New DORA Regulation to Impact Luxembourg Financial Institutions
The EU's new DORA regulation on digital operational resilience takes effect in January 2025, requiring significant changes for Luxembourg-based financial entities.

Luxembourg-based financial institutions are preparing for significant operational adjustments mandated by the European Union's new Digital Operational Resilience Act (DORA). The regulation, aimed at harmonizing cybersecurity and operational resilience rules across the EU, is set to become applicable in January 2025.
DORA will broadly affect financial sector players, including credit institutions, payment service providers, investment firms, crypto-asset service providers, and insurance undertakings. In Luxembourg, the regulation necessitates organizational changes extending beyond traditional ICT management. Particular focus will be placed on clear processes for monitoring and controlling outsourced critical or important business functions.
The regulation also strengthens board-level accountability for compliance, change management, oversight of outsourcing arrangements, and business continuity management. Financial entities must ensure they possess a comprehensive ICT risk management framework and a documented digital operational resilience strategy.
Key areas impacted include third-party risk management, ICT incident management and reporting, digital operational resilience testing, and governance and ICT risk management requirements. Firms must review their contracts with ICT third-party providers and ensure compliance, especially concerning critical outsourcing arrangements.
Financial institutions have approximately 24 months from the regulation's official publication (December 27, 2022) to meet all requirements. It is advised that entities promptly begin a gap analysis of DORA requirements and the design of an enhanced operational resilience framework, as further technical standards are anticipated in the coming months.