Recital 7

Recital 7

Digital Operational Resilience Act · UE 2022/2554

(7)

In April 2019, the European Supervisory Authority (European Banking Authority), (EBA) established by Regulation (EU) No 1093/2010 of the European Parliament and of the Council (4), the European Supervisory Authority (European Insurance and Occupational Pensions Authority), (‘EIOPA’) established by Regulation (EU) No 1094/2010 of the European Parliament and of the Council (5) and the European Supervisory Authority (European Securities and Markets Authority), (‘ESMA’) established by Regulation (EU) No 1095/2010 of the European Parliament and of the Council (6) (known collectively as ‘European Supervisory Authorities’ or ‘ESAs’) jointly issued technical advice calling for a coherent approach to ICT risk in finance and recommending to strengthen, in a proportionate way, the digital operational resilience of the financial services industry through a sector-specific initiative of the Union.

Luxembourg specificity
circulaires CSSF 22/806 et 24/847

In Luxembourg, the CSSF has issued circular CSSF 24/847 on ICT incident reporting and circular CSSF 22/806 on outsourcing arrangements, which form the national reading grid for DORA. The CSSF expects the proportionality referenced in recital 7 to be articulated with these circulars: a support PFS cannot invoke DORA to escape the more specific cloud outsourcing requirements of 22/806.

Luxgap practice: hand your CSSF relationship manager a single mapping memo cross-referencing DORA, circular 22/806 and circular 20/750 to avoid redundant requests during annual prudential interviews.