The classic trap
Recital 20 creates a dual-supervision zone for hyperscalers (AWS, Azure, GCP, OVHcloud) and regional cloud providers (LuxConnect, eBRC, Proximus NXT): they are simultaneously digital infrastructure under NIS 2 and potentially critical ICT third-party service providers under DORA. The CSSF sanctions financial entities that assume an ISO 27001 certification or their cloud provider's NIS 2 compliance is enough to cover their DORA obligations. Both frameworks are complementary, not interchangeable.
Reading this recital as an interpretive guide to Articles 28 to 44
Concretely, this recital must guide your reading of DORA's operational articles:
- The fact that AWS is already supervised as digital infrastructure under NIS 2 does not exempt your bank or fund from registering it in the information register (Article 28(3)) with all its dependencies.
- The possible designation of a cloud provider as a critical ICT third-party service provider by the ESAs (Articles 31 to 33) adds a layer of direct European oversight, without removing the national NIS 2 supervision carried out by the ILR in Luxembourg.
- The mandatory contractual clauses of Article 30 must apply fully, even with hyperscalers imposing standardised T&Cs: the CSSF rejects the take-it-or-leave-it argument.
- Multi-vendor strategy and exit testing (Article 28(8)) become an explicit objective for cloud services supporting critical functions.
The cloud sub-outsourcing chain trap
A business SaaS (core banking, KYC, asset management) hosted on Azure creates a three-tier chain: financial entity -> SaaS vendor -> Microsoft. DORA requires transparency across the entire chain, including the actual data location and cloud sub-regions used. Standard SaaS vendor contracts often hide this information.
How Luxgap automates this risk
Our Luxgap Cloud Concentration Radar maps in real time the actual cloud exposure of your financial entity and detects the blind spots in the sub-outsourcing chain, where the risk team's Excel files stop at tier-1 providers. The tool queries directly your AWS Organizations accounts, Azure Tenant, GCP Resource Manager, your SSO (Okta, Entra ID) and your Odoo / SAP invoices to rebuild the full map of cloud dependencies, including SaaS services that silently re-host with a hyperscaler.
- Automatically detects each new cloud service activated in your AWS, Azure and GCP tenants and reconciles it with the Article 28(3) information register.
- Identifies business SaaS that re-host with a hyperscaler by cross-checking TLS certificates, DNS records and destination IPs observed from your Defender / Zscaler gateways.
- Calculates a concentration score per provider, per cloud region and per critical function, to materialise Article 29 risk before the next CSSF review.
- Alerts on hidden non-EU transfers (data replication to a US region, offshore technical support) triggered without a contractual amendment.
- Pre-fills the information register in the ITS EBA/ESMA/EIOPA format expected for the annual submission to the CSSF, with tamper-evident timestamping.
- Simulates the impact of an ESAs critical designation of one of your providers and prepares the Article 28(8) exit plan.
Available as part of a Luxgap CISO mandate or as a standalone SaaS module depending on your perimeter. Request your demonstration and our teams will prepare a free 48-hour white audit on your real cloud tenants, with a first concentration report delivered before any engagement.