Recital 47

Recital 47

Digital Operational Resilience Act · UE 2022/2554

(47)

Inspired by relevant international, national and industry best practices, guidelines, recommendations and approaches to the management of cyber risk, this Regulation promotes a set of principles that facilitate the overall structure of ICT risk management. Consequently, as long as the main capabilities which financial entities put in place address the various functions in the ICT risk management (identification, protection and prevention, detection, response and recovery, learning and evolving and communication) set out in this Regulation, financial entities should remain free to use ICT risk management models that are differently framed or categorised.

Luxembourg specificity
circulaire CSSF 24/847 du 5 août 2024 relative à la notification des incidents TIC et de paiement

In Luxembourg, the CSSF has published circular CSSF 24/847 which specifies its expectations regarding ICT risk management and incident notification, in direct alignment with DORA. The circular confirms that entities may keep their existing framework (typically aligned with the now-repealed CSSF circular 20/750) provided they demonstrate correspondence with the six DORA functions. The CSSF requires a documented self-assessment to be kept available during on-site inspections.

Luxgap practice: prepare the correspondence matrix between your former 20/750 framework and DORA articles 5 to 14 now, it is the first document the CSSF will request during its next visit.