Recital 102

Recital 102

Digital Operational Resilience Act · UE 2022/2554

(102)

Since this Regulation, together with Directive (EU) 2022/2556 of the European Parliament and of the Council (27), entails a consolidation of the ICT risk management provisions across multiple regulations and directives of the Union’s financial services acquis, including Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014 and (EU) No 909/2014, and Regulation (EU) 2016/1011 of the European Parliament and of the Council (28), in order to ensure full consistency, those Regulations should be amended to clarify that the applicable ICT risk-related provisions are laid down in this Regulation.

Luxembourg specificity
loi luxembourgeoise du 1er juin 2023 portant mise en oeuvre du reglement DORA et circulaire CSSF associee

In Luxembourg, the CSSF is the single competent authority for supervising DORA implementation for credit institutions, investment firms, AIFMs, UCITS managers, PFS and payment institutions. The law of 1 June 2023 implementing the DORA Regulation and the related CSSF circular specify that entities must submit their ICT third-party register using the harmonised ESAs format, replacing the scattered reporting obligations under legacy CSSF circulars 20/750 and 22/806.

Luxgap practice: we prepare your documentary transposition file by explicitly mapping every reference from legacy CSSF circulars to the corresponding DORA articles, anticipating the typical CSSF inspection question on overall consistency.