Recital 30

Recital 30

Digital Operational Resilience Act · UE 2022/2554

(30)

A certain lack of homogeneity and convergence regarding the monitoring of ICT third-party risk and ICT third-party dependencies is evident today. Despite efforts to address outsourcing, such as EBA Guidelines on outsourcing of 2019 and ESMA Guidelines on outsourcing to cloud service providers of 2021 the broader issue of counteracting systemic risk which may be triggered by the financial sector’s exposure to a limited number of critical ICT third-party service providers is not sufficiently addressed by Union law. The lack of rules at Union level is compounded by the absence of national rules on mandates and tools that allow financial supervisors to acquire a good understanding of ICT third-party dependencies and to monitor adequately risks arising from the concentration of ICT third-party dependencies.

Luxembourg specificity
circulaire CSSF 22/806 du 22 avril 2022 relative aux arrangements d'externalisation

In Luxembourg, the CSSF is the competent authority designated under DORA for the whole financial sector (credit institutions, PFS, funds, insurance in coordination with the CAA). CSSF circular 22/806 on outsourcing arrangements, already in force, foreshadows DORA requirements and remains applicable as a complement: outsourcing register, prior notification of critical outsourcing, and concentration risk assessment. Since 2025, the CSSF expects a coherent integration between circular 22/806 and the DORA Article 28(3) information register.

Luxgap practice: we align your circular 22/806 outsourcing register and your DORA register in a single repository, to avoid the discrepancies that systematically trigger findings during CSSF inspections.