Recital 99
Digital Operational Resilience Act · UE 2022/2554
| (99) | Regulatory technical standards should ensure the consistent harmonisation of the requirements laid down in this Regulation. In their roles as bodies endowed with highly specialised expertise, the ESAs should develop draft regulatory technical standards which do not involve policy choices, for submission to the Commission. Regulatory technical standards should be developed in the areas of ICT risk management, major ICT-related incident reporting, testing, as well as in relation to key requirements for a sound monitoring of ICT third-party risk. The Commission and the ESAs should ensure that those standards and requirements can be applied by all financial entities in a manner that is proportionate to their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations. The Commission should be empowered to adopt those regulatory technical standards by means of delegated acts pursuant to Article 290 TFEU and in accordance with Articles 10 to 14 of Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010. |
In Luxembourg, the CSSF is the competent authority supervising DORA and its RTS for credit institutions, PFS, investment firms, UCITS, AIFMs and payment institutions, while the CAA supervises insurance and reinsurance undertakings. The CSSF has published Circular 24/847 on ICT incident reporting, directly aligned with the RTS on classification adopted under recital 99, and has updated its outsourcing framework (Circulars 22/806 and 17/656) to align with the DORA RTS on critical subcontracting.
Luxgap practice: we maintain a living mapping matrix between CSSF/CAA circulars and published DORA RTS, embedded in the Standards Radar, to avoid duplicate reporting and identify national requirements layered on top of EU RTS.