Recital 78
Digital Operational Resilience Act · UE 2022/2554
| (78) | Similarly, financial entities providing ICT services to other financial entities, while belonging to the category of ICT third-party service providers under this Regulation, should also be exempted from the Oversight Framework since they are already subject to supervisory mechanisms established by the relevant Union financial services law. Where applicable, competent authorities should take into account, in the context of their supervisory activities, the ICT risk posed to financial entities by financial entities providing ICT services. Likewise, due to the existing risk monitoring mechanisms at group level, the same exemption should be introduced for ICT third-party service providers delivering services predominantly to the entities of their own group. ICT third-party service providers providing ICT services solely in one Member State to financial entities that are active only in that Member State should also be exempted from the designation mechanism because of their limited activities and lack of cross-border impact. |
In Luxembourg, the CSSF is the competent authority for the supervisory activities referred to in Recital 78. The law of 1 June 2023 on markets in financial instruments and the CSSF circulars on IT outsourcing (notably CSSF circular 22/806 on outsourcing arrangements) make clear that even intragroup or single-Member-State Luxembourg providers exempt from the Oversight Framework remain subject to prior notification and outsourcing risk management requirements. The Luxembourg financial centre hosts many domestic outsourcers serving only local PSF, AIFM and UCITS entities, typically captured by the single-Member-State exemption.
Luxgap practice: qualify the single-Member-State exemption early in the contracting cycle and keep the qualification evidence in the DORA Article 28 register to anticipate any CSSF on-site inspection.