Recital 14

Recital 14

Digital Operational Resilience Act · UE 2022/2554

(14)

A Regulation helps reduce regulatory complexity, fosters supervisory convergence and increases legal certainty, and also contributes to limiting compliance costs, especially for financial entities operating across borders, and to reducing competitive distortions. Therefore, the choice of a Regulation for the establishment of a common framework for the digital operational resilience of financial entities is the most appropriate way to guarantee a homogenous and coherent application of all components of ICT risk management by the Union financial sector.

Luxembourg specificity
loi luxembourgeoise du 1er août 2024 portant mise en oeuvre du règlement (UE) 2022/2554 (DORA)

In Luxembourg, the law of 1 August 2024 implementing the DORA regulation designates the CSSF and the CAA as competent authorities depending on the type of financial entity, and confirms that prior CSSF circulars (notably CSSF 20/750 on ICT governance and CSSF 22/806 on outsourcing arrangements) articulate around DORA without being able to derogate from it. The law also specifies the administrative sanctions regime applicable on Luxembourg territory.

Luxgap practice: for CSSF-regulated entities, we systematically remap your existing ICT framework aligned with CSSF 20/750 and 22/806 to DORA articles, identifying the new requirements (information register Article 28, TLPT testing Article 26) that the circulars did not cover.