The classic trap
This recital flags an operational reality often overlooked: DORA does not replace existing RTS and ITS issued under CRA Regulation (1060/2009), EMIR (648/2012), MiFIR (600/2014) and CSDR (909/2014), it carries over and updates them. In practice, the CSSF checks the consistency between your DORA framework and the ICT obligations already in force under these sectoral regulations. Entities that treat DORA as a new silo, disconnected from their EMIR or CSDR obligations, end up with contradictory policies on the same critical system.
The regulatory layering you must map
Recital 101 mandates a cross-cutting reading. A Luxembourg central securities depository under CSDR already manages ICT risks under article 45 of Regulation 909/2014 and its associated RTS. DORA adds, harmonises and tightens, but does not erase. Concrete friction points:
- A central counterparty (CCP) under EMIR already has ICT continuity requirements: DORA layers on TLPT and the third-party provider register.
- A credit rating agency under CRA already has information system integrity obligations: DORA adds the harmonised major incident notification.
- A trading venue under MiFIR already has operational resilience requirements: DORA imposes the advanced testing framework.
- Future RTS published by the ESAs (EBA, ESMA, EIOPA) via the Joint Committee further specify DORA articles 15, 16, 18, 28 and 30 and must be integrated on a rolling basis into your internal policies.
How Luxgap automates this risk
Our Luxgap Regulatory Overlay Mapper eliminates the multi-regulatory blind spot risk by automatically projecting your DORA obligations onto the pre-existing RTS and ITS matrix under CRA, EMIR, MiFIR and CSDR. The tool ingests your CSSF license, your current ICT policies and the ESMA/EBA/EIOPA feeds to produce a living map of applicable requirements per critical system, updated whenever a new DORA RTS is published in the OJEU.
- Automatically detects your actual regulatory perimeter from your CSSF status and declared activities, without burdensome questionnaires.
- Cross-references each DORA requirement (articles 5 to 30) with existing RTS and ITS under 1060/2009, 648/2012, 600/2014 and 909/2014 to identify duplicates, conflicts and grey zones.
- Sends real-time alerts via Teams or Slack whenever a new RTS, ITS or Q&A is published by the Joint Committee of the ESAs and impacts your critical systems.
- Generates a consolidated compliance matrix per critical system, exportable in CSSF format for annual ICT governance reviews.
- Produces a timestamped PDF report enforceable during a CSSF inspection, demonstrating coordinated handling of DORA and pre-existing sectoral regulations.
Available as a complement to a Luxgap CISO or DPO mandate or as a standalone SaaS module depending on your regulatory perimeter. Request a tailored quote and our teams will prepare a demonstration on your actual CSSF license, with a free 48-hour blank audit to map your regulatory layering before any commitment.