Recital 49

Recital 49

Digital Operational Resilience Act · UE 2022/2554

(49)

Efficient business continuity and recovery plans are necessary to allow financial entities to promptly and quickly resolve ICT-related incidents, in particular cyber-attacks, by limiting damage and giving priority to the resumption of activities and recovery actions in accordance with their back-up policies. However, such resumption should in no way jeopardise the integrity and security of the network and information systems or the availability, authenticity, integrity or confidentiality of data.

Luxembourg specificity
loi du 17 fevrier 2025 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA), circulaires CSSF 22/806 et 24/847

In Luxembourg, the CSSF imposes through CSSF circular 22/806 on ICT outsourcing and CSSF circular 24/847 on ICT incident reporting an operational framework that refines recital 49: any major ICT incident must be notified to the CSSF using a standardised template, and DRP tests must be documented annually with execution evidence. The law of 17 February 2025 implementing DORA designates the CSSF and the CAA as competent authorities depending on the type of financial entity.

Luxgap practice: for support PFS and CSSF-supervised entities, we calibrate the Recovery Drill Orchestrator on the exact templates of circulars 22/806 and 24/847, and pre-fill CSSF eDesk notifications to reduce reporting time below 4 hours.