Recital 19

Recital 19

Digital Operational Resilience Act · UE 2022/2554

(19)

Given the strong interlinkages between the digital resilience and the physical resilience of financial entities, a coherent approach with regard to the resilience of critical entities is necessary in this Regulation and Directive (EU) 2022/2557 of the European Parliament and the Council (9). Given that the physical resilience of financial entities is addressed in a comprehensive manner by the ICT risk management and reporting obligations covered by this Regulation, the obligations laid down in Chapters III and IV of Directive (EU) 2022/2557 should not apply to financial entities falling within the scope of that Directive.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 relative a la mise en oeuvre du reglement DORA

In Luxembourg, the law of 1 August 2024 designating the competent authorities for DORA entrusts the CSSF and the CAA with the supervision of digital operational resilience depending on the type of financial entity. The Luxembourg transposition of the CER Directive (EU 2022/2557) follows a separate timeline but expressly recognises the exclusion of financial entities for Chapters III and IV, consistent with recital 19.

Luxgap practice: for mixed entities (groups with both CSSF-regulated financial activities and industrial or energy activities under HCPN scope), we clearly segment the DORA perimeter and the CER perimeter within a single governance file to avoid grey areas during a joint inspection.