Recital 54
Digital Operational Resilience Act · UE 2022/2554
| (54) | This Regulation should require credit institutions, payment institutions, account information service providers and electronic money institutions to report all operational or security payment-related incidents – previously reported under Directive (EU) 2015/2366 – irrespective of the ICT nature of the incident. |
In Luxembourg, the CSSF is the competent authority for both PSD2 reporting (transposed by the amended law of 10 November 2009 on payment services) and DORA reporting. The law of 1 August 2024 implementing the DORA regulation confirms the CSSF as the single window and requires operational consistency between both channels.
Luxgap practice: use the CSSF eDesk portal as the single submission reference and keep the timestamped filing proof of both notifications in a defensible digital vault.