Recital 10

Recital 10

Digital Operational Resilience Act · UE 2022/2554

(10)

To date, due to the ICT risk related provisions being only partially addressed at Union level, there are gaps or overlaps in important areas, such as ICT-related incident reporting and digital operational resilience testing, and inconsistencies as a result of emerging divergent national rules or cost-ineffective application of overlapping rules. This is particularly detrimental for an ICT-intensive user such as the financial sector since technology risks have no borders and the financial sector deploys its services on a wide cross-border basis within and outside the Union. Individual financial entities operating on a cross-border basis or holding several authorisations (e.g. one financial entity can have a banking, an investment firm, and a payment institution licence, each issued by a different competent authority in one or several Member States) face operational challenges in addressing ICT risk and mitigating adverse impacts of ICT incidents on their own and in a coherent cost-effective way.

Luxembourg specificity
Circulaire CSSF 24/847 du 5 avril 2024 relative a la notification des incidents TIC

In Luxembourg, the CSSF repealed and overhauled its legacy ICT Circulars (notably 20/750 and 22/806) to align its prudential framework with DORA via CSSF Circular 24/847 on ICT-related incident notification. Luxembourg financial entities holding several authorisations must now report major ICT incidents through a single CSSF channel, regardless of the licence concerned, which concretely embodies the harmonisation intent of recital 10.

Luxgap practice: for multi-licensed players (bank + PFS + EMI), we recommend redesigning the ICT mapping into a single group register before the next SREP, with migration from legacy Circulars to the DORA-CSSF 24/847 framework on an iso-functional basis.