Recital 63

Recital 63

Digital Operational Resilience Act · UE 2022/2554

(63)

To address the complexity of the various sources of ICT risk, while taking into account the multitude and diversity of providers of technological solutions which enable a smooth provision of financial services, this Regulation should cover a wide range of ICT third-party service providers, including providers of cloud computing services, software, data analytics services and providers of data centre services. Similarly, since financial entities should effectively and coherently identify and manage all types of risk, including in the context of ICT services procured within a financial group, it should be clarified that undertakings which are part of a financial group and provide ICT services predominantly to their parent undertaking, or to subsidiaries or branches of their parent undertaking, as well as financial entities providing ICT services to other financial entities, should also be considered as ICT third-party service providers under this Regulation. Lastly, in light of the evolving payment services market becoming increasingly dependent on complex technical solutions, and in view of emerging types of payment services and payment-related solutions, participants in the payment services ecosystem, providing payment-processing activities, or operating payment infrastructures, should also be considered to be ICT third-party service providers under this Regulation, with the exception of central banks when operating payment or securities settlement systems, and public authorities when providing ICT related services in the context of fulfilling State functions.

Luxembourg specificity
loi luxembourgeoise du 1er août 2024 portant mise en oeuvre du règlement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the competent DORA authority for credit institutions, investment firms, PFS, EMIs, UCITS, AIFMs and IORPs, while the CAA covers insurance and reinsurance undertakings. The law of 1 August 2024 implementing DORA explicitly designates these two authorities and grants the CSSF on-site inspection powers over critical ICT third-party providers. Recital 63 carries particular weight in Luxembourg: the financial center relies heavily on intra-group providers (IT competence centers in Dublin, Warsaw, Bangalore) and on local operators (LuxConnect, eBRC, POST Telecom), all of which must appear in the register of information.

Luxgap practice: we systematically map cross-border intra-group ICT flows toward the group's IT hubs (often overlooked) and qualify each relationship against the CSSF circular 24/856 grid before the annual register of information filing.