Recital 93

Recital 93

Digital Operational Resilience Act · UE 2022/2554

(93)

To avoid duplications and overlaps, competent authorities should refrain from taking individually any measures aiming to monitor the critical ICT third-party service provider’s risks and should, in that respect, rely on the relevant Lead Overseer’s assessment. Any measures should in any case be coordinated and agreed in advance with the Lead Overseer in the context of the exercise of tasks in the Oversight Framework.

Luxembourg specificity
loi luxembourgeoise du 1er juin 2023 portant mise en œuvre du reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the DORA competent authority for almost the entire financial sector, and the CAA for insurance. The law of 1 June 2023 implementing the DORA Regulation expressly designates the CSSF as the single point of contact with European Lead Overseers for entities supervised in Luxembourg, reinforcing the prior coordination requirement of recital 93.

Luxgap practice: centralise every CTPP communication through your declared CSSF compliance officer and archive each exchange in a single timestamped file to evidence alignment with the Lead Overseer in case of an eSurfi review or on-site inspection.