The classic trap
Recital 10 records a simple finding: before DORA, every multi-licensed financial entity juggled different ICT rules depending on the authority (CSSF for banking, investment firms, payment institutions, CAA for insurance), with divergent incident definitions and inconsistent reporting thresholds. DORA harmonises all of this, but the CSSF now sanctions entities that maintain legacy internal silos: a Luxembourg bank-EMI still managing its ICT risk via two separate registers, two distinct policies and two siloed reporting processes misses the legislator's intent and exposes itself to an operational inefficiency finding during the next ICT SREP review.
What this harmonisation intent concretely changes for a Luxembourg multi-licensed entity
- One consolidated ICT framework across all licences: the bank-investment firm-EMI no longer maintains three separate registers but a single register of critical functions mapped by licence.
- One DORA-aligned incident taxonomy (based on the RTS) applicable regardless of business line (banking, payment, investment) and reportable to the CSSF through a single notification flow.
- One resilience testing policy (TLPT, scenario-based testing) covering all authorisations, to avoid the costly overlap denounced by the recital.
- One consolidated group-level ICT third-party register, identifying concentrations on the same provider used cross-border (Azure, AWS, Swift, Bloomberg).
- One ICT risk governance reporting to a single management body, even if the entity holds several CSSF licences.
The operational trap: many Luxembourg players historically structured their ICT compliance by licence (legacy CSSF Circulars 12/552, 20/750, 22/806). DORA now requires a consolidated cross-cutting view, which implies redesigning steering tools, not just a documentary remapping.
How Luxgap automates this risk
Our Luxgap DORA Unified Cockpit consolidates in real time all your cross-licence ICT obligations into a single regulator-grade view. The tool plugs read-only into your existing sources (Active Directory, ServiceNow, Jira, Microsoft Defender, Azure Sentinel, vendor register in Odoo or SAP, contracts on SharePoint) and automatically rebuilds the consolidated mapping of your ICT risk, without asking business teams to fill in a single additional questionnaire.
- Automatically detects and merges duplicates between your legacy ICT registers (the same Azure provider declared three times under three different licences becomes a single consolidated entry with aggregated exposure).
- Classifies each detected incident under the harmonised DORA taxonomy (RTS 2024/1772) and pre-fills the CSSF notification form within regulatory deadlines (initial notification within 4 business hours, intermediate within 72h, final within 1 month).
- Maps concentration risk on critical cross-border ICT third-party providers and alerts as soon as the same vendor exceeds the cumulative criticality threshold across several licences.
- Generates a single digital operational resilience testing plan, covering all your licences, with a pre-built triennial TLPT calendar for significant entities.
- Produces a time-stamped, cryptographically sealed PDF report, defensible before the CSSF during ICT SREP, demonstrating coherent and harmonised DORA application across the entire group perimeter.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your licence perimeter. Request a tailored quote and our teams prepare a demonstration on your real perimeter, with a free 48h gap analysis to measure the current inconsistency between your per-licence ICT registers before any engagement.