The classic trap
Many Luxembourg financial entities believe that the model freedom offered by recital 47 allows them to keep their existing ICT risk management framework as is (often based on ISO 27005, NIST CSF or COBIT). A frequent mistake sanctioned by the CSSF during on-site inspections: the in-house model does not explicitly cover the six DORA functions (identification, protection and prevention, detection, response and recovery, learning and evolving, communication). Recital 47 is not a blank cheque: it is a conditional authorisation to reuse your framework, provided you demonstrate a mapping correspondence between your internal processes and the requirements of articles 5 to 14 of the Regulation.
The correspondence test: what the CSSF actually checks
When a CSSF inspector arrives, they do not ask you to throw away your NIST baseline. They ask you to prove that each DORA requirement is traceable within your model. The six control points:
- Identification: ICT asset inventory, classification, dependency mapping (art. 8 DORA).
- Protection and prevention: security policies, access management, encryption, segmentation (art. 9).
- Detection: continuous monitoring mechanisms, alert thresholds, SOC or MSSP (art. 10).
- Response and recovery: ICT continuity plans, RTO/RPO, restoration testing (art. 11 and 12).
- Learning and evolving: post-incident analysis, risk register updates (art. 13).
- Communication: internal, client and CSSF crisis communication plan (art. 14).
If even one of these six pillars is not explicitly addressed, your model freedom collapses and you are non-compliant, regardless of the actual quality of your setup.
How Luxgap automates this risk
Our Luxgap DORA Framework Mapper eliminates the grey zone of recital 47 by automatically producing the correspondence matrix between your existing ICT framework (ISO 27001, NIST CSF, COBIT, FFIEC, in-house framework) and the six DORA functions required by articles 5 to 14. The tool ingests your policies, procedures and risk registers from SharePoint, Confluence, GRC tools (ServiceNow GRC, Archer, OneTrust) and confronts them with the DORA baseline via a specialised LLM agent trained on the RTS and ITS published by the ESAs.
- Analyses your existing ICT policy documents and automatically detects which DORA function each procedure covers, with a completeness score per article (5 to 14).
- Identifies blind spots where your in-house framework does not explicitly cover a DORA requirement (typically the learning and evolving function and the communication function, often absent from classic NIST frameworks).
- Generates the official correspondence matrix ready to present to the CSSF, in Excel and timestamped PDF format, demonstrating that your alternative model complies with the principles of recital 47.
- Proposes procedure templates to integrate in order to fill detected gaps, broken down by entity type (bank, fund, PSF, insurance, intermediary).
- Refreshes the matrix automatically each time your internal policies are updated or whenever a new RTS is published by the EBA, ESMA or EIOPA.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS brick depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your actual ICT framework, with a free 48h white audit to measure your level of correspondence with the six DORA functions before any commitment.