Recital 16

Recital 16

Digital Operational Resilience Act · UE 2022/2554

(16)

However, as this Regulation increases the level of harmonisation of the various digital resilience components, by introducing requirements on ICT risk management and ICT-related incident reporting that are more stringent in comparison to those laid down in the current Union financial services law, this higher level constitutes an increased harmonisation also in comparison with the requirements laid down in Directive (EU) 2022/2555. Consequently, this Regulation constitutes lex specialis with regard to Directive (EU) 2022/2555. At the same time, it is crucial to maintain a strong relationship between the financial sector and the Union horizontal cybersecurity framework as currently laid out in Directive (EU) 2022/2555 to ensure consistency with the cyber security strategies adopted by Member States and to allow financial supervisors to be made aware of cyber incidents affecting other sectors covered by that Directive.

Luxembourg specificity
loi du 26 juillet 2023 portant transposition de la directive (UE) 2022/2555 (NIS 2)

In Luxembourg, the CSSF is the competent DORA authority for financial entities, while the HCPN (High Commission for National Protection) and ILR coordinate NIS 2 via the law of 26 July 2023 transposing the NIS 2 directive. Recital 16 concretely implies that your major ICT incidents are notified through the CSSF portal (eDesk) and not through the generic CSIRT procedure, except for cross-sector incidents.

Luxgap practice: we wire your incident playbook to automatically trigger the CSSF notification (initial 4h, intermediate 72h, final 1 month deadlines) and inform GOVCERT.LU in parallel when the incident affects a transverse essential service.