The classic trap
Recital 13 sets the principle-based proportionality rule: same framework for all, calibrated to size and risk profile. The CSSF sanctions two opposite drifts. On one side, the regulated fintech that invokes its small size to neglect basic hygiene (MFA, patching, tested backups). On the other, the small AIFM that copy-pastes a tier-1 bank's framework, produces 400 pages of unworkable procedures, and fails the first inspection because nothing is actually operated. Proportionality is not an excuse, it is an auditable calibration duty.
The proportionality test: how to defend your calibration before the CSSF
A proportionate DORA framework must withstand scrutiny on three auditable axes:
- Size and overall risk profile: client base, assets under management, transaction volumes, cross-border exposure, systemic criticality.
- Nature and complexity of services: high-frequency execution vs. discretionary management, cloud-native vs. on-premise core banking, critical third-party dependencies.
- Non-negotiable basic cyber hygiene: even an 8-person EMI must demonstrate generalised MFA, patch management, regularly restored backups, centralised logging, awareness training. These fundamentals do not scale down, they apply universally.
How Luxgap automates this risk
Our Luxgap Proportionality Compass turns the justification of your DORA calibration into evidence opposable to the CSSF, generated automatically rather than drafted in panic before an inspection. The tool ingests your real profile (AUM, transactions, IT headcount, ICT vendor register, cloud footprint) from Sage BOB 50, your core systems and Microsoft Defender, then confronts it with DORA requirements to produce a defensible article-by-article calibration.
- Computes an overall risk profile score weighted on CSSF criteria (size, complexity, interconnection, criticality of ICT services) and automatically recalibrates it each quarter.
- Verifies in real time the presence of non-negotiable basic hygiene controls (generalised MFA via Azure AD, patching via Intune, tested backups via Veeam or Rubrik, deployed EDR) and alerts on any regression.
- Generates an article-by-article proportionality matrix that justifies each calibration choice with the underlying factual data.
- Automatically detects over-engineered controls (procedures never executed, committees never convened) and under-engineered controls relative to the actual profile.
- Produces a timestamped, cryptographically sealed PDF report, opposable to the CSSF, demonstrating consistency between your calibration and your effective risk profile.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual perimeter, with a free 48-hour blind audit to measure the gap between your current framework and a defensible DORA calibration.