Recital 36

Recital 36

Digital Operational Resilience Act · UE 2022/2554

(36)

Notwithstanding the broad coverage envisaged by this Regulation, the application of the digital operational resilience rules should take into account the significant differences between financial entities in terms of their size and overall risk profile. As a general principle, when distributing resources and capabilities for the implementation of the ICT risk management framework, financial entities should duly balance their ICT-related needs to their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations, while competent authorities should continue to assess and review the approach of such distribution.

Luxembourg specificity
Circulaire CSSF 24/847 du 5 avril 2024 relative au cadre de notification des incidents lies aux TIC

In Luxembourg, the CSSF embedded DORA proportionality into CSSF Circular 24/847 on ICT risk management and incident reporting, specifying expectations per supervised entity category. Support PFS, EMIs and small investment firms benefit from documented alleviations but must still provide an ICT mapping and a continuity policy, even simplified.

Luxgap practice: for CSSF-supervised entities, we calibrate the Proportionality Compass on the Circular 24/847 grid and cross-reference your CSSF classification (bank, PFS, EMI, AIFM) to produce a proportionality memo directly aligned with the Luxembourg supervisor's expectations.