continue to
take steps to try to deal with this effectively.
In the event of a security incident involving the
loss of information assets, the materiality of
the incident is jointly assessed by technology
leaders and subject matter experts with
support from Corporate Intellectual Property
and Legal and Compliance.
In 2025, as far as we are aware, ASML had
zero incidents with a material impact.
How we manage information security
We have a dedicated Security function to
ensure we properly manage all security risks.
The security risk assessment process, which
includes cybersecurity, sits within our
ERM process and follows our governance
structure, with the Security Committee as
a sub-committee of the CESR, which acts
as the oversight committee mandated
by the BoM.
The three layers of our security governance
framework are:
1.The Security Committee: Oversees and
promotes the integration of security risk
management methodologies and related
controls in ASML’s business processes.
The Security Committee reports into
the CESR.
2.The Security Function Management
team: Monitors the implementation and
execution of security risk management
methodologies and related controls in
ASML’s business processes.
3.The Security Expert team: Determines
the risk and control strategies and
generates input for tactical plans by
providing content expertise and
setting requirements.
This governance framework enables cross-
disciplinary alignment through structured
meetings and ensures integration throughout
our broader risk management profile.
Alongside evaluation by our Internal Audit
department, we have engaged several third
parties to evaluate our security capabilities
and maturity and provide both expertise
and resources to assist in identifying and
managing material cybersecurity risks. Some
examples of these engagements include
external validation of security management
systems, capability assessments, red-teaming,
penetration testing and tabletop exercises.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] How we manage information security
We have a dedicated Security function to
ensure we properly manage all security risks.
The security risk assessment process, which
includes cybersecurity, sits within our
ERM process and follows our governance
structure, with the Security Committee as
a sub-committee of the CESR, which acts
as the oversight committee mandated
by the BoM.
The three layers of our security governance
framework are:
1.The Security Committee: Oversees and
promotes the integration of security risk
management methodologies and related
controls in ASML’s business processes.
The Security Committee reports into
the CESR.
2.The Security Function Management
team: Monitors the implementation and
execution of security risk management
methodologies and related controls in
ASML’s business processes.
3.The Security Expert team: Determines
the risk and control strategies and
generates input for tactical plans by
providing content expertise and
setting requirements.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block] We have a dedicated Security function to
ensure we properly manage all security risks.
The security risk assessment process, which
includes cybersecurity, sits within our
ERM process and follows our governance
structure, with the Security Committee as
a sub-committee of the CESR, which acts
as the oversight committee mandated
by the BoM.
The Security function led by the Chief
Information Security Officer (CISO)
monitors risk prevention, detection,
mitigation and remediation processes
related to cybersecurity, and regularly
reports to the Security Governance and to
the Audit Committee. We have implemented
processes to identify and respond to
cybersecurity threats intended to comply
with standards set by the International
Organization for Standardization (ISO 27002),
International Society of Automation (ISA/
IEC 62443) and US National Institute
of Standards and Technology (NIST
Cybersecurity Framework). We have a
dedicated team that works to increase
our strength and maturity and minimize
exploitable vulnerabilities by monitoring
threats, assessing our vulnerability and
defining incident responses.
The central security organization was
set up to define the policies, procedures
and adherence to these policies in a
second-line role, coordinated closely with
the security representatives in the business.
It also delivers operational services to the
ASML organization via the Security Operations
Center (SOC). In case of incidents, the SOC
is to be the central point for dealing with
these incidents effectively.
In the event of a possible material cybersecurity
incident, the Corporate Crisis Management
team (CCMT) verifies the assessment and
proposed response. The CCMT is chaired
by the Chief Operations Officer, who reports
out to the BoM on the proposed response.
A dedicated governance structure is in place
to deal with a crisis situation effectively.
The CISO coordinates the response as a
second line of responsibility, along with
the security teams in the business.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] We have a dedicated Security function to
ensure we properly manage all security risks.
The security risk assessment process, which
includes cybersecurity, sits within our
ERM process and follows our governance
structure, with the Security Committee as
a sub-committee of the CESR, which acts
as the oversight committee mandated
by the BoM.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] We have a dedicated Security function to
ensure we properly manage all security risks.
The security risk assessment process, which
includes cybersecurity, sits within our
ERM process and follows our governance
structure, with the Security Committee as
a sub-committee of the CESR, which acts
as the oversight committee mandated
by the BoM.
It also delivers operational services to the
ASML organization via the Security Operations
Center (SOC). In case of incidents, the SOC
is to be the central point for dealing with
these incidents effectively.
In the event of a possible material cybersecurity
incident, the Corporate Crisis Management
team (CCMT) verifies the assessment and
proposed response. The CCMT is chaired
by the Chief Operations Officer, who reports
out to the BoM on the proposed response.
A dedicated governance structure is in place
to deal with a crisis situation effectively.
The CISO coordinates the response as a
second line of responsibility, along with
the security teams in the business.
Cybersecurity Risk Role of Management [Text Block] The Security function led by the Chief
Information Security Officer (CISO)
monitors risk prevention, detection,
mitigation and remediation processes
related to cybersecurity, and regularly
reports to the Security Governance and to
the Audit Committee. We have implemented
processes to identify and respond to
cybersecurity threats intended to comply
with standards set by the International
Organization for Standardization (ISO 27002),
International Society of Automation (ISA/
IEC 62443) and US National Institute
of Standards and Technology (NIST
Cybersecurity Framework). We have a
dedicated team that works to increase
our strength and maturity and minimize
exploitable vulnerabilities by monitoring
threats, assessing our vulnerability and
defining incident responses.
The central security organization was
set up to define the policies, procedures
and adherence to these policies in a
second-line role, coordinated closely with
the security representatives in the business.
It also delivers operational services to the
ASML organization via the Security Operations
Center (SOC). In case of incidents, the SOC
is to be the central point for dealing with
these incidents effectively.
In the event of a possible material cybersecurity
incident, the Corporate Crisis Management
team (CCMT) verifies the assessment and
proposed response. The CCMT is chaired
by the Chief Operations Officer, who reports
out to the BoM on the proposed response.
A dedicated governance structure is in place
to deal with a crisis situation effectively.
The CISO coordinates the response as a
second line of responsibility, along with
the security teams in the business.
Third-party cybersecurity risks
In order to both oversee and identify risks
from cybersecurity threats associated with
our use of third parties, all of our providers
are required to comply with our ASML
Security Controls (part of the Supplier
Security Policy). We assess and monitor
providers using a risk-based approach
based on ISO 27002, ISA/IEC 62443 and
NIST Cybersecurity Framework. We also
have a dedicated team to deploy procedures
to increase our resistance strength and
minimize vulnerabilities by monitoring
threats, assessing our vulnerability through
testing, and defining responses.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Security function led by the Chief
Information Security Officer (CISO)
monitors risk prevention, detection,
mitigation and remediation processes
related to cybersecurity, and regularly
reports to the Security Governance and to
the Audit Committee. We have implemented
processes to identify and respond to
cybersecurity threats intended to comply
with standards set by the International
Organization for Standardization (ISO 27002),
International Society of Automation (ISA/
IEC 62443) and US National Institute
of Standards and Technology (NIST
Cybersecurity Framework). We have a
dedicated team that works to increase
our strength and maturity and minimize
exploitable vulnerabilities by monitoring
threats, assessing our vulnerability and
defining incident responses.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] The Security function led by the Chief
Information Security Officer (CISO)
monitors risk prevention, detection,
mitigation and remediation processes
related to cybersecurity, and regularly
reports to the Security Governance and to
the Audit Committee. We have implemented
processes to identify and respond to
cybersecurity threats intended to comply
with standards set by the International
Organization for Standardization (ISO 27002),
International Society of Automation (ISA/
IEC 62443) and US National Institute
of Standards and Technology (NIST
Cybersecurity Framework). We have a
dedicated team that works to increase
our strength and maturity and minimize
exploitable vulnerabilities by monitoring
threats, assessing our vulnerability and
defining incident responses.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] In the event of a possible material cybersecurity
incident, the Corporate Crisis Management
team (CCMT) verifies the assessment and
proposed response. The CCMT is chaired
by the Chief Operations Officer, who reports
out to the BoM on the proposed response.
A dedicated governance structure is in place
to deal with a crisis situation effectively.
The CISO coordinates the response as a
second line of responsibility, along with
the security teams in the business.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true