DORA, digital résilience for the financial sector.
DORA (EU régulation 2022/2554) imposes a strict ICT risk management framework on EU financial entities. Applicable since 17 January 2025, it is directly binding (no national transposition needed). In Luxembourg, the CSSF is the supervisory authority.
Law contents
All 64 articles, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- 5. Governance and organisation
- 6. ICT risk management framework
- 7. ICT systems, protocols and tools
- 8. Identification
- 9. Protection and prevention
- 10. Detection
- 11. Response and recovery
- 12. Backup policies and procedures, restoration and recovery procedures and methods
- 13. Learning and evolving
- 14. Communication
- 15. Further harmonisation of ICT risk management tools, methods, processes and policies
- 16. Simplified ICT risk management framework
- 17. ICT-related incident management process
- 18. Classification of ICT-related incidents and cyber threats
- 19. Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
- 20. Harmonisation of reporting content and templates
- 21. Centralisation of reporting of major ICT-related incidents
- 22. Supervisory feedback
- 23. Operational or security payment-related incidents concerning credit institutions, payment institutions, account informat
- 24. General requirements for the performance of digital operational resilience testing
- 25. Testing of ICT tools and systems
- 26. Advanced testing of ICT tools, systems and processes based on TLPT
- 27. Requirements for testers for the carrying out of TLPT
- 28. General principles
- 29. Preliminary assessment of ICT concentration risk at entity level
- 30. Key contractual provisions
- 31. Designation of critical ICT third-party service providers
- 32. Structure of the Oversight Framework
- 33. Tasks of the Lead Overseer
- 34. Operational coordination between Lead Overseers
- 35. Powers of the Lead Overseer
- 36. Exercise of the powers of the Lead Overseer outside the Union
- 37. Request for information
- 38. General investigations
- 39. Inspections
- 40. Ongoing oversight
- 41. Harmonisation of conditions enabling the conduct of the oversight activities
- 42. Follow-up by competent authorities
- 43. Oversight fees
- 44. International cooperation
- 46. Competent authorities
- 47. Cooperation with structures and authorities established by Directive (EU) 2022/2555
- 48. Cooperation between authorities
- 49. Financial cross-sector exercises, communication and cooperation
- 50. Administrative penalties and remedial measures
- 51. Exercise of the power to impose administrative penalties and remedial measures
- 52. Criminal penalties
- 53. Notification duties
- 54. Publication of administrative penalties
- 55. Professional secrecy
- 56. Data Protection
Who is concerned?
All financial entities in the broad sense: banks, investment firms, asset managers, UCITS, AIFs, EMIs, insurers and reinsurers, insurance intermediaries, crowdfunding platforms, crypto-asset service providers, central depositories, central counterparties, trading venues, crédit rating agencies, data reporting service providers. And also: critical third-party ICT service providers (cloud, datacenters, key SaaS vendors).
Key obligations
- ICT risk management framework: governance, identification of critical assets, protection, détection, response, recovery, learning and évolution.
- Major ICT incident management, classification and notification: initial notification within 4 hours, interim report within 72 hours, final report within 1 month.
- Digital operational résilience testing: regular tests on critical systems and advanced tests (Threat-Led Penetration Testing, TLPT) every 3 years for significant entities.
- ICT third-party risk management: provider register, mandatory contractual clauses, exit plans, continuous monitoring, désignation of critical providers with direct European supervision.
Deadlines
DORA has been applicable since 17 January 2025. No transitional phase. The CSSF issued application circulars in 2024 and has been conducting inspections since Q1 2025.
Sanctions for non-compliance
Heavy administrative sanctions: up to 1% of average daily turnover per day of non-compliance (capped at 6 months). For very large entities, this can be enormous. CSSF sanctions are cumulative with other sanctions (GDPR, NIS 2 where applicable).
How Luxgap helps
Our CISO mandate covers DORA's full scope, with a dedicated team for sector-specific requirements. Our business continuity plan is aligned with DORA and ISO 22301. We also run TLPT testing in partnership with accredited testers.
The DORA regulatory ecosystem, without the fog
DORA does not stand alone: it is a framework régulation completed by technical standards (RTS) and articulated with Luxembourg law. Here is the full map we master:
- DORA is lex specialis for the financial sector: for the entities it covers, it prevails over NIS 2 on ICT risk management and incident notification (Article 1 DORA).
- Penetration testing (TLPT): specified by Delegated Régulation (EU) 2025/1190, implemented in Luxembourg via the TIBER-LU framework (BCL + CSSF).
- ICT subcontracting: specified by RTS (EU) 2025/532 on ICT services supporting critical functions.
- Outsourcing: CSSF Circular 22/806, amended by CSSF 25/883 to align with DORA.
- ICT third-party services: CSSF Circular 25/882 gives the CSSF's practical instructions.
- ICT risk management: CSSF Circular 20/750, amended by CSSF 25/881.
- Data breaches: articulation with the GDPR where an ICT incident exposes personal data (dual CSSF + CNPD notification).
Let's set up your DORA compliance.
Configure a quote for a CISO mandate for the financial sector. Reply within one business day.
Build my quote →