Recital 52
Digital Operational Resilience Act · UE 2022/2554
| (52) | The direct reporting should enable financial supervisors to have immediate access to information about major ICT-related incidents. Financial supervisors should in turn pass on details of major ICT-related incidents to public non-financial authorities (such as competent authorities and single points of contact under Directive (EU) 2022/2555, national data protection authorities, and to law enforcement authorities for major ICT-related incidents of a criminal nature) in order to enhance such authorities awareness of such incidents and, in the case of CSIRTs, to facilitate prompt assistance that may be given to financial entities, as appropriate. Member States should, in addition, be able to determine that financial entities themselves should provide such information to public authorities outside the financial services area. Those information flows should allow financial entities to swiftly benefit from any relevant technical input, advice about remedies, and subsequent follow-up from such authorities. The information on major ICT-related incidents should be mutually channelled: financial supervisors should provide all necessary feedback or guidance to the financial entity, while the ESAs should share anonymised data on cyber threats and vulnerabilities relating to an incident, to aid wider collective defence. |
In Luxembourg, the designated financial supervisor under DORA is the CSSF, with the CAA for insurance entities. The NIS 2 transposition via the law of 28 May 2025 and the law appointing the ILR as competent NIS 2 authority require that GOVCERT.LU and CIRCL (private CSIRT) receive major incident information when the financial entity also qualifies as essential or important under NIS 2. The CSSF published its Circular CSSF 24/847 on ICT incident reporting, detailing eDesk channels and practical procedures.
Luxgap practice: map in advance whether your entity falls under both DORA and NIS 2 (a frequent case for large banks and support PFS), since dual notification to the CSSF and to the ILR/GOVCERT.LU then applies, with distinct deadlines and formats to be orchestrated simultaneously.