Recital 24

Recital 24

Digital Operational Resilience Act · UE 2022/2554

(24)

To enable competent authorities to fulfil supervisory roles by acquiring a complete overview of the nature, frequency, significance and impact of ICT-related incidents and to enhance the exchange of information between relevant public authorities, including law enforcement authorities and resolution authorities, this Regulation should lay down a robust ICT-related incident reporting regime whereby the relevant requirements address current gaps in financial services law, and remove existing overlaps and duplications to alleviate costs. It is essential to harmonise the ICT-related incident reporting regime by requiring all financial entities to report to their competent authorities through a single streamlined framework as set out in this Regulation. In addition, the ESAs should be empowered to further specify relevant elements for the ICT-related incident reporting framework, such as taxonomy, timeframes, data sets, templates and applicable thresholds. To ensure full consistency with Directive (EU) 2022/2555, financial entities should be allowed, on a voluntary basis, to notify significant cyber threats to the relevant competent authority, when they consider that the cyber threat is of relevance to the financial system, service users or clients.

Luxembourg specificity
Circulaire CSSF 24/847 du 5 aout 2024 relative aux exigences de notification des incidents TIC, alignee sur DORA

In Luxembourg, the CSSF is the DORA competent authority for almost all financial entities (banks, PFS, funds, managers, payment institutions, EMIs), and the CAA for insurance and reinsurance undertakings. CSSF Circular 24/847 already sets out the national ICT incident reporting framework and has been aligned with DORA since 17 January 2025: it requires an initial notification within 4 business hours after classification of a major incident, an intermediate report and a final report, via the CSSF eDesk portal.

Luxgap practice: we configure the Incident Reporting Orchestrator with the native CSSF eDesk connector and automatic dual CSSF + CNPD notification where personal data is affected, to comply with Circular 24/847 and GDPR Article 33 simultaneously without double entry.