Recital 38

Recital 38

Digital Operational Resilience Act · UE 2022/2554

(38)

As larger financial entities might enjoy wider resources and can swiftly deploy funds to develop governance structures and set up various corporate strategies, only financial entities that are not microenterprises in the sense of this Regulation should be required to establish more complex governance arrangements. Such entities are better equipped in particular to set up dedicated management functions for supervising arrangements with ICT third-party service providers or for dealing with crisis management, to organise their ICT risk management according to the three lines of defence model, or to set up an internal risk management and control model, and to submit their ICT risk management framework to internal audits.

Luxembourg specificity
loi luxembourgeoise du 1er juin 2023 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the competent authority for DORA across all regulated financial entities (credit institutions, PFS, EMIs, payment institutions, AIFMs, UCITS, insurance undertakings via the CAA for the insurance sector). The law of 1 June 2023 implementing DORA explicitly designates the CSSF and the CAA as supervisory authorities and confirms application of the microenterprise test within the meaning of the regulation, with no more favourable national threshold. The CSSF has published its CSSF Circular 24/847 on ICT incident reporting, which articulates with the governance requirements of recital 38.

Luxgap practice: for Luxembourg support PFS and EMIs approaching the EUR 2 million balance sheet threshold, we recommend anticipating the regime shift at least 6 months before the projected crossing, because the CSSF requires an operational governance framework from the moment the threshold is exceeded, not afterwards.