Recital 91
Digital Operational Resilience Act · UE 2022/2554
| (91) | The exercise of the oversight should be guided by three operational principles seeking to ensure: (a) close coordination among the ESAs in their Lead Overseer roles, through a joint oversight network (JON), (b) consistency with the framework established by Directive (EU) 2022/2555 (through a voluntary consultation of bodies under that Directive to avoid duplication of measures directed at critical ICT third-party service providers), and (c) applying diligence to minimise the potential risk of disruption to services provided by the critical ICT third-party service providers to customers that are entities falling outside the scope of this Regulation. |
In Luxembourg, the CSSF is the competent authority for DORA oversight of financial entities, and the law of 1 August 2024 implementing DORA explicitly designates the CSSF and the CAA as national contact points with the Joint Oversight Network. The Luxembourg financial centre concentrates strong dependency on a few hyperscalers and shared service providers (eBRC, LuxConnect, POST), which makes recital 91 particularly sensitive: an ESA measure on a critical provider can cascade across a significant part of the sector.
Luxgap practice: we map your critical ICT providers against the dual grid of CSSF circular 22/806 (outsourcing) and DORA articles 28-30, and we integrate JON communications into your quarterly IT risk committee to anticipate contract renegotiations before the CSSF asks for them.