Operational Resilience / Outsourcing in Luxembourg
Operational Resilience / Outsourcing regulatory updates from Luxembourg.
We track 59 Operational Resilience / Outsourcing updates from Luxembourg regulators, published by CSSF. The archive covers 35 news items, 18 guidance notes and 3 consultations. Most recent update: September 2026. Coverage runs from 2025 to 2026.
for Luxembourg-domiciled funds subject to the 2010 Law relating to UCIs, specialised investment funds governed by the Law of 13 February 2007, and investment companies in risk capital governed by the Law of 15 June 2004.
Why this matters
This is a CSSF communiqué establishing mandatory notification procedures through the eDesk 'LMT activation' module for suspension of redemptions under national law. The update implements transposition of EU Directive 2024/927 and applies to UCIs, specialised investment funds, and risk capital investment companies.
The CSSF alert addresses active exploitation of CVE-2026-76461, an unauthenticated remote code execution vulnerability in Cisco Secure Email Gateway affecting email parsing.
on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg
AI Analysis
CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.
Key dates
2025-01-17
DORA became applicable to financial entities within the CSSF supervisory perimeter.
2025-12-17
The European Commission confirmed through DORA Q&A DORA102-3097 that DORA applies to qualifying third-country branches in an EU country.
2026-08-27
Circular CSSF 26/915 was published and its amendments took effect immediately.
2027-02-27 Deadline
The six-month transition period for PSPs not otherwise subject to DORA under Circular CSSF 25/893 is expected to end; the DORA incident-reporting framework then applies to those PSPs and Circular CSSF 21/787 is repealed for them.
2027-03-31 Deadline
Latest date in the annual CSSF register-of-information submission window for arrangements contracted during 2026, subject to the applicable CSSF collection process.
Suggested considerations
Firms should map each Luxembourg third-country branch against the DORA Article 2(1)(a) to (t) categories as the undertaking would be classified in the third country, documenting the legal-entity and regulatory-status analysis.
Compliance teams may wish to update the branch's regulatory inventory, DORA applicability assessment, governance documentation and responsibility matrices to reflect immediate inclusion where the qualifying test is met.
Affected branches should review ICT third-party-service contracts, the register of information and planned arrangements supporting critical or important functions, including whether CSSF notification was made at least three months before implementation or one month where the specified Luxembourg support-PFS exception applies.
Firms should distinguish ICT outsourcing from other outsourcing: ICT outsourcing should be managed under the DORA framework and Circular CSSF 25/882, while non-ICT outsourcing remains subject to Circular CSSF 22/806 Part I.
Incident-response teams should test the CSSF eDesk Portal and S3 API reporting channels and maintain a contingency process for notifying ictrisksupervision@cssf.lu by the applicable deadline if technical failure prevents use of the primary channel.
Firms should confirm that major ICT incidents are reported individually and that outsourced reporting arrangements preserve the firm's responsibility for timing, completeness and notification content.
Affected branches should assess whether they are microenterprises under DORA Article 3(60), since Circular CSSF 25/892 excludes microenterprises from its aggregated-cost estimation framework, except for trading venues, central counterparties, trade repositories and central securities depositories.
Where the branch is an EU branch rather than a third-country branch, firms should verify the home-Member-State allocation rules because the CSSF circulars generally exclude EU branches from the relevant Luxembourg reporting chapters.
What changed
The circular implements the European Commission's 17 December 2025 DORA Q&A position and includes qualifying third-country branches in the scope of Circulars CSSF 25/882 on ICT third-party services, 25/892 on aggregated annual costs and losses from major ICT incidents, and 25/893 on major ICT-related incident and significant cyber-threat reporting.
Compliance impact
The impact is high for affected third-country branches because the clarification brings them into DORA governance, ICT third-party-service, register-of-information, incident-reporting and loss-estimation regimes immediately, while removing reliance on Circulars 20/750 and 22/806 Part II for ICT matters. The CSSF states that missed notification deadlines or non-compliant arrangements may be treated as not notified and may lead to supervisory or administrative measures; outsourcing reporting does not transfer responsibility away from the branch.
CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.
Key dates
2025-01-17
DORA began applying to in-scope financial entities supervised by the CSSF.
2025-12-17
The European Commission confirmed through DORA Q&A 102 that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF’s extended best-efforts deadline for the first register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2026-08-27
Circular CSSF 26/915 was published and took effect immediately; the listed CSSF circulars were amended to include or remove qualifying third-country branches as applicable.
2027-03-31 Deadline
Target date identified by CSSF for the required-quality register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2027-01-11
Relevant CRD VI third-country-branch provisions are scheduled to take effect, subject to national transposition and applicable transitional rules.
Suggested considerations
Firms should map each Luxembourg third-country branch against the counterfactual test in Circular 26/915: whether the head-office undertaking would qualify under Article 2(1)(a) to (t) of DORA if established in the relevant third country.
Affected branches should update their regulatory-perimeter inventories, governance documents, ICT-risk policies, outsourcing inventories, incident-classification procedures and DORA control testing to reflect immediate inclusion in the DORA-specific CSSF circulars.
Compliance teams may wish to separate non-ICT outsourcing, which remains subject to Part I of Circular CSSF 22/806, from ICT outsourcing, which is governed by DORA and Circular CSSF 25/882 rather than the legacy Part II framework.
Affected entities should validate their register-of-information process under DORA and Circular CSSF 25/882, including branch-level data, ICT third-party contracts, intra-group arrangements and submission ownership. The 30 June 2026 best-efforts deadline for third-country branches of credit institutions has passed, and firms should prepare for the 31 March 2027 collection and any CSSF remediation requests.
Incident-response teams should test access to the CSSF eDesk procedure and S3 API and document an escalation process for emailing ictrisksupervision@cssf.lu when technical impossibility prevents electronic submission.
Firms should assess whether they qualify for the microenterprise exclusion in Circular CSSF 25/892; the exclusion applies to entities employing fewer than 10 persons with annual turnover and/or annual balance-sheet total not exceeding EUR 2 million, subject to the DORA definition and exclusions for specified market infrastructures.
Third-country banking groups should coordinate DORA implementation with the CRD VI third-country-branch analysis, including the 11 January 2027 effective date for relevant CRD VI provisions, rather than assuming that the two regimes have identical scope or timing.
What changed
Qualifying third-country branches are added to the scope of Circulars CSSF 25/882, 25/892 and 25/893, covering DORA ICT third-party-service information and reporting, estimation of aggregated annual costs and losses from major ICT-related incidents under Article 11(11) of DORA and the Joint ESA Guidelines JC/GL/2024/34, and reporting of major ICT-related incidents and significant cyber threats.
Compliance impact
The impact is high for affected Luxembourg third-country branches because Circular 26/915 makes DORA-specific ICT third-party, incident-reporting and operational-resilience obligations immediately applicable and removes reliance on legacy ICT frameworks. Non-compliance may create supervisory findings, missed DORA reporting deadlines and deficiencies in ICT third-party oversight or incident governance; the CSSF does not describe a new penalty schedule in this publication.
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).
Key dates
2025-01-17
DORA became applicable to financial entities within its scope, subject to the specific DORA provisions and technical standards applicable to each entity.
2025-04-09
Circular CSSF 25/881 was published and took effect, removing DORA financial entities from Circular 20/750 and retaining 20/750 for entities outside DORA; PSP-specific provisions were reorganised under Circular 25/880.
2026-06-30 Deadline
CSSF extended the first Register of Information submission for Luxembourg branches of third-country credit institutions to this date on a best-efforts basis; the CSSF indicated that the required level of quality should be achieved for the 2027 submission.
2026-08-27
Circular CSSF 26/915 was published, confirming the DORA treatment of qualifying third-country branches and removing them from the full scope of Circular 20/750 and related overlapping circular provisions.
2027-03-31 Deadline
Target date identified by the CSSF for the required-quality Register of Information submission by Luxembourg branches of third-country credit institutions.
Suggested considerations
Firms should classify each Luxembourg entity and branch against DORA Article 2 and the amended scope of Circular 20/750, including an assessment of whether a third-country head office would qualify under DORA Article 2(1)(a) to (t).
Compliance teams may wish to determine whether the entity should operate under DORA rather than 20/750, and document the rationale, legal-entity perimeter and treatment of any Luxembourg branch.
Firms remaining within Circular 20/750 should consider reviewing their ICT and security-risk-management framework, governance approvals, risk assessments, incident processes, business-continuity arrangements and control testing against the continuing requirements.
Payment service providers should consider replacing references to the PSP provisions formerly contained in Circular 20/750 with the applicable requirements in Circular CSSF 25/880 and EBA/GL/2025/02.
Third-country branches treated as DORA entities should consider validating their DORA governance, ICT-risk framework, incident-reporting arrangements, ICT contractual inventory and Register of Information processes, taking account of CSSF reporting communications.
Firms should update policies, regulatory inventories, outsourcing and ICT-third-party registers, training materials and regulatory mapping to distinguish DORA obligations from the residual Circular 20/750 obligations.
Compliance teams may wish to retain evidence of the scope assessment and implementation date, because the 2025 amendment was effective immediately and the 2026 amendment changes the treatment of a previously identified 20/750 population.
What changed
Circular 25/881 provides that DORA financial entities supervised by the CSSF no longer fall within Circular 20/750; for entities covered by 20/750 but outside DORA, the circular continues to apply in full. Payment-service-provider-specific ICT and security-risk provisions were removed from 20/750 and regrouped in Circular CSSF 25/880, reflecting the revised EBA Guidelines on ICT and security risk management for payment service providers, including EBA/GL/2025/02.
Compliance impact
The principal impact is perimeter and framework migration rather than a wholly new ICT-control standard: entities in DORA must avoid relying on residual 20/750 requirements where DORA governs, while non-DORA entities retain substantive 20/750 obligations. The CSSF and market commentary indicate that misclassification may create gaps in DORA governance, ICT-third-party documentation, incident reporting and Register of Information submissions, with potential supervisory findings and related remediation or enforcement consequences.
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
AI Analysis
Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.
Key dates
2025-01-17
DORA became applicable to in-scope financial entities, according to the CSSF implementation communication referenced by Circular CSSF 25/882.
2025-04-09
Circular CSSF 25/882 was published and applied with immediate effect.
2025-04-01 Deadline
The first exceptional CSSF register submission window opened for arrangements contracted up to 31 March 2025.
2025-04-15 Deadline
The first exceptional CSSF register submission window closed.
2026-08-27
Circular CSSF 26/915 was published and immediately amended Circular CSSF 25/882 to include qualifying third-country branches in Luxembourg.
2027-03-31 Deadline
Latest date for submission of the register covering arrangements contracted through the end of 2026, under the recurring annual window running from 28 February to 31 March of the following year.
Suggested considerations
Firms should assess whether Luxembourg third-country branches now fall within the amended scope by comparing the branch’s undertaking and head-office activities with the DORA categories in Article 2(1)(a) to (t) and documenting the conclusion.
Compliance teams may wish to inventory all ICT third-party arrangements, including digital, data, cloud, infrastructure and operational services that may not qualify as outsourcing under prior CSSF terminology.
Firms should consider updating ICT third-party approval workflows so arrangements supporting critical or important functions are notified through the CSSF-prescribed form at least three months before commencement, or one month before commencement where the provider is an eligible Luxembourg support PFS.
Firms should maintain an accurate register of information at individual, sub-consolidated and consolidated levels, with controls for prompt correction when requested by the CSSF and the ability to provide the register outside the annual submission window.
Compliance and outsourcing teams may wish to reassess contractual access to professional-secrecy data against Article 41(2a) LFS or Article 30(2a) LPS and verify that Luxembourg ICT management or operations providers hold the required Article 29-3 LFS authorisation or qualify for an applicable exception.
Firms using cloud services should confirm that the resource operator has designated a suitably qualified cloud officer and that internal cloud, information-security and third-party oversight responsibilities are clearly allocated.
Third-country branches should consider implementing the requirements immediately because Circular CSSF 26/915 provides no transition period, while preserving evidence of governance, notification and register controls for supervisory review.
What changed
Circular CSSF 26/915 includes in Circular CSSF 25/882’s scope all Luxembourg third-country branches of undertakings covered by the specified DORA financial-entity categories where the head office would qualify as a DORA entity under Article 2(1)(a) to (t) in the relevant third country. The requirements apply to ICT services broadly, not only arrangements that meet a traditional outsourcing definition.
Compliance impact
The amendment materially increases the population subject to Luxembourg’s ICT third-party controls because qualifying third-country branches must comply immediately, without a transition period. Non-compliance may leave arrangements formally untreated as notified and expose firms to supervisory measures, binding measures and administrative sanctions, while firms remain fully responsible for compliance and for the resilience and governance of their ICT third-party providers.
amending Circular CSSF 22/806 on outsourcing arrangements
AI Analysis
Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.
Key dates
2025-01-17
DORA began applying to financial entities within its scope, subject to the relevant provisions and transitional arrangements.
2025-04-09
Circular CSSF 25/883 was published and applied with immediate effect, amending Circular CSSF 22/806 and introducing the DORA-based division between ICT and business-process outsourcing.
2025-12-17
The European Commission confirmed through a DORA Q&A that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF-extended submission date for the 2026 DORA register of information for third-country branches of credit institutions headquartered in a third country; entities were invited to submit on a best-efforts basis.
2026-08-27
Circular CSSF 26/915 was published and applied with immediate effect, confirming the DORA treatment of qualifying Luxembourg third-country branches and updating Circular CSSF 22/806 accordingly.
2027-03-31 Deadline
Target CSSF submission deadline for the DORA register of information for affected third-country branches following the initial 2026 collection.
Suggested considerations
Firms should classify each outsourcing arrangement as ICT or non-ICT and determine whether the entity and arrangement fall within DORA, Circular 22/806, or both regimes in their respective areas of application.
DORA entities should consider moving ICT arrangements from their Circular 22/806 outsourcing inventory and controls into the DORA ICT third-party register, while retaining Circular 22/806 controls for business-process outsourcing.
Non-DORA entities should consider continuing to apply the full Circular 22/806 framework to ICT and business-process outsourcing, including due diligence, governance, critical-or-important assessments, monitoring, sub-outsourcing and exit planning.
Third-country branches should assess whether their head office would qualify under Article 2(1)(a) to (t) of DORA and, if so, align ICT governance, contractual arrangements, registers and reporting with DORA rather than relying solely on Circular 22/806.
Compliance teams may wish to review cloud contracts and avoid carrying forward legacy EEA governing-law or hosting clauses where DORA now provides the applicable framework, while preserving enforceable audit, access, cooperation, security, business-continuity and exit rights.
Firms should use the revised CSSF notification form for new critical or important ICT outsourcing arrangements and preserve evidence supporting the three-month notification period, or the one-month period for arrangements involving a support PSF.
Firms should consider validating that existing ICT outsourcing notifications remain complete under the applicable DORA register-of-information requirements, even though Circular 25/883 does not require their re-submission.
Affected third-country branches should consider submitting and maintaining the DORA register of information through the CSSF process, with the 2027 collection requiring data quality suitable for the 31 March 2027 submission deadline.
What changed
From 9 April 2025, DORA entities generally no longer apply the ICT-outsourcing provisions of Circular CSSF 22/806 to ICT arrangements; those arrangements are governed by DORA, including its ICT third-party risk-management, contractual, register-of-information and oversight requirements, together with Circular CSSF 25/882. Circular 22/806 continues to apply to business-process outsourcing by DORA entities, and continues to apply in full to non-DORA entities, including their ICT outsourcing. Chapter 16 management companies remain subject to Circular 22/806 for ICT outsourcing.
Compliance impact
The impact is material for outsourcing inventories, contractual templates, ICT governance, regulatory registers and third-country branch assessments, although Circular 25/883 does not require previously notified ICT outsourcing arrangements to be re-notified. Misclassification may result in applying the wrong control framework, incomplete DORA registers or failures to meet CSSF notification and oversight expectations; the CSSF and market commentary indicate that DORA entities should treat Circular 22/806 primarily as the business-process outsourcing framework, while non-DORA entities retain...
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
AI Analysis
CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.
Key dates
2025-05-19
The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
2025-05-31
Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
2026-08-27
Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.
Suggested considerations
Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.
What changed
From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report.
Compliance impact
The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irrespective of the classification trigger, increasing the importance of coordination between ICT, operational risk, finance and regulatory reporting teams.
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
AI Analysis
CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.
Key dates
2025-01-17
DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
2025-05-28
Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
2025-11-28 Deadline
End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
2026-08-27
Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.
Suggested considerations
Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.
What changed
DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month...
Compliance impact
The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immediate integration of local branch incident reporting into DORA governance and response arrangements.
CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.
Key dates
2022-04-22
Circular CSSF 22/806 was published and replaced or amended specified earlier CSSF and IML outsourcing, governance and control circulars.
2022-06-30
Circular CSSF 22/806 became applicable according to the CSSF implementation framework.
2025-01-17
DORA Regulation (EU) 2022/2554 became applicable to in-scope financial entities, creating the primary EU framework for ICT third-party risk management.
2025-04-09
Circular CSSF 25/883 was published; the amended Circular 22/806 applies to outsourcing arrangements entered into, reviewed or amended on or after this date.
2025-12-17
The European Commission confirmed that DORA also applies to qualifying third-country branches in an EU Member State where the third-country head-office entity would fall within DORA Article 2(1)(a) to (t).
2026-08-27
Circular CSSF 26/915 was published and the CSSF webpage consolidated the amended version of Circular 22/806, confirming the DORA treatment of qualifying Luxembourg third-country branches.
Suggested considerations
Firms should map each outsourcing and third-party technology arrangement against the applicable regime: DORA, Circular 22/806 business-process outsourcing requirements, or the full Circular 22/806 framework for non-DORA entities.
Compliance teams may wish to review whether Luxembourg third-country branches have a head-office activity that corresponds to a DORA Article 2(1)(a) to (t) financial entity and document the resulting DORA scope assessment.
Firms should update outsourcing policies, risk assessments, governance approvals, materiality or criticality assessments, due-diligence files, monitoring controls and exit strategies to reflect the split between DORA ICT third-party risk management and Circular 22/806 business-process outsourcing.
Firms should maintain or update the DORA register of information for ICT third-party arrangements where DORA applies, and reconcile it with the outsourcing inventory and CSSF notification processes.
Firms should review legacy cloud contracts and remove reliance on the repealed Circular 22/806 EEA-law and EEA-resilience clauses where DORA is the applicable ICT third-party regime, while retaining contract terms needed to satisfy DORA and any applicable national requirements.
Non-DORA entities should consider whether their existing contracts still address Circular 22/806 requirements for access and audit rights, sub-outsourcing, confidentiality, data location, business continuity, termination and exit.
Management companies authorised solely under Article 125-1 should consider retaining the full Circular 22/806 control framework for ICT outsourcing rather than assuming that DORA displaces it.
Firms should assess whether outsourcing arrangements entered into, reviewed or amended from 9 April 2025 require remediation or re-papering under the amended framework.
What changed
Circular 25/883 amended Circular 22/806 following DORA Regulation (EU) 2022/2554 becoming applicable on 17 January 2025. For entities subject to DORA, the ICT-outsourcing provisions of Circular 22/806 were largely repealed or displaced by DORA's ICT third-party risk-management requirements, while Circular 22/806 remains applicable to business-process outsourcing.
Compliance impact
The impact is high for firms with complex ICT and outsourcing models because misclassification can lead to the wrong contractual, governance, register and notification framework, and because DORA brings direct requirements for ICT third-party risk management and supervisory oversight. Independent market commentary from EY, Deloitte, Baker McKenzie and Luxembourg industry bodies reads the amendments as a practical division between DORA-regulated ICT services and Circular 22/806 business-process outsourcing, with particular remediation needs for investment managers, non-DORA entities and...
Requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.
Key dates
2020-08-25
Circular CSSF 20/750 was originally published, establishing CSSF expectations for ICT and security risk management.
2025-01-17
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector became applicable to DORA-defined financial entities supervised by the CSSF.
2025-04-09
Circular CSSF 25/881 amended Circular 20/750, narrowing it primarily to non-DORA entities and moving PSP-specific requirements to Circular CSSF 25/880.
2026-08-27
Circular CSSF 26/915 was published and applies with immediate effect; DORA-equivalent third-country branches are removed from Circular 20/750 and addressed through the DORA-related CSSF framework.
Suggested considerations
Firms with Luxembourg third-country branches should document an entity-by-entity DORA scoping analysis, including the classification of the non-EU head-office undertaking under Article 2(1)(a) to (t) of Regulation (EU) 2022/2554 and the relevance of Article 2(2).
Affected branches should consider retiring Circular 20/750 as their primary ICT framework and mapping controls instead to DORA and the applicable CSSF circulars, including Circular CSSF 25/882 on ICT third-party services and Circular CSSF 25/893 on major ICT-related incidents and significant cyber threats.
Firms should review ICT third-party inventories, contracts, due diligence files, exit strategies and, where relevant, the DORA Register of Information so that all ICT services are captured regardless of whether the arrangement is formally classified as outsourcing.
Entities remaining within Circular 20/750 should consider confirming that the management body has approved the ICT and security risk-management framework and that it is reviewed at least annually.
Remaining in-scope entities should consider refreshing their annual ICT and security risk assessment, critical-function and information-asset mapping, threat and vulnerability monitoring, access controls, patching, backup, recovery, incident-response and business-continuity documentation.
Compliance teams may wish to verify that critical ICT systems undergo security testing at least annually, non-critical systems are tested regularly and at least every three years, and critical business continuity arrangements are tested at least annually.
Branches and PSP-related entities should consider validating incident-reporting channels and escalation procedures, including the CSSF alternative email channel for exceptional technical failures where the prescribed DORA reporting channel cannot be used.
Firms should consider preserving evidence of proportionality assessments, control testing, audit findings, remediation, management-body reporting and staff security training for CSSF supervisory review.
What changed
Circular 26/915 applies with immediate effect and removes DORA-equivalent third-country branches from the scope of Circular 20/750. A third-country branch is treated as DORA-relevant where, in the jurisdiction of its head office, the undertaking would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554, subject to the applicable exclusions and Article 2(2) conditions.
Compliance impact
The immediate-effect scope change is operationally significant for third-country branches because applying the wrong framework could result in duplicated controls, incomplete DORA reporting, or failure to maintain DORA third-party and incident-reporting records. For entities remaining under Circular 20/750, the CSSF continues to expect a documented, independently controlled and annually reviewed ICT risk framework, with deficiencies capable of generating supervisory remediation and broader CSSF enforcement consequences.
This is a routine maintenance notification from CSSF (Luxembourg financial regulator) regarding scheduled system downtime. It is informational content affecting operational continuity for all regulated firms using CSSF services. No specific sector applies as this is infrastructure-related.
This is an administrative form update from CSSF for UCI depositary authorization applications. It is informational/procedural content regarding licensing requirements for entities acting as depositaries for Undertakings for Collective Investment.
ESMA Common Supervisory Action targeting UCITS Management Companies and Alternative Investment Fund Managers on risk management function effectiveness. Focuses on governance, risk identification/measurement/monitoring, and reporting requirements.
Administrative sanction imposed on the members of the board of directors of an electronic money institution
AI Analysis
The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.
Key dates
20 January 2026
– CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions, electronic money institutions and account information service providers is published
23 March 2026
– Decision date of the administrative sanction imposed on members of the board of directors of an electronic money institution
30 June 2026
– Application date of CSSF Circular 26/906, from which its governance and risk‑management requirements formally apply to payment institutions and electronic money institutions
21 July 2026
– CSSF publicly releases the notice “Administrative sanction of 23 March 2026 – Administrative sanction imposed on the members of the board of directors of an electronic money institution.”
Suggested considerations
Review and map the institution’s current governance framework, board charter and committee mandates against the detailed requirements of CSSF Circular 26/906, including central administration, board composition, responsibilities and functioning.
Ensure that the board of directors collectively has the required expertise, independence, diversity and time commitment, and that this is documented and periodically reassessed in line with CSSF expectations.
Update board policies to explicitly assign responsibility for strategy, risk appetite, safeguarding of client funds, information security, outsourcing, conflicts of interest and AML/CFT, and ensure these responsibilities are effectively discharged and evidenced.
Confirm that the institution’s central administration, decision‑making centre and administrative centre are physically located in Luxembourg and that members of the management body are sufficiently present on site, as required under the governance framework.
Establish or reinforce the “three lines of defence” model by clearly separating business units, control functions (compliance and risk) and internal audit, and ensure reporting lines to the board are independent and robust.
What changed
- The CSSF demonstrates that it is prepared to impose administrative sanctions directly on members of the board of directors of electronic money institutions, not just on the institution as a legal...
Board members of Luxembourg‑authorised electronic money institutions are now clearly exposed to personal regulatory liability for governance, risk management and safeguarding failures under the CSSF...
This enforcement confirms that CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions and electronic money institutions is not only a formal...
The sanction underscores CSSF expectations that the supervisory body (board of directors) must ensure sound and prudent management, continuity of the institution and protection of its reputation, and...
The case signals a stricter enforcement posture by the CSSF towards the payments and e‑money sector, aligning its expectations and enforcement intensity more closely with bank‑equivalent governance...
Compliance impact
Non‑compliance with CSSF governance, safeguarding and AML/CFT expectations can lead to administrative sanctions directly against board members, reputational damage, potential licence constraints and increased supervisory scrutiny. For EMIs and PIs, this raises the risk profile of board roles and makes demonstrable, documented governance and oversight a critical compliance priority.
Administrative sanction imposed on PingPong Europe S.A.
AI Analysis
The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.
Key dates
20 January 2026
– CSSF publishes Circular 26/906 on central administration, internal governance and risk management for payment and e‑money institutions, raising supervisory expectations for the sector
2 March 2026
– CSSF issues the administrative sanction decision imposing an administrative fine of EUR 12,000 on PingPong Europe S.A. as an electronic money institution
30 June 2026
– Effective date of CSSF Circular 26/906, from which strengthened governance, risk management and safeguarding requirements apply to payment and e‑money institutions
8 July 2026
– CSSF publicly publishes the administrative sanction of 2 March 2026, formally informing the market and stakeholders
Suggested considerations
Review the CSSF sanction against PingPong Europe S.A. and identify which categories of requirements (e.g. governance, safeguarding of client funds, reporting, outsourcing, internal controls) were implicated, then map these to your own control framework.
Conduct a gap analysis against CSSF Circular 26/906, focusing on central administration, internal governance, risk management, and safeguarding of client funds for payment and e‑money institutions.
Update policies, procedures and internal control documentation governing payment services, e‑money issuance, safeguarding (segregation, reconciliations), outsourcing and IT connectivity to ensure alignment with CSSF Circular 26/906.
Ensure that a clearly designated member of the management body holds documented responsibility for oversight of safeguarding arrangements and compliance with CSSF requirements for payment and e‑money institutions.
Implement or enhance daily reconciliations and robust segregation of client funds accounts, supported by periodic internal reviews and testing of safeguarding controls.
What changed
(From the enforcement notice itself, there are no new rules; the impact is interpretative and enforcement‑related.)
CSSF confirms that authorised electronic money institutions are subject to active supervisory and enforcement scrutiny, including public administrative sanctions for regulatory breaches.
The sanction demonstrates that failures which may appear operational or procedural can nonetheless result in monetary fines and public naming, reinforcing the need for robust compliance frameworks in...
The case is likely to be assessed by CSSF in light of the new governance, risk management and safeguarding expectations introduced under CSSF Circular 26/906 for payment and e‑money institutions,...
The public nature of the sanction underscores CSSF’s use of transparency as a deterrent tool, increasing reputational risk for firms that do not comply with licensing, governance, reporting or...
Compliance impact
The compliance impact is high for Luxembourg‑authorised payment and electronic money institutions, given the combination of a formal monetary sanction and public disclosure, which increases both regulatory and reputational risk. Continued or serious non‑compliance with governance, safeguarding or reporting obligations could lead to larger fines, restrictions on business, or, in extreme cases, licence withdrawal.
CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...
under Article 5(4)(b)(iv) of the Law of 2013 and/or Article 101(3)(b), fourth indent of the Law of 2010 as introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council of 13 March 2024
Why this matters
CSSF communication announcing new notification procedures for Luxembourg-based investment fund managers seeking to provide ancillary services to third parties under transposed EU Directive 2024/927. Informational guidance on regulatory requirements and form submission process.
EBA report on simplifying EU prudential and resolution framework stacking orders. Informational publication addressing regulatory complexity reduction while maintaining resilience standards. Primarily impacts banks' capital requirements and resolution frameworks.
This is an informational notice about scheduled technical maintenance of eDesk (CSSF's electronic desk system). It affects operational continuity and is relevant to all regulated firms using the platform.
CSSF is pressing Luxembourg market participants to complete T+1 readiness surveys by **9 June 2026** and to engage with ESMA’s broader T+1 consultation work, because the EU settlement cycle moves to **T+1 on 11 October 2027** under CSDR. The publication matters because it signals that supervisors are already assessing industry preparedness and that firms must accelerate post-trade process changes, especially around allocations, confirmations, and electronic messaging.
Key dates
02 June 2026
- CSSF publishes the reminder on T+1 readiness, survey participation, and ESMA’s consultation work
09 June 2026 Deadline
- Deadline to complete the CSSF national competent authorities’ T+1 readiness survey
07 December 2026
- Expected application date of the revised ESMA guidelines on standardised procedures and messaging protocols
11 October 2027
- T+1 settlement cycle becomes effective under CSDR
Suggested considerations
Complete the CSSF T+1 readiness survey before 9 June 2026 and ensure the submission accurately reflects the firm’s current operational readiness.
Participate in the EU T+1 Industry Committee second readiness survey to demonstrate engagement with the EU-wide readiness process.
Review the firm’s allocation and confirmation workflows to ensure they can operate within T+1 timeframes.
Replace any reliance on oral, manual, or non-machine-readable communications with electronic, standardised messaging channels unless a temporary technical disruption justifies an exception.
Align internal messaging standards with international messaging protocols used for post-trade communication.
What changed
- CSSF is requiring market participants to complete the national competent authorities’ T+1 readiness survey by 9 June 2026, with responses visible only to CSSF and ESMA.
CSSF is strongly encouraging participation in the EU T+1 Industry Committee second readiness survey to support a Union-wide assessment of market preparedness.
CSSF is flagging that the transition to T+1 settlement on 11 October 2027 under CSDR will require coordinated changes across the trading and post-trading chain.
CSSF is warning that forthcoming amendments to the RTS on Settlement Discipline are expected to be endorsed by the European Commission and will further define operational requirements for the T+1...
ESMA’s revised guidelines on standardised procedures and messaging protocols are intended to make post-trade communication faster, clearer, and more consistent across the EU.
Compliance impact
Non-participation in the surveys will not itself appear to be the substantive T+1 breach, but it will materially weaken supervisory visibility and may invite follow-up scrutiny from CSSF and ESMA. Firms that fail to adapt allocations, confirmations, and messaging processes risk being unprepared for the 7 December 2026 guidance phase-in and the 11 October 2027 settlement-cycle change, which could create settlement fails, operational disruption, and conduct/governance issues.
CSSF reminds Luxembourg market participants that the EU move to a **T+1 settlement cycle under CSDR on 11 October 2027** is now in execution phase and links this directly to concrete supervisory tools: mandatory-like readiness surveys, RTS on Settlement Discipline amendments, and new ESMA post‑trade communication guidelines. For compliance teams, this is a front‑to‑back operating model change: firms must demonstrate T+1 readiness to CSSF/ESMA, transition to fully electronic, standardised post‑trade communication, and align allocations/confirmations processes to tighter regulatory timelines.
Key dates
09 June 2026 Deadline
- Deadline for Luxembourg market participants to complete the CSSF national competent authorities’ T+1 readiness survey
07 December 2026
- Expected application date of revised ESMA guidelines on standardised procedures and messaging protocols and the aligned new RTS on Settlement Discipline requirements on allocations and confirmations
11 October 2027
- Effective date for the transition to a T+1 settlement cycle in the EU under CSDR
Suggested considerations
Identify all group entities and business lines in Luxembourg that are in scope of CSDR T+1 (trading, clearing, settlement, custody, collateral, fund dealing) and formally designate a T+1 programme owner at senior management level.
Complete the CSSF T+1 national competent authorities’ survey in full and by 9 June 2026, ensuring that responses accurately reflect current readiness, key risks, dependencies on third parties, and planned remediation milestones.
Arrange for appropriate internal review and sign‑off (e.g. by Compliance and relevant senior management) of the responses to both the CSSF survey and the EUIC second readiness survey before submission.
Participate in the EU T+1 Industry Committee second readiness survey and ensure the firm’s answers are consistent with the information provided to CSSF and with internal T+1 project documentation.
Perform a comprehensive T+1 impact assessment of front‑to‑back trade flows, covering trade execution, allocation, confirmation, affirmation, clearing, settlement, collateral movements, cash and liquidity management, and corporate actions.
What changed
- The EU settlement cycle for in‑scope financial instruments under CSDR will shorten from T+2 to T+1 with effect from 11 October 2027, materially reducing the time to complete front‑to‑back trade,...
CSSF has launched a national competent authorities’ T+1 readiness survey and sets a firm completion deadline of 9 June 2026 for Luxembourg market participants, treating it as a critical supervisory...
In parallel, CSSF strongly encourages Luxembourg firms to complete the EU T+1 Industry Committee (EUIC) second readiness survey to support an EU‑wide view of T+1 readiness and potential systemic...
ESMA’s final draft amendments to the CSDR RTS on Settlement Discipline will introduce additional operational requirements specifically designed to support T+1 (e.g.
ESMA has launched a consultation on updated guidelines on standardised procedures and messaging protocols for allocations, confirmations and affirmations, explicitly aimed at facilitating the T+1...
Compliance impact
Non‑compliance is high‑impact: failure to prepare for T+1, to respond adequately to supervisory surveys, or to align processes with RTS on Settlement Discipline and ESMA guidelines can lead to increased settlement fails, penalties, supervisory scrutiny, and potential enforcement action. The T+1 change also amplifies operational, liquidity, and conduct risks if firms cannot meet accelerated timelines, making early execution of remediation plans a prudential and conduct priority.
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
Key dates
Later in 2026
- Final adoption of guidelines and technical standards
16 April 2026
- Consultation launched
20 May 2026, 10:00–12:00 CET
- Public hearing on draft RTS on group-wide requirements
28 May 2026, 10:00–12:00 CET
- Public hearing on draft Guidelines on business-wide risk assessment
15 July 2026 Deadline
- Consultation deadline for submissions
Suggested considerations
*Immediate (by 15 July 2026):
Review draft Guidelines and assess alignment with current BWRA practices
Identify gaps between existing risk assessment frameworks and proposed minimum requirements
Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
What changed
The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
This is a critical supply chain attack targeting the widely used Axios HTTP client library, which is central to many architectures. The compromise of the build pipeline can result in remote code execution, credential theft, and lateral movement within the information system.
on the failure of credit institutions and certain investment firms
Why this matters
This regulatory update relates to the law on the failure of credit institutions and certain investment firms, which is being updated. It covers prudential and operational requirements, as well as authorization and licensing for banks, wealth managers, and asset managers.
This regulatory update from the CSSF covers a pre-inception readiness review for managed file transfer (MFT) services, which is relevant for investment management firms, wealth managers, and banks.
This regulatory update from the CSSF outlines key supervisory priorities for the investment fund sector in 2026, covering areas such as governance/operational risks, ICT/cyber risks, liquidity and credit risks, contagion risks, asset valuation, sustainable finance, and costs/fees.
This is a warning from the CSSF about fraudsters misusing the name of the CSSF Board Chair to contact supervised entities. It is relevant for banks, wealth managers, and all financial firms that may be targeted by such fraud attempts. The warning covers consumer protection, AML, and operational resilience topics.
This regulatory update provides quarterly statistics on the development of banks' balance sheet totals, which is relevant for prudential requirements, reporting, and operational resilience. It covers a range of banking and investment management firms.
This regulatory update provides quarterly statistics on employment in the banking sector, which is relevant for banks, asset managers, and wealth managers from a prudential, reporting, and operational resilience perspective.
This regulatory update from the CSSF covers consumer protection and financial crime issues, which are relevant for banking, wealth management, and fintech firms. The medium urgency reflects the ongoing nature of these compliance requirements.
This regulatory update from the CSSF relates to disruptions on the eDesk platform, which is likely a critical operational system for financial firms. The impact could be widespread across banking, investment management, and wealth management firms, as well as fintechs that rely on the eDesk platform.
This regulatory update provides information on the profit and loss account of credit institutions in Luxembourg as of 31 December 2025. It covers key financial metrics such as net interest margin, net commission income, and general expenses.
This regulatory update identifies reporting requirements and completeness checks, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and disclosure perspective.
This regulatory update is relevant for third-country branches of credit institutions, as it sets a new submission timeframe for a register of information required under DORA. This impacts banking and payments firms operating in the EU.
Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)
Why this matters
This regulatory update from the CSSF provides details on the submission timeframe and process for the DORA register of information, which is relevant for banking, investment management, and wealth management firms. It covers operational resilience, reporting, and technology/cyber topics.
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
AI Analysis
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
Key dates
30 April 2025 Deadline
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
May 2025
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
11 February 2026
- Publication date of this error guidance (last updated 10/02/2026)
Suggested considerations
Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
What changed
- Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Compliance impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM.
This regulatory update provides quarterly employment statistics for support PFS firms, which is informational in nature and does not indicate any urgent regulatory changes or actions.
This regulatory update provides annual statistics on the balance sheet total and net result of support PFS firms in Luxembourg. It is informational in nature and does not appear to require immediate action, hence the low urgency level.
This regulatory update is related to the annual PSD2 ICT assessment reporting requirement for payment service providers (PSPs) in Luxembourg. It provides details on the submission process and timeline, which is of medium importance for the affected firms.
The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025
Why this matters
This regulatory update from the CSSF focuses on the outcomes of the 2025 SFTR data quality review, which is relevant for banking, capital markets, and payments firms that are subject to SFTR reporting requirements.
This is an informational update on the members of the Consultative Committee for Prudential Regulation, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and authorization perspective.
This regulatory update relates to resolution reporting requirements, which is relevant for banking, investment management, and wealth management firms. The topics covered include reporting and disclosure, prudential/capital requirements, and operational resilience.
CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.
Key dates
20 January 2026
- Publication date of Circular CSSF 26/906
30 June 2026 Deadline
- Compliance deadline: Institutions must assess/review central administration, internal governance, and risk management frameworks to ensure full compliance
Suggested considerations
Gap analysis: Assess current frameworks against circular requirements on management bodies, internal controls, conflicts of interest, product approval, and fund safeguarding.
Updates and notifications: Review/revise governance arrangements (e.g., policies, structures); notify CSSF of management body members, compliance officers, and internal auditors with required documentation (professional experience, police records, etc.).
Documentation: Develop conflicts policy, new product approval procedures, and safeguarding rules; ensure management body authorization.
Ongoing: Maintain sound/prudent management amid growth; integrate with Law of 10 November 2009 requirements.
What changed
The circular consolidates and updates governance rules, focusing on:
Management bodies: Responsibilities, composition, qualifications, organization, and functioning, including CSSF authorization of members based on professional experience, standing (e.g., police...
Internal control functions: Responsibilities, characteristics, organization, and execution of work for compliance officers and internal auditors, with notifications to CSSF including detailed...
Conflicts of interest: Key requirements for a management policy applicable to all staff and management body members.
New product approval: Defined key steps in the process.
Compliance impact
Urgency: High - With ~5 months from publication (20 Jan 2026) to compliance (30 Jun 2026), firms face tight timelines for assessments, policy overhauls, and CSSF notifications, especially given repealed circulars and sector growth pressures. Non-compliance risks supervisory actions, as this fosters "sound and prudent management" in a high-volume industry; proactive reviews are essential to avoid disruptions.
Central administration, internal governance and risk management
AI Analysis
Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.
Key dates
20 January 2026
Publication date of Circular CSSF 26/906
30 June 2026 Deadline
Compliance deadline; Institutions must assess, review, and ensure their central administration, internal governance, and risk management frameworks fully comply with the circular
Suggested considerations
Assess and update governance frameworks: Review central administration location, board/management responsibilities, risk strategy, AML/CFT policies, compliance charter, and funds safeguarding principles to align with the circular.
Confirm control functions: Ensure compliance function (CCO) has independence, resources, direct board access, and authority for investigations; justify/secure CSSF approval for part-time/dual roles.
Implement operational safeguards: Establish daily reconciliations (or justified weekly), segregation/insurance for client funds, system access controls (4-eyes, board validation for significant movements), and third-party due diligence/monitoring.
Document proportionality: Tailor governance to business risks (staff, volumes, products, outsourcing); update new product approval, conflicts policies, and business continuity/incident reporting.
Retain records and report: Board-approve all key policies; prepare for CSSF inspections on outsourcing (per Circular CSSF 22/806) and ICT risks.
What changed
- Consolidation and repeal: Replaces outdated circulars with unified requirements under the amended Law of 10 November 2009 on payment services, covering central administration (decision-making must...
Governance enhancements: Board approves strategy, risk appetite, AML/CFT policies, outsourcing, and information security; management implements via procedures; proportionality based on business...
Operational controls: Strict access to systems (need-to-know, least-privilege, 4-eyes validation); counterparty due diligence for custodians/insurers; full responsibility for agents, distributors,...
AML/CFT focus: Elevates compliance function independence, direct board reporting, risk-based resourcing, and oversight of third parties/opaque structures to close gaps exploited by criminals.
Compliance impact
Urgency: High – With a 30 June 2026 deadline (five months from publication), firms face immediate pressure to review and remediate governance gaps amid sector growth and heightened AML/CFT scrutiny; non-compliance risks supervisory actions, fines, or license issues, especially as it closes criminal exploitation vectors like weak controls and third-party risks.
This regulatory update on resolution reporting requirements is relevant for banking, investment management, and wealth management firms. It covers prudential and capital requirements, reporting and disclosure obligations, as well as operational resilience considerations.
This appears to be an informational update from the CSSF regarding the SSM Calendar Claude Wampach, which is likely relevant for banks, wealth managers, and asset managers operating in the banking and investment management sectors.
Circular CSSF 19/708 mandates the electronic transmission of specified documents to the CSSF via secure platforms like e-file or SOFiE, effective from February 1, 2019, replacing prior paper or other methods. This updated annex (as amended by Circular CSSF 21/790 and further revisions up to April 1, 2025) standardizes submissions for investment funds and related entities, reducing administrative burdens while ensuring document integrity and CSSF accessibility. Compliance professionals must monitor the dynamic annex list on the CSSF website to avoid nullified submissions.
Key dates
28 January 2019
Publication date; of original Circular CSSF 19/708
1 February 2019
Entry into force; Mandatory electronic transmission for listed documents; non-electronic submissions null and void
22 December 2021
Amendment; by Circular CSSF 21/790
1 April 2025
Latest annex update; noted
Ongoing Deadline
Regular checks required; Entities must monitor CSSF website for annex updates
Suggested considerations
Register/access e-file or SOFiE platforms if not already (test/production environments available since February 2019).
Consult and adhere to the latest Annex I for document list, nomenclatures, and formats (PDF with full functionality).
Ensure submissions are final/official versions matching hard copies; use specified identifiers for UCIs/SIFs/SICARs.
Implement processes for automatic/manual transmission (e.g., via updated sending services v4.9.0 or transmission module 6.6.0).
Train staff on responsibilities and integrate into reporting workflows; reference CSSF FAQs for closing documents.
What changed
- Mandatory Electronic-Only Submission: Documents listed in Annex I must be transmitted exclusively via e-file (http://www.e-file.lu) or SOFiE...
Dynamic Annex Updates: The annex, published on the CSSF website, is regularly updated (e.g., latest noted April 1, 2025) and includes prospectuses, management regulations, annual reports, risk...
Scope Expansion: Extends beyond UCIs to securitisation undertakings (2004 Law), pension funds (2005 Law), SICARs, and Luxembourg IFMs; repeals prior Circulars CSSF 09/423 and 08/371.
Filer Responsibilities: Entities ensure documents match official final hard copies, handle content/format accuracy, and check annex updates regularly.
Compliance impact
Urgency: Low (for new implementations post-2019; medium for ongoing monitoring). This matters for operational efficiency and CSSF relations, as non-compliance risks rejected filings, delays (e.g., approvals under SFDR processes), or supervisory scrutiny, but long-standing rule (since 2019) with established platforms reduces immediate pressure. Firms must prioritize annex vigilance to avoid disruptions in routine reporting like annual reports or prospectuses.
Long Form Report – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms – Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors)
Update of Circular CSSF 24/850 on the practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS, as well as the engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning…
AI Analysis
Circular CSSF 25/903 updates Circular CSSF 24/850, refining practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg regarding their annual descriptive report, self-assessment questionnaire, and the roles of approved statutory auditors (réviseurs d’entreprises agréés). It specifies requirements for auditors' engagement, management letters, and separate annual reports. This matters for support PFS as it enhances supervisory oversight, ensures consistent reporting quality, and strengthens internal controls, directly impacting compliance and audit processes amid CSSF's focus on robust PFS supervision.
Key dates
30 April (annually) Deadline
Submission Deadline; Support PFS must submit descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF by 30 April following the financial year-end (first applicable: 30 April 2026 for FY 2025)
31 December 2025 Deadline
Preparation Milestone; Auditors must be engaged and initial scoping completed by year-end 2025 for FY 2025 compliance
1 January 2026
Effective Date; Applies to annual reporting cycles starting for financial year 2025 onwards
Suggested considerations
*Review and Update Processes: Support PFS must map current reporting against new templates in CSSF 25/903 and revise internal procedures for descriptive reports and self-assessments.
*Engage/Confirm Auditors: Select or confirm approved statutory auditors compliant with new engagement rules; execute updated engagement letters incorporating circular requirements by Q4 2025.
*Implement Templates and Testing: Adopt CSSF-provided templates for reports, management letters, and separate reports; conduct sample-based testing of controls as specified.
*Training and Governance: Train compliance/audit teams on changes; ensure board approval of self-assessments and auditor findings.
*Submit on Time: Prepare and file all documents by 30 April deadlines, retaining evidence for CSSF inspections.
What changed
- Updates to Descriptive Report and Self-Assessment Questionnaire: Refines content, format, and submission requirements for support PFS's annual submissions, emphasizing more detailed disclosures on...
Auditor Engagement Rules: Introduces specific practical guidelines for approved statutory auditors, including mandatory scope of work, independence confirmations, and standardized procedures for...
Management Letter and Separate Report: Establishes detailed rules for auditors to issue an annual management letter (addressing findings, recommendations, and remediation) and a separate report for...
Enhanced Documentation and Evidence: Requires support PFS and auditors to provide verifiable evidence (e.g., checklists, testing samples) supporting self-assessments, with stricter CSSF validation...
Compliance impact
Urgency: High. This is high urgency for support PFS due to the impending 30 April 2026 deadline for FY 2025 submissions, with non-compliance risking supervisory fines, license reviews, or reputational damage under CSSF's PFS enforcement regime. It matters as it tightens audit accountability, potentially increasing costs (e.g., auditor fees) while reducing reporting errors—critical for smaller support entities with limited resources.
Practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS.Engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be…
AI Analysis
Circular CSSF 24/850, as amended by Circular CSSF 25/903, establishes practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg to submit annual descriptive reports and self-assessment questionnaires, while also defining the roles of approved statutory auditors (réviseurs d’entreprises agréés) in issuing management letters and separate reports. This guidance standardizes supervisory reporting and audit processes to enhance oversight of support PFS, which provide essential back-office services to authorized PFS. It matters because non-compliance risks supervisory sanctions, reputational damage, and operational disruptions for entities reliant on support PFS structures.
Key dates
1 January 2025
- Effective date of original Circular CSSF 24/850
15 December 2025
- Effective date of amendments in Circular CSSF 25/903, applicable to 2025 reporting cycle onwards
31 March annually Deadline
- Deadline for submission of descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF (first applicable for FY 2024 reporting due 31 March 2025)
End of February annually Deadline
- Support PFS must engage auditors and provide necessary data to enable timely report preparation
Suggested considerations
Annual Reporting Cycle:
1. By year-end, conduct internal self-assessment using the prescribed questionnaire template (available via CSSF portal).
February to review submissions, test controls, and issue management letter (flagging deficiencies) plus separate compliance report.
Governance Updates: Review and update internal policies on risk assessment, auditor selection, and remediation of management letter findings; ensure board oversight of submissions.
Auditor Coordination: Verify auditor qualifications per CSSF register; implement any remediation plans from prior-year management letters before next cycle.
Record-Keeping: Maintain 5-year audit trail of all supporting documentation for CSSF inspections.
What changed
- Standardized Reporting Templates: Introduces detailed formats and content requirements for the annual descriptive report and self-assessment questionnaire, covering governance, risk management,...
Auditor Engagement Rules: Mandates approved statutory auditors to perform specific procedures, issue a management letter highlighting control weaknesses, and prepare a separate report confirming...
Amendments via CSSF 25/903: Updates clarify submission procedures, expand self-assessment criteria (e.g., adding cybersecurity and outsourcing risk questions), and refine auditor independence...
Frequency and Scope: Annual submissions required without exceptions; scope limited to support PFS (not primary PFS), emphasizing substance over form in service descriptions.
Compliance impact
Urgency: High – This is a recurring annual obligation with a firm 31 March deadline, where delays trigger automatic CSSF notifications and potential fines (up to €250,000 per Law 1993). It matters for support PFS as it intensifies scrutiny on operational resilience in a post-SFI (2021) landscape, where CSSF prioritizes substance in delegated functions; failure risks de-authorization or client outflows. Early implementation of templates and auditor pipelines is essential to avoid first-year pitfalls.
amending Circular CSSF 22/811.Authorisation and organisation of entities acting as UCI administrators.
AI Analysis
Circular CSSF 25/900, issued on 16 December 2025, amends Circular CSSF 22/811 to clarify governance principles, authorisation requirements, and operational standards for UCI (Undertakings for Collective Investment) administrators in Luxembourg, while reforming annual reporting obligations. It matters because it strengthens supervisory oversight, aligns with DORA for ICT outsourcing, and simplifies reporting to enhance efficiency and compliance in the fund administration sector.
Key dates
January 2025
- DORA entry into force, applying to ICT outsourcing for in-scope UCIAs
16 December 2025
- Issuance date; repeal of Annex B of Circular CSSF 22/811 effective immediately
31 December 2025
- New reporting framework (SAQ and updated modalities) applies to all financial years ending on or after this date
Suggested considerations
Assess eligibility and obtain prior CSSF authorisation via Annex A application (or notify substantial changes); ensure ongoing validity by monitoring operational model and delegations.
Adapt internal processes for revised annual UCIA reporting (SAQ-focused, integrated where applicable); submit using CSSF website instructions starting for FY ending 31 Dec 2025.
Review/update contracts with UCIs/IFMs to define roles, responsibilities, and oversight; implement delegation monitoring, remediation plans, and ICT compliance (DORA/Circular 25/882 or 20/750).
For DORA-scope entities, align outsourcing arrangements with Circular CSSF 25/882.
What changed
- Repeals Annex B of Circular CSSF 22/811 with immediate effect, replacing it with streamlined annual reporting via a core compliance-focused Self-Assessment Questionnaire (SAQ) that assesses...
Introduces prior CSSF authorisation requirements for entities acting as UCI administrators, including a defined administrative procedure with application details in Annex A; authorisation remains...
Clarifies scope for eligible entities (e.g., UCIs, IFMs, management companies under Luxembourg law) performing one or more of three UCI administration functions (defined in point 10); mandates...
Aligns ICT outsourcing with DORA (effective January 2025) for in-scope UCIAs (credit institutions, investment fund managers, investment firms, certain support professionals), referencing Circular...
Strengthens delegation rules (section 3.5): prior CSSF notification for critical/important tasks, ongoing monitoring by UCI/IFM, and remediation plans for shortcomings.
Compliance impact
Urgency: High - Immediate repeal of prior reporting Annex requires prompt process updates; new framework applies to FY 2025 year-ends (just past as of Jan 2026), risking supervisory scrutiny or penalties for non-compliance; DORA alignment adds operational resilience pressure amid ongoing CSSF focus on fund admin governance.
Authorisation and organisation of entities acting as UCI administrators
AI Analysis
Circular CSSF 22/811, as amended by Circular CSSF 25/900, establishes CSSF requirements for the authorisation, governance, internal organisation, and oversight of entities acting as UCI (Undertakings for Collective Investment) administrators in Luxembourg. It matters because it standardises practices amid regulatory, technological, and market evolutions, ensuring robust controls, risk management, and supervision for fund administration activities critical to Luxembourg's fund industry.
Suggested considerations
Submit authorisation application to CSSF with Annex A information before commencing UCI administration; notify substantial changes and keep file updated.
Establish/implement governance, controls, escalation processes, resource adequacy, ICT/business continuity per circular; ensure single provider per function.
For delegations: Conduct due diligence, execute written contracts detailing roles/obligations, notify CSSF in advance, retain oversight without delegating monitoring.
Conclude written contracts with UCI/IFM; submit annual UCIA activity reports.
UCIs/IFMs: Supervise coordinators, ensure information exchange/cooperation with administrators.
What changed
- Authorisation Requirements: Prior CSSF authorisation is mandatory for appointment as UCI administrator, via full application under sectoral laws or a simplified administrative procedure;...
Scope of UCI Administration: Defines three core functions—registrar, NAV calculation/accounting, and client communication—requiring only one designated service provider per function per UCI (or...
Governance and Controls: Mandates sound governance principles, control frameworks, escalation processes for errors/incidents, adequate resources (human, ICT), business continuity, and compliance with...
Delegation Rules: Delegation of tasks allowed but not of monitoring/oversight; requires written contracts, due diligence, and prior CSSF notification (3 months generally, 1 month for certain agents);...
Contracts and Reporting: Written contracts between UCI administrator and UCI/IFM; annual activity reporting due 5 months after financial year-end, starting from financial years ending post-30 June...
Compliance impact
Urgency: High – Non-compliance risks CSSF sanctions, as authorisation is prior and ongoing; critical for Luxembourg fund ecosystem given evolutions in tech/markets/DORA. Firms must act promptly if unauthorised or misaligned, especially with annual reporting since 2023 and DORA integration; impacts operational models, delegations, and reporting immediately for active administrators.
This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.
Update of Circular CSSF 07/325 on Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services, as amended by Circulars CSSF 21/765 and CSSF 22/827
AI Analysis
Circular CSSF 25/898 updates Luxembourg's supervisory framework for EU-origin credit institutions and investment firms operating in Luxembourg through branches or free provision of services. This amendment enhances the self-assessment questionnaire (SAQ) used by the CSSF to align supervisory oversight with current regulatory priorities, particularly adding UCI administration as a new thematic module. The update reflects the CSSF's evolving supervisory focus and requires affected institutions to demonstrate compliance with expanded assessment criteria.
Key dates
31 October 2025
- Circular CSSF 25/898 published by the CSSF
19 December 2025
- Related modernization framework (Circular CSSF 25/901) entered into force for Part II UCIs, SIFs, and SICARs
No specific implementation deadline stated Deadline
- Institutions should align their SAQ responses and compliance documentation with the updated framework immediately upon publication
Suggested considerations
*Update Self-Assessment Processes
Revise internal SAQ completion procedures to address the new UCI administration module
Ensure all thematic modules reflect current supervisory expectations
*Assess UCI Administration Compliance
If the institution provides or is involved in UCI administration services, conduct a detailed assessment of compliance with CSSF expectations
What changed
The circular introduces the following material modifications to Circular CSSF 07/325:
New Supervisory Module
UCI administration has been added as a thematic module to the self-assessment questionnaire, reflecting increased regulatory attention to fund administration practices.
Enhanced Self-Assessment...
Existing modules have been updated to better align with supervisory objectives and current regulatory priorities.
The revised SAQ now captures a broader range of supervisory points of focus relevant to branch operations and cross-border service provision.
Scope Clarification
The circular applies to credit institutions whose head office is in another EU Member State and to investment firms of EU origin established in Luxembourg by way of branches or exercising activities...
This press release from the CSSF appears to be related to regulatory oversight and authorization for BGL BNP Paribas, a bank operating in the banking, investment management, and wealth management sectors.
This regulatory update from the CSSF in Luxembourg focuses on the use of artificial intelligence in the financial sector, which impacts banking, investment management, and wealth management firms.
This regulatory update relates to the mandate and audit charter for the Internal Auditors Committee of the Eurosystem/ESCB and the Single Supervisory Mechanism. It is relevant for banks, asset managers, and wealth managers as it covers prudential requirements, operational resilience, and reporting obligations.