The classic trap
Financial entities often believe they must stack DORA obligations on top of the CER Directive (EU 2022/2557) on the resilience of critical entities. The result: duplicated mapping, duplicated continuity plans, duplicated notifications, and inconsistency between the physical security team and the ICT team. The CSSF expects the opposite: a single integrated framework where physical resilience of sites (datacenters, trading floors, branches) is handled under DORA, not in a CER silo.
The DORA / CER articulation in practice
- Chapters III (resilience measures) and IV (incident reporting) of the CER Directive do NOT apply to financial entities within DORA's scope: DORA as lex specialis absorbs these obligations.
- However, the qualification as a critical entity under CER may still apply for other purposes (national identification, cross-border cooperation).
- Physical resilience (access, power, cooling, geographic redundancy of datacenters) must be integrated into the ICT risk management framework of DORA article 6, not handled in a separate plan.
- Advanced threat-led penetration tests (TLPT) must include credible physical components: primary datacenter outage, physical intrusion, cable sabotage.
- Governance must avoid duality: one resilience committee, one incident register, one CSSF reporting chain.
Why this matters for Luxembourg market participants
A Luxembourg private bank, a CSSF-regulated fintech or an AIFM hosts its critical systems at LuxConnect, eBRC or in sovereign cloud. The physical continuity of these infrastructures (Tier IV, N+1 redundancy, geographically separated sites) must be documented within your DORA framework, not in a parallel CER binder. The CSSF will read a single file.
How Luxgap automates this risk
Our Luxgap Resilience Convergence Hub merges your DORA obligations and the residual CER requirements into one single framework, and eliminates the physical / digital duality that makes most CSSF files fail. The tool continuously maps your physical dependencies (LuxConnect / eBRC datacenters, POST / Creos power suppliers, backup sites) and digital dependencies (M365, Azure, AWS, critical SaaS providers) by leveraging your Odoo contracts, supplier invoices and Defender / Sentinel configurations.
- Automatically detects the physical components of your ICT chain (primary datacenter, secondary, telecom, energy) and links them to the DORA article 28 register of information.
- Computes a geographic redundancy score per critical asset by crossing datacenter geolocation, contractual RTO / RPO and Tier Uptime Institute certifications.
- Generates the hybrid TLPT scenarios (cyber + physical) expected by the CSSF: datacenter outage, physical intrusion, cross-border fiber sabotage LU-DE-BE.
- Alerts in real time via Teams or Slack when an infrastructure supplier loses an ISO 22301 / Tier certification or suffers a public incident referenced on HIBP / OSINT sources.
- Produces a cryptographically sealed time-stamped PDF report, enforceable before the CSSF, demonstrating the absorption of CER obligations into the DORA framework and avoiding the dual reporting burden.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual infrastructure mapping, with a free 48h white audit to measure your convergent exposure before any commitment.