Recital 89
Digital Operational Resilience Act · UE 2022/2554
| (89) | Due to the significant impact of being designated as critical, this Regulation should ensure that the rights of critical ICT third-party service providers are observed throughout the implementation of the Oversight Framework. Prior to being designated as critical, such providers should, for example, have the right to submit to the Lead Overseer a reasoned statement containing any relevant information for the purposes of the assessment related to their designation. Since the Lead Overseer should be empowered to submit recommendations on ICT risk matters and suitable remedies thereto, which include the power to oppose certain contractual arrangements ultimately affecting the stability of the financial entity or the financial system, critical ICT third-party service providers should also be given the opportunity to provide, prior to the finalisation of those recommendations, explanations regarding the expected impact of the solutions, envisaged in the recommendations, on customers that are entities falling outside the scope of this Regulation and to formulate solutions to mitigate risks. Critical ICT third-party service providers disagreeing with the recommendations should submit a reasoned explanation of their intention not to endorse the recommendation. Where such reasoned explanation is not submitted or where it is considered to be insufficient, the Lead Overseer should issue a public notice summarily describing the matter of non-compliance. |
In Luxembourg, the CSSF is the DORA competent authority under article 46 for almost the entire financial sector (banks, PFS, EMIs, UCITS, AIFMs, regulated fintechs), while the CAA remains competent for insurance and reinsurance undertakings. CSSF circular 22/806 on outsourcing, read together with DORA, requires prior notification to the CSSF for any critical or important outsourcing, which now includes the obligation to immediately report any CTPP designation or public notice of non-compliance affecting an already notified provider.
Luxgap practice: we configure the Critical Provider Radar to automatically generate the CSSF notification under article 35 of circular 22/806 as soon as one of your outsourced providers is designated as CTPP by the ESAs, in order to meet the prudential communication timeline expected by the CSSF.