Live Updates
🇱🇺 CSSF News Urgency: high

Communication to the Investment Fund Industry regarding the requirement to notify the “suspension of redemption (only)” in the “LMT activation” module related to liquidity management requirements

for Luxembourg-domiciled funds subject to the 2010 Law relating to UCIs, specialised investment funds governed by the Law of 13 February 2007, and investment companies in risk capital governed by the Law of 15 June 2004.

Why this matters

This is a CSSF communiqué establishing mandatory notification procedures through the eDesk 'LMT activation' module for suspension of redemptions under national law. The update implements transposition of EU Directive 2024/927 and applies to UCIs, specialised investment funds, and risk capital investment companies.

Asset ManagerHedge Fund
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 26/915

on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg

AI Analysis

CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 27 February 2027
BankBroker DealerPayment Provider
Crypto Exchange
🇱🇺 CSSF News Urgency: high Significant

Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

No description available.

AI Analysis

CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankPayment ProviderInsurance
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated)

on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)

AI Analysis

Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankAsset ManagerFintech
Crypto Exchange
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/883 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 22/806 on outsourcing arrangements

AI Analysis

Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: medium

Circular CSSF 25/892 (as amended by Circular CSSF 26/915) (Updated)

Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)

AI Analysis

CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
All FirmsBankAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/893 (as amended by Circular CSSF 25/915) (Updated)

on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)

AI Analysis

CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915) (Updated)

on outsourcing arrangements

AI Analysis

CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 31 December 2022
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915) (Updated)

Requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 27 August 2026
BankBroker DealerPayment Provider
All Firms

Scheduled maintenance on Friday, 7 August 2026 between 12pm and 2pm

No description available.

Why this matters

This is a routine maintenance notification from CSSF (Luxembourg financial regulator) regarding scheduled system downtime. It is informational content affecting operational continuity for all regulated firms using CSSF services. No specific sector applies as this is infrastructure-related.

All Firms

Application for administrative authorisation to act as UCI depositary (Updated)

Version 3.3

Why this matters

This is an administrative form update from CSSF for UCI depositary authorization applications. It is informational/procedural content regarding licensing requirements for entities acting as depositaries for Undertakings for Collective Investment.

Asset ManagerBank

Launch of the ESMA Common Supervisory Action on the risk management function of UCITS Management Companies and Alternative Investment Fund Managers

No description available.

Why this matters

ESMA Common Supervisory Action targeting UCITS Management Companies and Alternative Investment Fund Managers on risk management function effectiveness. Focuses on governance, risk identification/measurement/monitoring, and reporting requirements.

Asset ManagerHedge Fund
🇱🇺 CSSF Enforcement Urgency: high Significant

Administrative sanction of 23 March 2026

Administrative sanction imposed on the members of the board of directors of an electronic money institution

AI Analysis

The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Payment ProviderFintechBank
🇱🇺 CSSF Enforcement Urgency: high Significant

Administrative sanction of 2 March 2026

Administrative sanction imposed on PingPong Europe S.A.

AI Analysis

The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Payment ProviderFintech

Evolving opportunities and risks in artificial intelligence and its adoption

No description available.

Why this matters

CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...

All Firms

Communication to the investment fund industry in relation to the notification of the intention of a Luxembourg-based investment fund manager to provide ancillary services to third parties

under Article 5(4)(b)(iv) of the Law of 2013 and/or Article 101(3)(b), fourth indent of the Law of 2010 as introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council of 13 March 2024

Why this matters

CSSF communication announcing new notification procedures for Luxembourg-based investment fund managers seeking to provide ancillary services to third parties under transposed EU Directive 2024/927. Informational guidance on regulatory requirements and form submission process.

Asset Manager

The European Banking Authority published a Report on simplifying the stacking orders of the EU prudential and resolution framework

No description available.

Why this matters

EBA report on simplifying EU prudential and resolution framework stacking orders. Informational publication addressing regulatory complexity reduction while maintaining resilience standards. Primarily impacts banks' capital requirements and resolution frameworks.

Bank
🇱🇺 CSSF Consultation Urgency: high

Rappel de l’importance de participer aux initiatives T+1 (enquêtes et consultations publiques)

No description available.

AI Analysis

CSSF is pressing Luxembourg market participants to complete T+1 readiness surveys by **9 June 2026** and to engage with ESMA’s broader T+1 consultation work, because the EU settlement cycle moves to **T+1 on 11 October 2027** under CSDR. The publication matters because it signals that supervisors are already assessing industry preparedness and that firms must accelerate post-trade process changes, especially around allocations, confirmations, and electronic messaging.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 9 June 2026
Asset ManagerBankBroker Dealer
🇱🇺 CSSF Consultation Urgency: high

Reminder of the importance of participating in T+1 initiatives (surveys and public consultations)

No description available.

AI Analysis

CSSF reminds Luxembourg market participants that the EU move to a **T+1 settlement cycle under CSDR on 11 October 2027** is now in execution phase and links this directly to concrete supervisory tools: mandatory-like readiness surveys, RTS on Settlement Discipline amendments, and new ESMA post‑trade communication guidelines. For compliance teams, this is a front‑to‑back operating model change: firms must demonstrate T+1 readiness to CSSF/ESMA, transition to fully electronic, standardised post‑trade communication, and align allocations/confirmations processes to tighter regulatory timelines.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 9 June 2026
BankBroker DealerAsset Manager
🇱🇺 CSSF Consultation Urgency: high Significant

Public consultation by AMLA on the draft Guidelines on business-wide risk assessment

No description available.

AI Analysis

AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 15 July 2026
All Firms
🇱🇺 CSSF News Urgency: critical

Active supply chain attack targeting Axios NPM

No description available.

Why this matters

This is a critical supply chain attack targeting the widely used Axios HTTP client library, which is central to many architectures. The compromise of the build pipeline can result in remote code execution, credential theft, and lateral movement within the information system.

BankFintechAsset Manager
Wealth Manager
🇱🇺 CSSF News Urgency: medium

Law of 18 December 2015 (consolidated version) (being updated) (Updated)

on the failure of credit institutions and certain investment firms

Why this matters

This regulatory update relates to the law on the failure of credit institutions and certain investment firms, which is being updated. It covers prudential and operational requirements, as well as authorization and licensing for banks, wealth managers, and asset managers.

BankWealth ManagerAsset Manager
🇱🇺 CSSF News Urgency: medium

Fund Pre-Inception Readiness Review (Updated)

No description available.

Why this matters

This regulatory update from the CSSF covers a pre-inception readiness review for managed file transfer (MFT) services, which is relevant for investment management firms, wealth managers, and banks.

Asset ManagerBankWealth Manager
🇱🇺 CSSF News Urgency: medium

The CSSF's 2026 priorities for supervising the investment fund sector

No description available.

Why this matters

This regulatory update from the CSSF outlines key supervisory priorities for the investment fund sector in 2026, covering areas such as governance/operational risks, ICT/cyber risks, liquidity and credit risks, contagion risks, asset valuation, sustainable finance, and costs/fees.

Asset Manager
🇱🇺 CSSF Warning Urgency: high

Warning concerning persons misusing the name of the Chair of the CSSF Board

(first publication: 30 October 2024)

Why this matters

This is a warning from the CSSF about fraudsters misusing the name of the CSSF Board Chair to contact supervised entities. It is relevant for banks, wealth managers, and all financial firms that may be targeted by such fraud attempts. The warning covers consumer protection, AML, and operational resilience topics.

BankWealth Manager

Development of the bank's balance sheet total

Situation as at 31 December 2025

Why this matters

This regulatory update provides quarterly statistics on the development of banks' balance sheet totals, which is relevant for prudential requirements, reporting, and operational resilience. It covers a range of banking and investment management firms.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: low

Quarterly development of employment in banks

Situation as at 31 December 2025

Why this matters

This regulatory update provides quarterly statistics on employment in the banking sector, which is relevant for banks, asset managers, and wealth managers from a prudential, reporting, and operational resilience perspective.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: medium

Legal department - Consumer protection / financial crime (Updated)

Out-of-court consumer complaint resolution

Why this matters

This regulatory update from the CSSF covers consumer protection and financial crime issues, which are relevant for banking, wealth management, and fintech firms. The medium urgency reflects the ongoing nature of these compliance requirements.

BankWealth ManagerFintech
🇱🇺 CSSF News Urgency: high

eDesk – Disruptions on Monday 16 March 2026

No description available.

Why this matters

This regulatory update from the CSSF relates to disruptions on the eDesk platform, which is likely a critical operational system for financial firms. The impact could be widespread across banking, investment management, and wealth management firms, as well as fintechs that rely on the eDesk platform.

BankWealth ManagerFintech
🇱🇺 CSSF News Urgency: low

Profit and loss account of credit institutions as at 31 December 2025 (only in French)

Press release 26/06

Why this matters

This regulatory update provides information on the profit and loss account of credit institutions in Luxembourg as of 31 December 2025. It covers key financial metrics such as net interest margin, net commission income, and general expenses.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: medium

Identification of reporting requirements and checks for 2nd level completeness (Updated)

No description available.

Why this matters

This regulatory update identifies reporting requirements and completeness checks, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and disclosure perspective.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: medium

DORA – Submission timeframe for register of information for third-country branches of credit institutions having their head office in a third country

No description available.

Why this matters

This regulatory update is relevant for third-country branches of credit institutions, as it sets a new submission timeframe for a register of information required under DORA. This impacts banking and payments firms operating in the EU.

BankPayment Provider
🇱🇺 CSSF News Urgency: medium

DORA – Submission timeframe for register of information – eDesk Portal open as of 11 February 2026

Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)

Why this matters

This regulatory update from the CSSF provides details on the submission timeframe and process for the DORA register of information, which is relevant for banking, investment management, and wealth management firms. It covers operational resilience, reporting, and technology/cyber topics.

BankAsset ManagerWealth Manager
🇱🇺 CSSF Guidance Urgency: high

Guidance for interpretation and resolution of CSSF error messages related to the submission of the DORA register

Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.

AI Analysis

This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2026
BankFintechPayment Provider
🇱🇺 CSSF News Urgency: critical

Active exploitation of vulnerabilities on Ivanti Endpoint Manager Mobile (EPMM)

CVE-2026-1281 & CVE-2026-1340

Why this matters

The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM.

BankWealth ManagerFintech
🇱🇺 CSSF News Urgency: low

Quarterly development of employment in support PFS

Situation as at 31 December 2025

Why this matters

This regulatory update provides quarterly employment statistics for support PFS firms, which is informational in nature and does not indicate any urgent regulatory changes or actions.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: low

Balance sheet total and net result of support PFS

Situation as at 31 December 2025

Why this matters

This regulatory update provides annual statistics on the balance sheet total and net result of support PFS firms in Luxembourg. It is informational in nature and does not appear to require immediate action, hence the low urgency level.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: medium

PSD2 - PSP ICT Assessment – 2026 Campaign related to the financial year 2025

No description available.

Why this matters

This regulatory update is related to the annual PSD2 ICT assessment reporting requirement for payment service providers (PSPs) in Luxembourg. It provides details on the submission process and timeline, which is of medium importance for the affected firms.

Payment Provider
🇱🇺 CSSF News Urgency: medium

Outcomes of the 2025 SFTR Data Quality indicators review

The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025

Why this matters

This regulatory update from the CSSF focuses on the outcomes of the 2025 SFTR data quality review, which is relevant for banking, capital markets, and payments firms that are subject to SFTR reporting requirements.

BankBroker DealerPayment Provider
🇱🇺 CSSF News Urgency: low

List of members of the Consultative Committee for Prudential Regulation (Updated)

No description available.

Why this matters

This is an informational update on the members of the Consultative Committee for Prudential Regulation, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and authorization perspective.

BankAsset ManagerWealth Manager
🇱🇺 CSSF News Urgency: medium

Resolution Reporting Requirements - track changes

No description available.

Why this matters

This regulatory update relates to resolution reporting requirements, which is relevant for banking, investment management, and wealth management firms. The topics covered include reporting and disclosure, prudential/capital requirements, and operational resilience.

BankAsset ManagerWealth Manager
🇱🇺 CSSF Guidance Urgency: high Significant

New Circular CSSF 26/906 “Central administration, internal governance and risk management” applicable to payment and electronic money institutions

No description available.

AI Analysis

CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 30 June 2026
Payment ProviderFintech
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 26/906

Central administration, internal governance and risk management

AI Analysis

Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 30 June 2026
Payment Provider
🇱🇺 CSSF News Urgency: high

Resolution Reporting Requirements (Updated)

No description available.

Why this matters

This regulatory update on resolution reporting requirements is relevant for banking, investment management, and wealth management firms. It covers prudential and capital requirements, reporting and disclosure obligations, as well as operational resilience considerations.

BankAsset ManagerWealth Manager

SSM Calendar Claude Wampach – 10/2025

No description available.

Why this matters

This appears to be an informational update from the CSSF regarding the SSM Calendar Claude Wampach, which is likely relevant for banks, wealth managers, and asset managers operating in the banking and investment management sectors.

BankWealth ManagerAsset Manager
🇱🇺 CSSF Guidance Urgency: low

Circular CSSF 19/708 - Annex (Updated)

Electronic transmission of documents to the CSSF

AI Analysis

Circular CSSF 19/708 mandates the electronic transmission of specified documents to the CSSF via secure platforms like e-file or SOFiE, effective from February 1, 2019, replacing prior paper or other methods. This updated annex (as amended by Circular CSSF 21/790 and further revisions up to April 1, 2025) standardizes submissions for investment funds and related entities, reducing administrative burdens while ensuring document integrity and CSSF accessibility. Compliance professionals must monitor the dynamic annex list on the CSSF website to avoid nullified submissions.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 1 February 2019
Asset ManagerWealth ManagerInsurance
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 24/853 (as amended by Circulars CSSF 25/870 and 26/904) (Updated)

Long Form Report – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms – Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors)

Compliance Deadline: 31 March 2026
Broker DealerWealth ManagerAsset Manager
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/903

Update of Circular CSSF 24/850 on the practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS, as well as the engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning…

AI Analysis

Circular CSSF 25/903 updates Circular CSSF 24/850, refining practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg regarding their annual descriptive report, self-assessment questionnaire, and the roles of approved statutory auditors (réviseurs d’entreprises agréés). It specifies requirements for auditors' engagement, management letters, and separate annual reports. This matters for support PFS as it enhances supervisory oversight, ensures consistent reporting quality, and strengthens internal controls, directly impacting compliance and audit processes amid CSSF's focus on robust PFS supervision.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 31 July 2026
FintechPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 24/850 (as amended by Circular CSSF 25/903) (Updated)

Practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS.Engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be…

AI Analysis

Circular CSSF 24/850, as amended by Circular CSSF 25/903, establishes practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg to submit annual descriptive reports and self-assessment questionnaires, while also defining the roles of approved statutory auditors (réviseurs d’entreprises agréés) in issuing management letters and separate reports. This guidance standardizes supervisory reporting and audit processes to enhance oversight of support PFS, which provide essential back-office services to authorized PFS. It matters because non-compliance risks supervisory sanctions, reputational damage, and operational disruptions for entities reliant on support PFS structures.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 31 July 2026
BankWealth Manager
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/900

amending Circular CSSF 22/811.Authorisation and organisation of entities acting as UCI administrators.

AI Analysis

Circular CSSF 25/900, issued on 16 December 2025, amends Circular CSSF 22/811 to clarify governance principles, authorisation requirements, and operational standards for UCI (Undertakings for Collective Investment) administrators in Luxembourg, while reforming annual reporting obligations. It matters because it strengthens supervisory oversight, aligns with DORA for ICT outsourcing, and simplifies reporting to enhance efficiency and compliance in the fund administration sector.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 December 2025
Asset ManagerWealth ManagerBank
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 22/811 (as amended by Circular CSSF 25/900) (Updated)

Authorisation and organisation of entities acting as UCI administrators

AI Analysis

Circular CSSF 22/811, as amended by Circular CSSF 25/900, establishes CSSF requirements for the authorisation, governance, internal organisation, and oversight of entities acting as UCI (Undertakings for Collective Investment) administrators in Luxembourg. It matters because it standardises practices amid regulatory, technological, and market evolutions, ensuring robust controls, risk management, and supervision for fund administration activities critical to Luxembourg's fund industry.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2026
Asset ManagerBank
🇱🇺 CSSF News Urgency: high

Supply-chain attack using NPM packages

Press release 25/18

Why this matters

This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.

BankFintech
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/898

Update of Circular CSSF 07/325 on Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services, as amended by Circulars CSSF 21/765 and CSSF 22/827

AI Analysis

Circular CSSF 25/898 updates Luxembourg's supervisory framework for EU-origin credit institutions and investment firms operating in Luxembourg through branches or free provision of services. This amendment enhances the self-assessment questionnaire (SAQ) used by the CSSF to align supervisory oversight with current regulatory priorities, particularly adding UCI administration as a new thematic module. The update reflects the CSSF's evolving supervisory focus and requires affected institutions to demonstrate compliance with expanded assessment criteria.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

BankBroker DealerAsset Manager

Press release regarding BGL BNP Paribas

Press release 25/13

Why this matters

This press release from the CSSF appears to be related to regulatory oversight and authorization for BGL BNP Paribas, a bank operating in the banking, investment management, and wealth management sectors.

Bank
🇱🇺 CSSF News Urgency: medium

Second thematic review on the use of Artificial Intelligence in the Luxembourg financial sector

Press release 25/08

Why this matters

This regulatory update from the CSSF in Luxembourg focuses on the use of artificial intelligence in the financial sector, which impacts banking, investment management, and wealth management firms.

BankAsset ManagerWealth Manager
Fintech
🇱🇺 CSSF News Urgency: medium

Internal Auditors Committee Mandate and Audit Charter for the Eurosystem/ESCB and the Single Supervisory Mechanism

No description available.

Why this matters

This regulatory update relates to the mandate and audit charter for the Internal Auditors Committee of the Eurosystem/ESCB and the Single Supervisory Mechanism. It is relevant for banks, asset managers, and wealth managers as it covers prudential requirements, operational resilience, and reporting obligations.

BankAsset ManagerWealth Manager