Recital 23

Recital 23

Digital Operational Resilience Act · UE 2022/2554

(23)

To reduce the administrative burden and potentially duplicative reporting obligations for certain financial entities, the requirement for the incident reporting pursuant to Directive (EU) 2015/2366 of the European Parliament and of the Council (12) should cease to apply to payment service providers that fall within the scope of this Regulation. Consequently, credit institutions, e-money institutions, payment institutions and account information service providers, as referred to in Article 33(1) of that Directive, should, from the date of application of this Regulation, report pursuant to this Regulation, all operational or security payment-related incidents which have been previously reported pursuant to that Directive, irrespective of whether such incidents are ICT-related.

Luxembourg specificity
loi du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA) et circulaire CSSF 24/847

In Luxembourg, the CSSF is the single competent authority for receiving DORA notifications from PSPs established in the country. The law of 1 August 2024 implementing the DORA Regulation and CSSF Circular 24/847 (incident reporting framework) specify that the CSSF eDesk portal becomes the exclusive channel from 17 January 2025, replacing the former PSD2 setup (CSSF Circular 21/787 as amended). EMIs and PIs authorised under the amended law of 10 November 2009 on payment services switch in full.

Luxgap practice: we reconfigure your escalation matrix to point to CSSF eDesk with DORA thresholds and we archive a signed migration attestation, enforceable during the next CSSF on-site inspection.