Recital 20

Recital 20

Digital Operational Resilience Act · UE 2022/2554

(20)

Cloud computing service providers are one category of digital infrastructure covered by Directive (EU) 2022/2555. The Union Oversight Framework (‘Oversight Framework’) established by this Regulation applies to all critical ICT third-party service providers, including cloud computing service providers providing ICT services to financial entities, and should be considered complementary to the supervision carried out pursuant to Directive (EU) 2022/2555. Moreover, the Oversight Framework established by this Regulation should cover cloud computing service providers in the absence of a Union horizontal framework establishing a digital oversight authority.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant transposition de la directive (UE) 2022/2555 (NIS 2)

In Luxembourg, the CSSF supervises DORA application for the financial sector, while the ILR (Luxembourg Regulatory Institute) supervises cloud providers designated as digital infrastructure under NIS 2. The Law of 1 August 2024 transposing NIS 2 explicitly designates the ILR as the competent authority for cloud computing service providers established in Luxembourg, which includes key local players (LuxConnect, eBRC, Proximus NXT, EBRC). A Luxembourg financial entity using a LU cloud must therefore manage two distinct authority counterparts.

Luxgap practice: build an authority x provider x framework matrix that clarifies for each cloud service which authority (CSSF on the financial entity side, ILR on the provider side, ESAs in case of critical designation) will intervene in case of incident, and synchronise your notification deadlines between DORA Article 19 and Article 23 of the LU NIS 2 law.