Luxgap coverage GDPR NIS 2 DORA AI Act Whistleblowing CSSF 22/806
Recital 36

Recital 36

Digital Operational Resilience Act · UE 2022/2554

(36)

Notwithstanding the broad coverage envisaged by this Regulation, the application of the digital operational resilience rules should take into account the significant differences between financial entities in terms of their size and overall risk profile. As a general principle, when distributing resources and capabilities for the implementation of the ICT risk management framework, financial entities should duly balance their ICT-related needs to their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations, while competent authorities should continue to assess and review the approach of such distribution.