Recital 11

Recital 11

Digital Operational Resilience Act · UE 2022/2554

(11)

As the Single Rulebook has not been accompanied by a comprehensive ICT or operational risk framework, further harmonisation of key digital operational resilience requirements for all financial entities is required. The development of ICT capabilities and overall resilience by financial entities, based on those key requirements, with a view to withstanding operational outages, would help preserve the stability and integrity of the Union financial markets and thus contribute to ensuring a high level of protection of investors and consumers in the Union. Since this Regulation aims to contribute to the smooth functioning of the internal market, it should be based on the provisions of Article 114 of the Treaty on the Functioning of the European Union (TFEU) as interpreted in accordance with the consistent case law of the Court of Justice of the European Union (Court of Justice).

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the law of 1 August 2024 implementing the DORA regulation designates the CSSF and the Commissariat aux Assurances (CAA) as competent authorities depending on entity type, and amends the 1993 sectoral law to articulate DORA with the existing prudential framework. CSSF circulars 20/750 (ICT and security risk) and CSSF 22/806 (outsourcing) remain applicable in areas not covered by DORA, but lose their primacy as soon as a point is addressed by DORA or its RTS/ITS.

Luxgap practice: before any DORA programme, build a three-column articulation table (DORA requirement / existing CSSF circular clause / applicable rule); this is the first document the CSSF requests during a thematic visit.