Recital 91

Recital 91

Digital Operational Resilience Act · UE 2022/2554

(91)

The exercise of the oversight should be guided by three operational principles seeking to ensure: (a) close coordination among the ESAs in their Lead Overseer roles, through a joint oversight network (JON), (b) consistency with the framework established by Directive (EU) 2022/2555 (through a voluntary consultation of bodies under that Directive to avoid duplication of measures directed at critical ICT third-party service providers), and (c) applying diligence to minimise the potential risk of disruption to services provided by the critical ICT third-party service providers to customers that are entities falling outside the scope of this Regulation.

Luxembourg specificity
loi luxembourgeoise du 1er aout 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the competent authority for DORA oversight of financial entities, and the law of 1 August 2024 implementing DORA explicitly designates the CSSF and the CAA as national contact points with the Joint Oversight Network. The Luxembourg financial centre concentrates strong dependency on a few hyperscalers and shared service providers (eBRC, LuxConnect, POST), which makes recital 91 particularly sensitive: an ESA measure on a critical provider can cascade across a significant part of the sector.

Luxgap practice: we map your critical ICT providers against the dual grid of CSSF circular 22/806 (outsourcing) and DORA articles 28-30, and we integrate JON communications into your quarterly IT risk committee to anticipate contract renegotiations before the CSSF asks for them.