Recital 85
Digital Operational Resilience Act · UE 2022/2554
| (85) | The Oversight Framework should be without prejudice to Member States’ competence to conduct their own oversight or monitoring missions in respect to ICT third-party service providers which are not designated as critical under this Regulation, but which are regarded as important at national level. |
In Luxembourg, the CSSF exercises national oversight of important ICT providers through Circular CSSF 22/806 on outsourcing arrangements (including cloud), which co-exists with DORA and requires prior notifications, outsourcing registers and contractual review, even for providers not designated as critical at ESAs level.
Luxgap practice: maintain a unified register that simultaneously satisfies DORA Article 28(3) and CSSF 22/806, with automated field mapping between the two frameworks to avoid duplicate declarative work.