Recital 86

Recital 86

Digital Operational Resilience Act · UE 2022/2554

(86)

To leverage the multi-layered institutional architecture in the financial services area, the Joint Committee of the ESAs should continue to ensure overall cross-sectoral coordination in relation to all matters pertaining to ICT risk, in accordance with its tasks on cybersecurity. It should be supported by a new Subcommittee (the ‘Oversight Forum’) carrying out preparatory work both for the individual decisions addressed to critical ICT third-party service providers, and for the issuing of collective recommendations, in particular in relation to benchmarking the oversight programmes for critical ICT third-party service providers, and identifying best practices for addressing ICT concentration risk issues.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the competent authority designated under DORA for almost all financial entities (credit institutions, PSF, AIFMs, UCITS, payment institutions, EMIs), while the CAA supervises insurance and reinsurance undertakings. The law of 1 August 2024 implementing the DORA regulation designates these authorities and grants them the sanction powers set out in Article 50 DORA, applicable to governance failures linked to monitoring Joint Committee and Oversight Forum recommendations.

Luxgap practice: ensure that your regulatory watch explicitly integrates CSSF circulars (notably 22/806 on outsourcing arrangements) and CAA publications, in addition to ESAs publications, as the CSSF systematically refers to its own circulars when transposing a European recommendation.