Recital 54

Recital 54

Digital Operational Resilience Act · UE 2022/2554

(54)

This Regulation should require credit institutions, payment institutions, account information service providers and electronic money institutions to report all operational or security payment-related incidents – previously reported under Directive (EU) 2015/2366 – irrespective of the ICT nature of the incident.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the competent authority for both PSD2 reporting (transposed by the amended law of 10 November 2009 on payment services) and DORA reporting. The law of 1 August 2024 implementing the DORA regulation confirms the CSSF as the single window and requires operational consistency between both channels.

Luxgap practice: use the CSSF eDesk portal as the single submission reference and keep the timestamped filing proof of both notifications in a defensible digital vault.