Recital 21
Digital Operational Resilience Act · UE 2022/2554
| (21) | In order to maintain full control over ICT risk, financial entities need to have comprehensive capabilities to enable a strong and effective ICT risk management, as well as specific mechanisms and policies for handling all ICT-related incidents and for reporting major ICT-related incidents. Likewise, financial entities should have policies in place for the testing of ICT systems, controls and processes, as well as for managing ICT third-party risk. The digital operational resilience baseline for financial entities should be increased while also allowing for a proportionate application of requirements for certain financial entities, particularly microenterprises, as well as financial entities subject to a simplified ICT risk management framework. To facilitate an efficient supervision of institutions for occupational retirement provision that is proportionate and addresses the need to reduce administrative burdens on the competent authorities, the relevant national supervisory arrangements in respect of such financial entities should take into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations even when the relevant thresholds established in Article 5 of Directive (EU) 2016/2341 of the European Parliament and of the Council (10) are exceeded. In particular, supervisory activities should focus primarily on the need to address serious risks associated with the ICT risk management of a particular entity. Competent authorities should also maintain a vigilant but proportionate approach in relation to the supervision of institutions for occupational retirement provision which, in accordance with Article 31 of Directive (EU) 2016/2341, outsource a significant part of their core business, such as asset management, actuarial calculations, accounting and data management, to service providers. |
In Luxembourg, the CSSF is the sole competent authority for DORA over all regulated financial entities, with the CAA (Commissariat aux Assurances) for insurance, reinsurance undertakings and intermediaries. The law of 1 July 2024 implementing the DORA Regulation formally designates these authorities and activates administrative penalties (up to 1% of average daily worldwide turnover). For Luxembourg IORPs (ASSEP, SEPCAV), the CSSF applies the recital 21 proportionality principle taking into account the typical outsourcing model of the financial centre (central administration delegated to a support PSF).
Luxgap practice: for a Luxembourg IORP outsourcing its central administration to a support PSF, the simplified Article 16 DORA framework remains applicable, but the subcontracting chain towards the PSF must be mapped at the same level as a bank, since the PSF is itself a CSSF-regulated financial entity with its own cascading DORA obligations.