Recital 58
Digital Operational Resilience Act · UE 2022/2554
| (58) | To draw on the expertise already acquired by certain competent authorities, in particular with regard to implementing the TIBER-EU framework, this Regulation should allow Member States to designate a single public authority as responsible in the financial sector, at national level, for all TLPT matters, or competent authorities, to delegate, in the absence of such designation, the exercise of TLPT related tasks to another national financial competent authority. |
In Luxembourg, the CSSF is the competent authority for DORA in the financial sector and hosts the national TLPT Cyber Team that runs the TIBER-LU framework, derived from TIBER-EU. The law of 1 June 2023 implementing the DORA Regulation and CSSF circular 24/847 on ICT risk management clarify the scope of covered entities and the incident reporting regime, without designating an alternative TLPT authority: CSSF owns the topic end-to-end.
Luxgap practice: before any TLPT, we recommend a pre-engagement letter to the CSSF six months in advance, together with the TIBER-LU scoping document and the named list of third-party ICT providers involved, to avoid a scope rejection during the framing phase.