The classic trap
Recital 36 sets DORA's proportionality principle, but in practice the CSSF sanctions two opposite drifts. Small entities (insurance intermediaries, sub-threshold AIFMs, modest EMIs) invoke proportionality to do nothing and have neither ICT mapping nor documented continuity policy. On the other side, banking groups copy-paste the holding's framework into the Luxembourg subsidiary without local adaptation, ending up with a theoretical setup disconnected from real operations. The CSSF expects a written, quantified justification of your sizing, not a declaration of principle.
The proportionality test: 4 axes to document
To evidence proportionality (Article 4, derived from recital 36) before the CSSF, your file must demonstrate explicit calibration along four dimensions:
- Size: balance sheet, internal and outsourced ICT headcount, number of critical systems mapped, transaction volume processed.
- Overall risk profile: exposure to non-EU cloud services, single-vendor dependency, criticality of activities for the Luxembourg market.
- Nature and complexity: structured products, algorithmic trading, cross-border payment services, crypto custody, each raising the expected control intensity.
- Periodic review: the CSSF expects you to re-evidence this sizing at least annually, and at every material change (acquisition, new product, change of critical ICT provider).
The recurring mistake is to freeze the sizing at DORA go-live in 2025 and never revisit it. Recital 36 expressly states that competent authorities should continue to assess and review the approach, meaning the CSSF will challenge your calibration at every thematic inspection.
How Luxgap automates this risk
Our Luxgap Proportionality Compass turns the DORA proportionality argument, often reduced to a footnote, into a quantified, timestamped score defensible before the CSSF during an inspection. The tool continuously aggregates internal signals (ICT headcount via Workday or Sage BOB 50, balance sheet via your core banking, register of critical ICT providers) and external signals (CSSF entity classification, exposures reported to the ESAs) to compute a calibrated DORA expectation level, axis by axis.
- Computes an ICT complexity score on the four axes of recital 36 (size, risk, nature, complexity) with auditable weighting and documented formula.
- Benchmarks your score against a panel of comparable Luxembourg financial entities (private bank, CSSF fintech, AIFM, EMI) to flag suspicious under-sizing.
- Auto-generates the DORA Article 4 proportionality memo, ready to embed in your ICT risk management framework, with quantified justification of every relaxation or reinforcement.
- Detects review-triggering events (acquisition, new product, change of critical provider, threshold breach) and alerts management via Teams or email with an update recommendation.
- Produces a cryptographically sealed PDF report, defensible before the CSSF, evidencing the traceability of your calibration over time.
Available as part of a Luxgap CISO mandate or as a standalone SaaS module depending on your scope. Request a tailored quote and our team will prepare a demonstration on your real perimeter, with a free 48-hour blank audit to measure your current calibration before any commitment.