Recital 64

Recital 64

Digital Operational Resilience Act · UE 2022/2554

(64)

A financial entity should at all times remain fully responsible for complying with its obligations set out in this Regulation. Financial entities should apply a proportionate approach to the monitoring of risks emerging at the level of the ICT third-party service providers, by duly considering the nature, scale, complexity and importance of their ICT-related dependencies, the criticality or importance of the services, processes or functions subject to the contractual arrangements and, ultimately, on the basis of a careful assessment of any potential impact on the continuity and quality of financial services at individual and at group level, as appropriate.

Luxembourg specificity
circulaire CSSF 24/847 du 5 avril 2024 relative au cadre de gestion des risques TIC et au signalement des incidents majeurs lies aux TIC

In Luxembourg, the CSSF has integrated DORA into its supervisory framework via CSSF circular 24/847 on ICT risk management and incident reporting, which extends and partially replaces circular 22/806 on outsourcing. The CSSF expects an up-to-date ICT vendor map, available on demand, with an explicit distinction between critical or important functions (CIF) and non-critical functions.

Luxgap practice: we calibrate the proportionality scoring directly on the CSSF grid (CIF / non-CIF + cloud outsourcing) so that your reports are immediately usable during an on-site inspection or an ad hoc request from the prudential supervision department.