The classic trap
This recital traces DORA back to its origin: a joint technical advice from the three ESAs (EBA, EIOPA, ESMA) calling for a coherent and proportionate approach to ICT risk. In practice, the CSSF uses this intent to reject a la carte approaches: a Luxembourg private bank cannot invent its own in-house framework while ignoring the regulatory technical standards (RTS) published by the ESAs. The classic trap is to treat DORA as an isolated IT project, disconnected from the EBA/EIOPA/ESMA guidelines already in force (EBA guidelines on outsourcing, EBA guidelines on ICT and security risk management), when DORA consolidates and makes them binding.
Proportionality: a double-edged sword
Recital 7 insists on the proportionate nature of the reinforcement. This proportionality (reflected in Article 4 of DORA) is often misread:
- It does not exempt any financial entity from the core obligations (ICT governance, third-party register, major incident management, resilience testing).
- It modulates the intensity of controls based on size, risk profile, nature and complexity of services, but not their existence.
- Microenterprises benefit from an explicit simplified regime (Article 16), but a 20-person CSSF-regulated fintech remains fully subject to the baseline.
- The CSSF expects a documented justification for every proportionality trade-off: without a written file, the argument collapses during inspection.
Articulation with pre-existing sectoral guidelines
Before rewriting your DORA policies, map what you already apply: EBA/GL/2019/02 on outsourcing, EBA/GL/2019/04 on ICT risk management, CSSF circular 22/806 on outsourcing arrangements, CSSF circular 20/750 on ICT and security risk. DORA absorbs and tightens these texts: mapping your current compliance to DORA articles prevents doing the same work twice.
How Luxgap automates this risk
Our Luxgap DORA Proportionality Engine turns declarative proportionality into a CSSF-defensible argument. The tool ingests your balance sheet, your risk appetite statement, your IT mapping and your outsourcing contracts from connected systems (Sage BOB 50, M365, Active Directory, internal registers), then calculates for each DORA requirement the expected level of application with its legal reasoning, cross-referencing DORA, the RTS published by the ESAs and CSSF circulars.
- Automatically classifies your entity (microenterprise, small non-interconnected entity, standard entity, significant entity) according to Article 16 and RTS criteria, with monthly recalculation whenever an indicator changes.
- Maps each existing ICT policy (CSSF circular 20/750, EBA/GL/2019/04, ISO 27001) to the corresponding DORA article and detects gaps to close.
- Generates a proportionality memo per requirement, electronically signed, justifying each trade-off with citations to DORA recitals and articles.
- Alerts in real time when a new RTS or ITS is published in the OJEU and impacts your proportionality file.
- Produces a timestamped, cryptographically sealed PDF file handed to the CSSF during on-site inspections to demonstrate coherence with the European legislator's intent.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your actual mapping, with a free white audit within 48h to measure your exposure before any commitment.