Recital 85

Recital 85

Digital Operational Resilience Act · UE 2022/2554

(85)

The Oversight Framework should be without prejudice to Member States’ competence to conduct their own oversight or monitoring missions in respect to ICT third-party service providers which are not designated as critical under this Regulation, but which are regarded as important at national level.

Luxembourg specificity
circulaire CSSF 22/806 du 22 avril 2022 relative aux arrangements d'externalisation

In Luxembourg, the CSSF exercises national oversight of important ICT providers through Circular CSSF 22/806 on outsourcing arrangements (including cloud), which co-exists with DORA and requires prior notifications, outsourcing registers and contractual review, even for providers not designated as critical at ESAs level.

Luxgap practice: maintain a unified register that simultaneously satisfies DORA Article 28(3) and CSSF 22/806, with automated field mapping between the two frameworks to avoid duplicate declarative work.