Recital 8
Digital Operational Resilience Act · UE 2022/2554
| (8) | The Union financial sector is regulated by a Single Rulebook and governed by a European system of financial supervision. Nonetheless, provisions tackling digital operational resilience and ICT security are not yet fully or consistently harmonised, despite digital operational resilience being vital for ensuring financial stability and market integrity in the digital age, and no less important than, for example, common prudential or market conduct standards. The Single Rulebook and system of supervision should therefore be developed to also cover digital operational resilience, by strengthening the mandates of competent authorities to enable them to supervise the management of ICT risk in the financial sector in order to protect the integrity and efficiency of the internal market, and to facilitate its orderly functioning. |
In Luxembourg, the CSSF is the designated competent authority for DORA for credit institutions, PFS, EMIs, UCITS, AIFMs and investment firms, while the CAA (Commissariat aux Assurances) supervises insurance and reinsurance undertakings and intermediaries. The law of 1 August 2024 implementing the DORA regulation designates these authorities, articulates DORA with pre-existing CSSF circulars 20/750 and 22/806, and confirms that CSSF circular 24/847 on ICT incidents becomes the single notification channel.
Luxgap practice: for any dual-regulated entity (CSSF and CAA, e.g. bancassurance), we map both reporting regimes in parallel to avoid duplicate notification and leverage the bridges provided by the law of 1 August 2024.