Recital 68
Digital Operational Resilience Act · UE 2022/2554
| (68) | To evaluate and monitor on a regular basis the ability of an ICT third party service provider to securely provide services to a financial entity without adverse effects on a financial entity’s digital operational resilience, several key contractual elements with ICT third-party service providers should be harmonised. Such harmonisation should cover minimum areas which are crucial for enabling a full monitoring by the financial entity of the risks that could emerge from the ICT third-party service provider, from the perspective of a financial entity’s need to secure its digital resilience because it is deeply dependent on the stability, functionality, availability and security of the ICT services received. |
In Luxembourg, the CSSF is the DORA competent authority for the entire financial sector, including support PFS (article 29-3 of the amended law of 5 April 1993). The law of 1 August 2024 implementing DORA specifies that the CSSF may require full disclosure of the ICT information register and trigger on-site inspections at subcontracted ICT providers, including outside Luxembourg. The CSSF also published Circular CSSF 24/847 on ICT risk management, which complements DORA at national level.
Luxgap practice: we prepare your ICT information register in the CSSF expected format (ESA taxonomy, LEI identifiers, critical functions classification) and keep it updated automatically via Luxgap Contract Harmonizer, ready for annual reporting submission.