Recital 76
Digital Operational Resilience Act · UE 2022/2554
| (76) | With a view to promoting convergence and efficiency in relation to supervisory approaches when addressing ICT third-party risk in the financial sector, as well as to strengthening the digital operational resilience of financial entities which rely on critical ICT third-party service providers for the provision of ICT services that support the supply of financial services, and thereby to contributing to the preservation of the Union’s financial system stability and the integrity of the internal market for financial services, critical ICT third-party service providers should be subject to a Union Oversight Framework. While the set-up of the Oversight Framework is justified by the added value of taking action at Union level and by virtue of the inherent role and specificities of the use of ICT services in the provision of financial services, it should be recalled, at the same time, that this solution appears suitable only in the context of this Regulation specifically dealing with digital operational resilience in the financial sector. However, such Oversight Framework should not be regarded as a new model for Union supervision in other areas of financial services and activities. |
In Luxembourg, the CSSF is the national competent authority for DORA and participates in the Lead Overseer's Joint Examination Teams. The Luxembourg financial centre is particularly exposed to concentration on a few hyperscalers (Microsoft, AWS, Google) and on local providers such as LuxConnect, eBRC or POST Telecom, some of which could be designated as CTPPs. CSSF Circular 22/806 on ICT outsourcing continues to apply alongside DORA and requires prior notification to the CSSF for critical outsourcing arrangements.
Luxgap practice: we systematically cross-check your DORA art. 28 mapping with the residual requirements of Circular 22/806 to avoid poorly coordinated dual compliance during a CSSF inspection.