Live Updates
🇱🇺 CSSF News Urgency: high Significant

Evolution of prudential reporting for payment institutions, electronic money institutions and crypto-asset service providers

No description available.

Why this matters

This is a policy statement from CSSF announcing a modernized prudential reporting framework with binding obligations for payment institutions, electronic money institutions, and crypto-asset service providers.

Payment ProviderCrypto ExchangeFintech
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 26/915

on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg

AI Analysis

CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 27 February 2027
BankBroker DealerPayment Provider
Crypto Exchange
🇱🇺 CSSF News Urgency: high Significant

Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

No description available.

AI Analysis

CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankPayment ProviderInsurance
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/883 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 22/806 on outsourcing arrangements

AI Analysis

Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: medium

Circular CSSF 25/892 (as amended by Circular CSSF 26/915) (Updated)

Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)

AI Analysis

CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
All FirmsBankAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/893 (as amended by Circular CSSF 25/915) (Updated)

on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)

AI Analysis

CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915) (Updated)

on outsourcing arrangements

AI Analysis

CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 31 December 2022
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915) (Updated)

Requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 27 August 2026
BankBroker DealerPayment Provider
All Firms
🇱🇺 CSSF Warning Urgency: high

Warning concerning the website www.melzapay.com

No description available.

Why this matters

This is a standard regulatory warning against an unlicensed entity (MelzaPay S.A.) claiming to offer financial services from Luxembourg without CSSF authorisation. The warning targets a specific fraudulent operator rather than establishing new obligations or precedent.

Payment ProviderFintech
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1940 of 7 August 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is an EU implementing regulation on restrictive measures (sanctions) related to Ukraine, published as informational content by CSSF. It affects financial institutions' compliance with sanctions screening and AML obligations. Classified as news/informational rather than urgent regulatory change, hence null urgency.

Effective Date: 8 August 2026
All Firms
🇱🇺 CSSF Warning Urgency: high

Warning concerning fraudulent activities performed under the name of the Luxembourg company Molentis S.A.

No description available.

Why this matters

CSSF warning of identity theft and fraudulent impersonation of Luxembourg-registered company Molentis S.A. Fraudsters using fake website, email, and claiming false registered office. High urgency due to active fraud scheme targeting financial sector participants and potential customers.

All Firms

Law of 12 November 2004 (consolidated version) (Updated)

on the fight against money laundering and terrorist financing

Why this matters

Consolidated legislative update on anti-money laundering and terrorist financing requirements applicable across financial services. Published as informational regulatory reference material by CSSF (Luxembourg regulator). Affects all regulated financial institutions.

All Firms
🇱🇺 CSSF News Significant

Council Regulation (EU) 2026/1844 of 23 July 2026

amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

EU sanctions regulation amending restrictive measures against Russia regarding Ukraine. This is informational regulatory update affecting financial institutions' compliance obligations for sanctions screening, reporting, and AML procedures.

Effective Date: 24 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Regulation (EU) 2026/1848 of 23 July 2026

amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine

Why this matters

This is an EU sanctions regulation amendment concerning Russia, published as regulatory news by CSSF. It affects financial institutions' compliance obligations regarding restrictive measures and sanctions screening.

Effective Date: 24 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1843 of 23 July 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is an EU implementing regulation on restrictive measures (sanctions) regarding Ukraine, published by CSSF as informational content. It affects financial institutions' compliance obligations for sanctions screening, reporting, and AML/CFT procedures.

Effective Date: 23 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Regulation (EU) 2026/1846 of 23 July 2026

amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine

Why this matters

This is an EU Council Regulation amending restrictive measures against Belarus and related to Russian aggression. It constitutes sanctions/restrictive measures that impact financial institutions' AML/sanctions compliance obligations.

Effective Date: 25 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1817 of 23 July 2026

implementing Article 8a(1) of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine

Why this matters

This is an EU implementing regulation concerning restrictive measures (sanctions) against Belarus and related entities. It impacts financial institutions' AML/sanctions compliance obligations across banking and payment sectors.

Effective Date: 25 July 2026
All Firms
🇱🇺 CSSF Warning Urgency: critical

Warning concerning the website www.carrera-finance.digital

No description available.

Why this matters

CSSF warning of fraudulent website impersonating legitimate financial services company. Involves identity theft, illicit activities, and unauthorized financial services provision. Critical urgency due to active fraud threat to consumers and need for immediate awareness across financial sector.

All Firms
🇱🇺 CSSF Enforcement Urgency: high Significant

Administrative sanction of 23 March 2026

Administrative sanction imposed on the members of the board of directors of an electronic money institution

AI Analysis

The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Payment ProviderFintechBank
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1779 of 17 July 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is an EU implementing regulation on restrictive measures (sanctions) regarding Ukraine, published as informational content by CSSF. It affects financial institutions' compliance obligations for sanctions screening, reporting, and AML/CFT procedures.

Effective Date: 17 July 2026
All Firms
🇱🇺 CSSF Warning Urgency: high

Warning concerning fraudulent activities by persons misusing the name of Clearstream Banking S.A.

No description available.

Why this matters

CSSF warning about fraudulent impersonation of Clearstream Banking S.A. using fake contact details. This is a financial crime alert requiring immediate awareness among market participants to prevent fraud victimization.

BankPayment Provider
🇱🇺 CSSF News Significant

Council Regulation (EU) 2026/1805 of 16 July 2026

amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine

Why this matters

This is an EU Council Regulation amending sanctions measures against Russia related to Ukraine. It affects financial institutions' compliance obligations regarding restrictive measures, sanctions screening, and reporting requirements. Published as regulatory news update by CSSF (Luxembourg financial regulator).

Effective Date: 18 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1710 of 13 July 2026

implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities

Why this matters

This is an implementing regulation for EU restrictive measures against Russia. It affects financial institutions' compliance obligations regarding sanctions screening, reporting, and asset freeze procedures.

Effective Date: 13 July 2026
All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1708 of 13 July 2026

implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia

Why this matters

This is an implementing regulation for EU restrictive measures related to Russia, published by CSSF as informational content. It affects financial institutions' compliance obligations regarding sanctions and restrictive measures. Classified as news/informational with null urgency.

Effective Date: 13 July 2026
All Firms
🇱🇺 CSSF Warning Urgency: critical

Warning concerning the fraudulent activities carried out by SB Systems sp. Zo.o

No description available.

Why this matters

CSSF warning against unauthorized entity SB Systems sp. Zo.o conducting fraudulent investment services from Luxembourg without authorization. Critical urgency due to active fraud alert requiring immediate awareness among regulated entities and consumers.

Fintech
🇱🇺 CSSF Enforcement Urgency: high Significant

Administrative sanction of 2 March 2026

Administrative sanction imposed on PingPong Europe S.A.

AI Analysis

The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Payment ProviderFintech

Evolving opportunities and risks in artificial intelligence and its adoption

No description available.

Why this matters

CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...

All Firms

MiCA: Transition period for virtual asset service providers ended on 1 July 2026

No description available.

Why this matters

Informational update from CSSF regarding the end of MiCA transition period for virtual asset service providers on 1 July 2026. Focuses on regulatory compliance requirements, consumer guidance on checking provider authorizations, and wind-down procedures for non-compliant providers.

Crypto ExchangeFintechPayment Provider
🇱🇺 CSSF Warning Urgency: high

Warning concerning the website www.urbanmint.io

No description available.

Why this matters

CSSF warning against unauthorized entity UrbanMint Digital Assets S.A. operating www.urbanmint.io without proper authorization or supervision. Warning highlights illicit activities and lack of regulatory approval to provide investment/financial services in Luxembourg.

Crypto ExchangeFintech
🇱🇺 CSSF Consultation Urgency: medium Significant

Public consultation by FATF by 21 August 2026 on guidance to increase payment transparency - “travel rule”

No description available.

AI Analysis

FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 21 August 2026
BankPayment ProviderCrypto Exchange
Fintech
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 26/914

Identification of obliged entities eligible for direct supervision by AMLA

AI Analysis

Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 22 July 2026
BankPayment ProviderCrypto Exchange
🇱🇺 CSSF Warning Urgency: high Significant

ESMA calls on unauthorised crypto-asset service providers to wind down orderly, while also safeguarding clients’ interests, as MiCA transitional period ends

No description available.

Why this matters

ESMA directive regarding wind-down of unauthorised crypto-asset service providers as MiCA transitional period concludes. High urgency due to regulatory deadline and mandatory compliance requirement for unauthorised providers, with emphasis on client asset safeguarding during transition.

Crypto ExchangeFintechPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Annex to Circular CSSF 22/822

1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 19 June 2026

AI Analysis

CSSF published a new **Annex to Circular CSSF 22/822** on **22 June 2026**, updating the Luxembourg regulator’s reference list of FATF **high-risk jurisdictions** and **jurisdictions under increased monitoring**. For compliance teams, this matters because AML/CFT country-risk scoring, enhanced due diligence triggers, and sanctions-style controls must be aligned to the current FATF position reflected by CSSF.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

BankAsset ManagerFintech

Corrigendum to Council Implementing Regulation (EU) 2026/695 of 14 March 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

Corrigendum to EU sanctions regulation concerning Ukraine. Affects financial institutions subject to restrictive measures compliance and reporting obligations. Published as regulatory update/news rather than urgent enforcement action.

All Firms
🇱🇺 CSSF News Significant

Corrigendum to Council Implementing Regulation (EU) 2024/849 of 12 March 2024

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is a corrigendum to EU sanctions regulation concerning Ukraine. It affects financial institutions' compliance with restrictive measures and sanctions screening requirements. Published as informational update by CSSF (Luxembourg regulator). Applies broadly to all financial firms subject to EU sanctions regulations.

All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1361 of 15 June 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is an EU implementing regulation on restrictive measures (sanctions) related to Ukraine. It affects financial institutions' compliance obligations regarding sanctions screening and AML/CFT procedures. Published as informational regulatory update by CSSF (Luxembourg financial regulator), hence null urgency.

Effective Date: 17 June 2026
All Firms
🇱🇺 CSSF News Significant

Council Implementing Regulation (EU) 2026/1356 of 15 June 2026

implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities

Why this matters

This is an implementing regulation for EU restrictive measures against Russia. It affects financial institutions' compliance obligations regarding sanctions screening, reporting, and asset freezing. Classified as informational news publication rather than new substantive requirement, hence null urgency.

Effective Date: 15 June 2026
All Firms
🇱🇺 CSSF News Significant

Council Regulation (EU) 2026/1336 of 15 June 2026

amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is a Council Regulation amending EU restrictive measures regarding Ukraine. It impacts financial institutions through sanctions compliance, AML/CFT obligations, and reporting requirements. Published as informational content by CSSF (Luxembourg financial regulator), so urgency is null.

Effective Date: 17 June 2026
All Firms

De-risking Practices and ML/FT Risk Management

No description available.

Why this matters

CSSF clarification on ML/FT risk management expectations, addressing de-risking practices and financial inclusion balance. Informational guidance to supervised entities on proper risk management frameworks rather than risk avoidance, with emphasis on proportionate customer assessment and cooperation requirements.

BankPayment Provider

Suspicious transaction and order reports (MiCAR STORs)

No description available.

Why this matters

MiCAR STORs (Suspicious Transaction and Order Reports) under the Markets in Crypto-Assets Regulation is a regulatory framework requirement for reporting suspicious activities. This is informational content from CSSF (Luxembourg financial regulator) about a public register related to audit profession oversight.

All Firms

Update: Identification of obliged entities that will be eligible for direct supervision by the European Authority for anti-money laundering and countering the financing of terrorism (AMLA)

Further details concerning the AMLA webinar of 10 June 2026 from 10 am to 12 pm CEST

Why this matters

This is an informational update from CSSF announcing a webinar by AMLA regarding identification of obliged entities eligible for direct supervision. It covers AML/CFT regulatory requirements applicable to multiple financial sectors and firm types.

All Firms
🇱🇺 CSSF News Significant

Corrigendum to Council Implementing Regulation (EU) 2026/1055 of 11 May 2026

implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine

Why this matters

This is a corrigendum to EU sanctions regulation concerning Ukraine. It affects financial institutions' compliance with restrictive measures and sanctions screening requirements. Classified as informational/news content rather than new substantive regulatory requirement, hence null urgency.

Effective Date: 11 May 2026
All Firms
🇱🇺 CSSF Warning Urgency: high

Warning concerning the website www.isladova.com

No description available.

Why this matters

CSSF warning against unauthorized entity claiming to provide investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk. Entity operating across multiple financial service categories without proper licensing.

Broker Dealer
🇱🇺 CSSF News Significant

Identification of obliged entities that will be eligible for direct supervision by the European Authority for anti-money laundering and countering the financing of terrorism (AMLA)

Preparation of the new data collection exercice for the purpose of the direct supervision by AMLA – AMLA webinar of 10 June 2026 from 10 am – 12 pm CEST

Why this matters

AMLA webinar announcement regarding identification of obliged entities eligible for direct supervision. Covers AML/CFT regulatory framework, data collection exercise, and reporting requirements. Applies broadly to all obliged entities under AMLA jurisdiction.

Response Due: 22 July 2026
All Firms
🇱🇺 CSSF Consultation Urgency: high Significant

Public consultation by AMLA on the draft RTS on group-wide minimum requirements and additional measures for subsidiaries and branches in third countries

No description available.

AI Analysis

The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 15 June 2026
BankAsset ManagerPayment Provider
🇱🇺 CSSF Consultation Urgency: high Significant

Public consultation by AMLA on the draft Guidelines on business-wide risk assessment

No description available.

AI Analysis

AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 15 July 2026
All Firms
🇱🇺 CSSF Warning Urgency: high

Warning concerning fraudulent activities by persons misusing the name of Coinbase Luxembourg S.A.

No description available.

Why this matters

This regulatory warning concerns fraudulent activities misusing the name of a licensed crypto-asset service provider and electronic money institution, Coinbase Luxembourg S.A.

Crypto ExchangeFintechPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 26/909

Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)

AI Analysis

Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 28 July 2026
Crypto ExchangeBankFintech
Payment Provider
🇱🇺 CSSF Warning Urgency: high

Warning concerning the website www.vivid-money.lu

No description available.

Why this matters

This is a warning from the CSSF regarding a fraudulent website impersonating a legitimate electronic money institution, VIVID MONEY S.A. The warning covers identity theft and illicit activities, which are relevant to AML/financial crime and consumer protection.

FintechPayment Provider
🇱🇺 CSSF Guidance Urgency: critical

Annex of Circular CSSF 22/822

1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 17 February 2026

AI Analysis

The Annex of Circular CSSF 22/822 (Version of 17 February 2026) is Luxembourg's Commission de Surveillance du Secteur Financier's implementation guidance on FATF (Financial Action Task Force) designations of high-risk jurisdictions requiring enhanced due diligence and counter-measures, as well as jurisdictions under increased monitoring. This document is critical for Luxembourg-regulated financial institutions because it operationalizes international AML/CFT standards into binding compliance obligations, directly impacting customer acceptance, transaction monitoring, and correspondent banking relationships.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 23 February 2026
BankAsset ManagerPayment Provider
🇱🇺 CSSF News Urgency: medium

DORA – Submission timeframe for register of information for third-country branches of credit institutions having their head office in a third country

No description available.

Why this matters

This regulatory update is relevant for third-country branches of credit institutions, as it sets a new submission timeframe for a register of information required under DORA. This impacts banking and payments firms operating in the EU.

BankPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular letter

AML/CFT standardised data collection taking place in 2026

AI Analysis

The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 15 April 2026
BankPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Guidance for interpretation and resolution of CSSF error messages related to the submission of the DORA register

Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.

AI Analysis

This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2026
BankFintechPayment Provider
🇱🇺 CSSF News Urgency: medium

PSD2 - PSP ICT Assessment – 2026 Campaign related to the financial year 2025

No description available.

Why this matters

This regulatory update is related to the annual PSD2 ICT assessment reporting requirement for payment service providers (PSPs) in Luxembourg. It provides details on the submission process and timeline, which is of medium importance for the affected firms.

Payment Provider
🇱🇺 CSSF News Urgency: medium

Outcomes of the 2025 SFTR Data Quality indicators review

The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025

Why this matters

This regulatory update from the CSSF focuses on the outcomes of the 2025 SFTR data quality review, which is relevant for banking, capital markets, and payments firms that are subject to SFTR reporting requirements.

BankBroker DealerPayment Provider
🇱🇺 CSSF News Urgency: medium

Publication of the update of the ML/FT Sub-Sector Risk Assessment on Specialised Professionals of the Financial Sector providing corporate services (trust and company service provider activities)

No description available.

Why this matters

This regulatory update is focused on the money laundering and terrorist financing risks associated with trust and company service provider (TCSP) activities within the financial sector in Luxembourg. It requires firms providing these services to integrate the findings and recommendations into their AML/CFT frameworks.

BankWealth ManagerPayment Provider
🇱🇺 CSSF Guidance Urgency: high Significant

New Circular CSSF 26/906 “Central administration, internal governance and risk management” applicable to payment and electronic money institutions

No description available.

AI Analysis

CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 30 June 2026
Payment ProviderFintech
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 26/906

Central administration, internal governance and risk management

AI Analysis

Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 30 June 2026
Payment Provider
🇱🇺 CSSF Enforcement Urgency: high

Population concerned by the enforcement

No description available.

AI Analysis

This CSSF publication, dated January 12, 2026, identifies the specific population (likely a firm or individual) subject to an enforcement action, such as an administrative sanction, as part of the CSSF's transparency in supervisory measures. It matters because it signals CSSF's active enforcement priorities, potentially in areas like AML or reporting failures, enabling firms to assess similar risks in their operations and strengthen compliance to avoid parallel actions. Published amid rising focus on financial crime typologies like sexual extortion, it underscores the regulator's commitment to public accountability.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

BankPayment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF-CPDI 25/49

Survey on the amount of covered deposits held on 31 December 2025

AI Analysis

Circular CSSF-CPDI 25/49 is a **mandatory quarterly reporting requirement** for Luxembourg credit institutions and postal financial service providers to submit data on covered deposits as of December 31, 2025. This survey directly feeds into the Single Resolution Fund's annual target level calculation and the Luxembourg deposit guarantee scheme's contribution assessments, making it essential for regulatory compliance and fund management.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 22 January 2026
BankPayment Provider
🇱🇺 CSSF Enforcement Urgency: high Significant

Circular CSSF 25/896

Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)

AI Analysis

Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 30 December 2025
BankPayment ProviderCrypto Exchange