Recital 105

Recital 105

Digital Operational Resilience Act · UE 2022/2554

(105)

Since the objective of this Regulation, namely to achieve a high level of digital operational resilience for regulated financial entities, cannot be sufficiently achieved by the Member States because it requires harmonisation of various different rules in Union and national law, but can rather, by reason of its scale and effects, be better achieved at Union level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the designated competent authority for DORA supervision of financial entities within its scope (banks, PFS, funds, managers, payment institutions and EMIs), and the CAA for insurance and reinsurance undertakings. The Law of 1 August 2024 implementing the DORA Regulation designates national competent authorities and adapts CSSF/CAA sanction powers, without creating additional substantive obligations: the EU text applies in full.

Luxgap practice: for groups established in Luxembourg, align your third-party register of information with the ITS format expected by the CSSF from the very first annual reporting, including LU sovereign hosters (LuxConnect, eBRC, POST) with their documented criticality qualification.