Key dates
- 2025-01-17
- DORA began applying to in-scope financial entities supervised by the CSSF.
- 2025-12-17
- The European Commission confirmed through DORA Q&A 102 that DORA applies to qualifying third-country branches in an EU Member State.
- 2026-06-30 Deadline
- CSSF’s extended best-efforts deadline for the first register-of-information submission by third-country branches of credit institutions headquartered in a third country.
- 2026-08-27
- Circular CSSF 26/915 was published and took effect immediately; the listed CSSF circulars were amended to include or remove qualifying third-country branches as applicable.
- 2027-03-31 Deadline
- Target date identified by CSSF for the required-quality register-of-information submission by third-country branches of credit institutions headquartered in a third country.
- 2027-01-11
- Relevant CRD VI third-country-branch provisions are scheduled to take effect, subject to national transposition and applicable transitional rules.
Suggested considerations
- Firms should map each Luxembourg third-country branch against the counterfactual test in Circular 26/915: whether the head-office undertaking would qualify under Article 2(1)(a) to (t) of DORA if established in the relevant third country.
- Affected branches should update their regulatory-perimeter inventories, governance documents, ICT-risk policies, outsourcing inventories, incident-classification procedures and DORA control testing to reflect immediate inclusion in the DORA-specific CSSF circulars.
- Compliance teams may wish to separate non-ICT outsourcing, which remains subject to Part I of Circular CSSF 22/806, from ICT outsourcing, which is governed by DORA and Circular CSSF 25/882 rather than the legacy Part II framework.
- Affected entities should validate their register-of-information process under DORA and Circular CSSF 25/882, including branch-level data, ICT third-party contracts, intra-group arrangements and submission ownership. The 30 June 2026 best-efforts deadline for third-country branches of credit institutions has passed, and firms should prepare for the 31 March 2027 collection and any CSSF remediation requests.
- Incident-response teams should test access to the CSSF eDesk procedure and S3 API and document an escalation process for emailing ictrisksupervision@cssf.lu when technical impossibility prevents electronic submission.
- Firms should assess whether they qualify for the microenterprise exclusion in Circular CSSF 25/892; the exclusion applies to entities employing fewer than 10 persons with annual turnover and/or annual balance-sheet total not exceeding EUR 2 million, subject to the DORA definition and exclusions for specified market infrastructures.
- Third-country banking groups should coordinate DORA implementation with the CRD VI third-country-branch analysis, including the 11 January 2027 effective date for relevant CRD VI provisions, rather than assuming that the two regimes have identical scope or timing.
What changed
Qualifying third-country branches are added to the scope of Circulars CSSF 25/882, 25/892 and 25/893, covering DORA ICT third-party-service information and reporting, estimation of aggregated annual costs and losses from major ICT-related incidents under Article 11(11) of DORA and the Joint ESA Guidelines JC/GL/2024/34, and reporting of major ICT-related incidents and significant cyber threats.
Compliance impact
The impact is high for affected Luxembourg third-country branches because Circular 26/915 makes DORA-specific ICT third-party, incident-reporting and operational-resilience obligations immediately applicable and removes reliance on legacy ICT frameworks. Non-compliance may create supervisory findings, missed DORA reporting deadlines and deficiencies in ICT third-party oversight or incident governance; the CSSF does not describe a new penalty schedule in this publication.