The classic trap
Recital 62 sets the philosophy of DORA's Chapter V: this is not a one-shot check at contract signature, but a continuous monitoring of all ICT providers, with intensity proportionate to criticality. In practice, the CSSF sanctions financial entities that maintain a static register updated once a year, with no mechanism to detect changes (cascading subcontracting, location changes, certification expiry). The typical mistake is to concentrate 90% of the effort on the 5 'critical' contracts and leave a grey zone over the other 200 ICT dependencies which, cumulatively, carry a major concentration risk.
How to turn this recital into an operational mechanism
- Map all ICT dependencies, not only those supporting critical or important functions, in line with DORA Article 28(3).
- Differentiate monitoring intensity: enhanced due diligence and penetration testing for critical functions, lightweight but continuous monitoring for the rest.
- Automatically detect trigger events: change of control of the provider, public breach (HIBP, ransomware leak sites), ISO 27001 / SOC 2 / TISAX expiry, data relocation outside the EU.
- Document the full ICT subcontracting chain (Nth-tier subcontractors), required by DORA Article 30(2)(a) and the related CSSF RTS.
- Produce opposable evidence: register compliant with the DORA ITS template, signed and timestamped, ready for the annual CSSF submission.
How Luxgap automates this risk
Our Luxgap ICT Dependency Radar turns the declarative DORA register obligation into real-time surveillance of your ICT ecosystem. The tool connects to your internal sources (Active Directory, Azure AD, Microsoft Defender for Cloud Apps, AWS Cost Explorer, Odoo, Sage BOB 50, eBRC, DocuSign contracts) and continuously cross-references each flow with external signals (LU/EU business registries, Have I Been Pwned, ransomware leak sites, ISO/SOC certification databases). The result: a live radar where each ICT provider appears with its calculated criticality, up-to-date certifications, Nth-tier subcontractors and a predictive risk score.
- Automatically detects each new ICT provider as soon as a transaction, an SSO access or an API endpoint appears in your connected systems, with no form to fill.
- Classifies each dependency according to the DORA grid (critical or important function, mere support) based on observed business flows and the RTS published by the ESAs.
- Continuously monitors external signals (public breach, certification downgrade, OFAC sanction, change of capital control) and alerts on Teams or by email in less than 5 minutes.
- Maps the Nth-tier chain (your HR SaaS hosted on AWS Frankfurt relying on a US subcontractor) and identifies contractual transparency gaps.
- Computes a provider concentration score to detect systemic risk (e.g. 60% of your critical functions depend on the same hyperscaler).
- Generates the information register in DORA ITS format, timestamped and cryptographically sealed, ready for the annual CSSF submission.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real ICT ecosystem, with a free scan within 48h to measure your exposure before any commitment.