Recital 1

Recital 1

Digital Operational Resilience Act · UE 2022/2554

(1)

In the digital age, information and communication technology (ICT) supports complex systems used for everyday activities. It keeps our economies running in key sectors, including the financial sector, and enhances the functioning of the internal market. Increased digitalisation and interconnectedness also amplify ICT risk, making society as a whole, and the financial system in particular, more vulnerable to cyber threats or ICT disruptions. While the ubiquitous use of ICT systems and high digitalisation and connectivity are today core features of the activities of Union financial entities, their digital resilience has yet to be better addressed and integrated into their broader operational frameworks.

Luxembourg specificity
loi luxembourgeoise du 1er juillet 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA) et circulaire CSSF 24/847

In Luxembourg, the CSSF is the competent authority for DORA across the regulated financial sector, and the law of 1 July 2024 implementing the DORA regulation explicitly designates the CSSF and the CAA as supervisory authorities depending on the type of entity (CSSF-supervised financial entities on one side, insurance and reinsurance undertakings and insurance intermediaries under the CAA on the other). CSSF circular 24/847 on ICT incident reporting completes the framework and articulates with CSSF circular 22/806 on outsourcing.

Luxgap practice: linking the DORA mapping to your CSSF 22/806 outsourcing register from day one avoids duplicate data entry and ensures consistency between both exercises during an on-site review.