Recital 39
Digital Operational Resilience Act · UE 2022/2554
| (39) | Some financial entities benefit from exemptions or are subject to a very light regulatory framework under the relevant sector-specific Union law. Such financial entities include managers of alternative investment funds referred to in Article 3(2) of Directive 2011/61/EU of the European Parliament and of the Council (16), insurance and reinsurance undertakings referred to in Article 4 of Directive 2009/138/EC of the European Parliament and of the Council (17), and institutions for occupational retirement provision which operate pension schemes which together do not have more than 15 members in total. In light of those exemptions it would not be proportionate to include such financial entities in the scope of this Regulation. In addition, this Regulation acknowledges the specificities of the insurance intermediation market structure, with the result that insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries qualifying as microenterprises or as small or medium-sized enterprises should not be subject to this Regulation. |
In Luxembourg, the CSSF is the competent DORA authority for the financial entities listed in Article 2, and the CAA remains competent for insurance undertakings and insurance intermediaries. The Luxembourg law of 1 August 2024 implementing DORA explicitly designates the CSSF and the CAA as supervisory and sanctioning authorities, and clarifies that entities exempted under Recital 39 remain subject to the national ICT requirements set out in CSSF Circular 22/806 on outsourcing and CAA Circular 22/15 on governance.
Luxgap practice: even when exempt from DORA, a Luxembourg-regulated entity must produce an annual ICT compliance file opposable to its supervisory authority. We systematically embed CSSF 22/806 and CAA 22/15 requirements into the Scope Verifier to avoid the false-exemption trap.