The classic trap
This recital marks the end of an era: before DORA, ICT obligations were scattered across CRA Regulation (rating agencies), EMIR (central counterparties), MiFIR (trading venues), CSDR (central securities depositories) and BMR (benchmarks). The common trap for CSSF-regulated entities is to keep managing ICT compliance in silos by regulation, forgetting that DORA is now the lex specialis that consolidates and harmonises. Post-2025 CSSF inspections check overall consistency, not a patchwork of legacy procedures.
The regulations consolidated by DORA
- Regulation (EC) 1060/2009 on credit rating agencies: CRA-specific ICT requirements are now governed by DORA.
- Regulation (EU) 648/2012 (EMIR): ICT obligations for CCPs and trade repositories migrate to DORA.
- Regulation (EU) 600/2014 (MiFIR): ICT requirements for APAs, ARMs and CTPs now fall under DORA.
- Regulation (EU) 909/2014 (CSDR): central securities depositories see their ICT obligations harmonised under DORA.
- Regulation (EU) 2016/1011 (BMR): benchmark administrators are affected by the consolidation.
- The Directive (EU) 2022/2556 aligns in parallel the sectoral directives (CRD, Solvency II, MiFID II, UCITS, AIFMD, PSD2, IORP II).
What this changes for your procedures
If your entity is both a CCP and a MiFIR service provider, you no longer apply two separate ICT frameworks: it is DORA, full stop. Your ICT risk management policies, resilience testing, third-party ICT register and incident procedure must be one unified documentary architecture, not a historical stack. The CSSF expects a mapping that demonstrates the migration from old sectoral references to the corresponding DORA articles.
How Luxgap automates this risk
Our Luxgap Regulatory Crosswalk Engine eliminates the silo-management risk by automatically building the correspondence map between your legacy sectoral ICT obligations (EMIR, MiFIR, CSDR, BMR, CRA) and the DORA articles that replace them. The AI agent reads your existing internal procedures hosted on SharePoint, Confluence or internal DMS, identifies every reference to a consolidated regulation and proposes the wording aligned with the new DORA framework.
- Automatically scans your internal documentary corpus and detects every mention of EMIR, MiFIR, CSDR, BMR or CRA in an ICT context.
- Generates an article-by-article transposition table mapping the old sectoral reference to the equivalent DORA article.
- Detects dual-management zones (ICT incident procedure written under EMIR plus another written under MiFIR) and proposes the merger under DORA.
- Produces a time-stamped PDF report enforceable during a CSSF inspection, demonstrating the overall consistency required by recital 102.
- Alerts in real time via Teams or Slack when a new version of a procedure is published without integrating the DORA transposition.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual procedures, with a free 48-hour white audit to measure your documentary exposure before any engagement.