The classic trap
This recital signals a major legislative consolidation: DORA absorbs the digital operational resilience provisions scattered across five sectoral regulations (credit rating agencies, EMIR, MiFIR, CSDR, benchmarks). In practice, the CSSF already sanctions financial entities that keep steering their ICT risk by referring solely to the old sectoral regulations, without having performed the mapping exercise between the legacy framework and the new DORA obligations. The trap is to believe that EMIR or MiFIR compliance equals DORA compliance.
The overlaps that must be traced
- Regulation (EC) 1060/2009 (CRA): business continuity requirements for rating agencies, now under DORA.
- Regulation (EU) 648/2012 (EMIR): ICT obligations for CCPs and trade repositories, carried over to DORA.
- Regulation (EU) 600/2014 (MiFIR): operational requirements for APAs, ARMs and CTPs.
- Regulation (EU) 909/2014 (CSDR): operational continuity for central securities depositories.
- Regulation (EU) 2016/1011 (BMR): operational robustness of benchmark administrators.
- All delegated and implementing acts adopted on these legal bases must be re-read against DORA to identify overlap, tacit repeal or coexistence zones.
The cross-compliance test
For each article of your internal regulatory mapping derived from one of these five regulations, the question becomes: is this obligation now governed by DORA, or does it retain a standalone existence? A wrong answer leads to two symmetric risks: costly over-compliance (you enforce the same requirement twice) or sanctionable under-compliance (you assume the legacy provision still applies when it has been absorbed).
How Luxgap automates this risk
Our Luxgap Regulatory Crosswalk Engine eliminates the grey zone between the legacy sectoral framework and DORA by automatically building the article-by-article, requirement-by-requirement correspondence matrix. The tool ingests your existing regulatory mapping (Confluence extracts, SharePoint, GRC platforms such as ServiceNow, MetricStream or Archer) and cross-references each ICT obligation inherited from EMIR, MiFIR, CSDR, CRA or BMR with the matching DORA article, backed by the RTS published by the ESAs.
- Detects in your internal control library every obligation stemming from the five sectoral regulations referenced by recital 103.
- Classifies each requirement as transferred to DORA, retained in the sectoral regulation or duplicated, with citation of the applicable RTS or DORA article.
- Alerts via Teams or Slack connector when a newly published DORA RTS changes the status of an already mapped requirement.
- Produces a timestamped PDF report enforceable before the CSSF during an operational resilience thematic inspection, demonstrating mastery of the regulatory transfer.
- Synchronises obsolete controls back into your GRC to avoid costly over-compliance and free up internal audit budget.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual regulatory mapping, with a free 48-hour blank audit to measure your exposure to DORA overlaps before any engagement.