The classic trap
Recital 38 introduces a governance asymmetry that many Luxembourg financial entities misread: not being a microenterprise within the meaning of DORA automatically triggers the obligation to set up more complex governance arrangements (dedicated function for supervising ICT third-party arrangements, three lines of defence model, internal audit of the ICT risk management framework). The CSSF checks during inspections whether the actual size of the entity justifies or not the lighter regime, and sanctions fintechs or PSFs that self-qualify as microenterprise while exceeding the regulation's thresholds.
The microenterprise test under DORA: what actually changes
A financial entity qualifies as a microenterprise under DORA only if it employs fewer than 10 persons AND has annual turnover or balance sheet below EUR 2 million (cross-reference to Recommendation 2003/361/EC). As soon as you exceed one of these thresholds, you fall into the full regime and must demonstrate:
- A dedicated control function for supervising ICT third-party arrangements, separate from IT operations, with mandate, resources and reporting line to the management body.
- A formalised ICT crisis management function with an escalation procedure tested at least annually.
- The three lines of defence model applied to ICT risk: business (1st), risk and compliance (2nd), internal audit (3rd).
- Explicit inclusion of the ICT risk management framework in the multi-year internal audit plan, with documented audit trail.
- A written ICT risk management policy approved by the management body and reviewed at least annually (Article 5 DORA).
The most frequent trap in Luxembourg concerns EMIs, support PSFs and mid-sized AIFMs that think they benefit from a lighter regime because they are small, while their balance sheet exceeds EUR 2 million. The CSSF requalifies and imposes retroactive compliance with a tight timeline.
How Luxgap automates this risk
Our Luxgap DORA Governance Mapper removes ambiguity on your applicable regime and materialises the ICT governance expected by the CSSF before it comes to check it. The tool queries your HR systems (Sopra HR Suite, Workday LU, SD Worx), your financial statements (Sage BOB 50, Cegid Quadra, Odoo Finance) and your risk repository to qualify your DORA status in real time, then maps each missing governance requirement against the three lines of defence model.
- Continuously computes your eligibility for the DORA microenterprise regime by cross-referencing payroll headcount, turnover and total balance sheet, and alerts as soon as a threshold is crossed to anticipate the regime shift.
- Automatically maps your existing control functions against the three lines of defence model and identifies segregation breaches (e.g. same person manages ICT contracts and controls them).
- Generates the charters for the ICT third-party supervision and ICT crisis management functions tailored to your size, with mandate, KPIs and reporting lines ready to be approved by the management body.
- Integrates your ICT risk management framework into a multi-year internal audit plan compliant with Article 6(6) DORA, with a timestamped audit trail.
- Produces a cryptographically sealed PDF report, admissible during a CSSF inspection, demonstrating the consistency between your actual size and the sophistication of your ICT governance.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free 48-hour blank audit to qualify your DORA status and measure the governance gap before any commitment.