Recital 28
Directive on the security of network and information systems · UE 2022/2555
| (28) | Regulation (EU) 2022/2554 of the European Parliament and of the Council (10) should be considered to be a sector-specific Union legal act in relation to this Directive with regard to financial entities. The provisions of Regulation (EU) 2022/2554 relating to information and communication technology (ICT) risk management, management of ICT-related incidents and, in particular, major ICT-related incident reporting, as well as on digital operational resilience testing, information-sharing arrangements and ICT third-party risk should apply instead of those provided for in this Directive. Member States should therefore not apply the provisions of this Directive on cybersecurity risk-management and reporting obligations, and supervision and enforcement, to financial entities covered by Regulation (EU) 2022/2554. At the same time, it is important to maintain a strong relationship and the exchange of information with the financial sector under this Directive. To that end, Regulation (EU) 2022/2554 allows the European Supervisory Authorities (ESAs) and the competent authorities under that Regulation to participate in the activities of the Cooperation Group and to exchange information and cooperate with the single points of contact, as well as with the CSIRTs and the competent authorities under this Directive. The competent authorities under Regulation (EU) 2022/2554 should also transmit details of major ICT-related incidents and, where relevant, significant cyber threats to the CSIRTs, the competent authorities or the single points of contact under this Directive. This is achievable by providing immediate access to incident notifications and forwarding them either directly or through a single entry point. Moreover, Member States should continue to include the financial sector in their cybersecurity strategies and CSIRTs can cover the financial sector in their activities. |
In Luxembourg, the DORA vs NIS 2 routing is particularly sensitive given the density of the financial sector: support PFS (articles 29-1 to 29-6 of the law of 5 April 1993), fund depositaries and alternative managers fall under DORA and therefore escape the cyber obligations of the law of 28 July 2023 on cybersecurity, but their unregulated subsidiaries (holdings, ServCos, real estate vehicles) may remain under NIS 2 supervised by the ILR. The CSSF remains the competent authority for major ICT incident notification on the DORA side, while the ILR centralizes NIS 2 notifications.
Luxgap practice: we recommend an entity-by-entity mapping formalized in a regime matrix jointly validated by the CISO and the compliance officer, and reviewed at each change of CSSF authorization or group structure.