Recital 55

Recital 55

Digital Operational Resilience Act · UE 2022/2554

(55)

The ESAs should be tasked with assessing the feasibility and conditions for a possible centralisation of ICT-related incident reports at Union level. Such centralisation could consist of a single EU Hub for major ICT-related incident reporting either directly receiving relevant reports and automatically notifying national competent authorities, or merely centralising relevant reports forwarded by the national competent authorities and thus fulfilling a coordination role. The ESAs should be tasked with preparing, in consultation with the ECB and ENISA, a joint report exploring the feasibility of setting up a single EU Hub.

Luxembourg specificity
loi du 1er juillet 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA) et Circulaire CSSF 24/847

In Luxembourg, the CSSF is the DORA competent authority and has already clarified its expectations through CSSF Circular 24/847 of 5 June 2024 on the ICT incident notification framework for the financial sector, which operationally transposes DORA obligations. This circular sets out submission via the CSSF eDesk portal, pending the European decision on the EU Hub mentioned in this recital. The law of 1 July 2024 implementing the DORA Regulation designates the CSSF and the Commissariat aux assurances (CAA) as competent authorities depending on the entity type.

Luxgap practice: configure your notification orchestrator with CSSF eDesk as the current primary endpoint and a pivot connector to the future EU Hub, to avoid a full rebuild at switchover.