Technology & Cyber regulatory updates from Luxembourg.
We track 47 Technology & Cyber updates from Luxembourg regulators, published by CSSF. The archive covers 31 news items, 9 guidance notes and 6 warnings. Most recent update: September 2026. Coverage runs from 2025 to 2026.
The CSSF alert addresses active exploitation of CVE-2026-76461, an unauthenticated remote code execution vulnerability in Cisco Secure Email Gateway affecting email parsing.
Launch of the public API for the consultation of fund identification data
Why this matters
This is an informational announcement about a new CSSF service (eRegister by eDesk) providing API access to fund identification data. It describes a voluntary, opt-in tool requiring prior agreement rather than imposing binding obligations.
on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg
AI Analysis
CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.
Key dates
2025-01-17
DORA became applicable to financial entities within the CSSF supervisory perimeter.
2025-12-17
The European Commission confirmed through DORA Q&A DORA102-3097 that DORA applies to qualifying third-country branches in an EU country.
2026-08-27
Circular CSSF 26/915 was published and its amendments took effect immediately.
2027-02-27 Deadline
The six-month transition period for PSPs not otherwise subject to DORA under Circular CSSF 25/893 is expected to end; the DORA incident-reporting framework then applies to those PSPs and Circular CSSF 21/787 is repealed for them.
2027-03-31 Deadline
Latest date in the annual CSSF register-of-information submission window for arrangements contracted during 2026, subject to the applicable CSSF collection process.
Suggested considerations
Firms should map each Luxembourg third-country branch against the DORA Article 2(1)(a) to (t) categories as the undertaking would be classified in the third country, documenting the legal-entity and regulatory-status analysis.
Compliance teams may wish to update the branch's regulatory inventory, DORA applicability assessment, governance documentation and responsibility matrices to reflect immediate inclusion where the qualifying test is met.
Affected branches should review ICT third-party-service contracts, the register of information and planned arrangements supporting critical or important functions, including whether CSSF notification was made at least three months before implementation or one month where the specified Luxembourg support-PFS exception applies.
Firms should distinguish ICT outsourcing from other outsourcing: ICT outsourcing should be managed under the DORA framework and Circular CSSF 25/882, while non-ICT outsourcing remains subject to Circular CSSF 22/806 Part I.
Incident-response teams should test the CSSF eDesk Portal and S3 API reporting channels and maintain a contingency process for notifying ictrisksupervision@cssf.lu by the applicable deadline if technical failure prevents use of the primary channel.
Firms should confirm that major ICT incidents are reported individually and that outsourced reporting arrangements preserve the firm's responsibility for timing, completeness and notification content.
Affected branches should assess whether they are microenterprises under DORA Article 3(60), since Circular CSSF 25/892 excludes microenterprises from its aggregated-cost estimation framework, except for trading venues, central counterparties, trade repositories and central securities depositories.
Where the branch is an EU branch rather than a third-country branch, firms should verify the home-Member-State allocation rules because the CSSF circulars generally exclude EU branches from the relevant Luxembourg reporting chapters.
What changed
The circular implements the European Commission's 17 December 2025 DORA Q&A position and includes qualifying third-country branches in the scope of Circulars CSSF 25/882 on ICT third-party services, 25/892 on aggregated annual costs and losses from major ICT incidents, and 25/893 on major ICT-related incident and significant cyber-threat reporting.
Compliance impact
The impact is high for affected third-country branches because the clarification brings them into DORA governance, ICT third-party-service, register-of-information, incident-reporting and loss-estimation regimes immediately, while removing reliance on Circulars 20/750 and 22/806 Part II for ICT matters. The CSSF states that missed notification deadlines or non-compliant arrangements may be treated as not notified and may lead to supervisory or administrative measures; outsourcing reporting does not transfer responsibility away from the branch.
CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.
Key dates
2025-01-17
DORA began applying to in-scope financial entities supervised by the CSSF.
2025-12-17
The European Commission confirmed through DORA Q&A 102 that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF’s extended best-efforts deadline for the first register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2026-08-27
Circular CSSF 26/915 was published and took effect immediately; the listed CSSF circulars were amended to include or remove qualifying third-country branches as applicable.
2027-03-31 Deadline
Target date identified by CSSF for the required-quality register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2027-01-11
Relevant CRD VI third-country-branch provisions are scheduled to take effect, subject to national transposition and applicable transitional rules.
Suggested considerations
Firms should map each Luxembourg third-country branch against the counterfactual test in Circular 26/915: whether the head-office undertaking would qualify under Article 2(1)(a) to (t) of DORA if established in the relevant third country.
Affected branches should update their regulatory-perimeter inventories, governance documents, ICT-risk policies, outsourcing inventories, incident-classification procedures and DORA control testing to reflect immediate inclusion in the DORA-specific CSSF circulars.
Compliance teams may wish to separate non-ICT outsourcing, which remains subject to Part I of Circular CSSF 22/806, from ICT outsourcing, which is governed by DORA and Circular CSSF 25/882 rather than the legacy Part II framework.
Affected entities should validate their register-of-information process under DORA and Circular CSSF 25/882, including branch-level data, ICT third-party contracts, intra-group arrangements and submission ownership. The 30 June 2026 best-efforts deadline for third-country branches of credit institutions has passed, and firms should prepare for the 31 March 2027 collection and any CSSF remediation requests.
Incident-response teams should test access to the CSSF eDesk procedure and S3 API and document an escalation process for emailing ictrisksupervision@cssf.lu when technical impossibility prevents electronic submission.
Firms should assess whether they qualify for the microenterprise exclusion in Circular CSSF 25/892; the exclusion applies to entities employing fewer than 10 persons with annual turnover and/or annual balance-sheet total not exceeding EUR 2 million, subject to the DORA definition and exclusions for specified market infrastructures.
Third-country banking groups should coordinate DORA implementation with the CRD VI third-country-branch analysis, including the 11 January 2027 effective date for relevant CRD VI provisions, rather than assuming that the two regimes have identical scope or timing.
What changed
Qualifying third-country branches are added to the scope of Circulars CSSF 25/882, 25/892 and 25/893, covering DORA ICT third-party-service information and reporting, estimation of aggregated annual costs and losses from major ICT-related incidents under Article 11(11) of DORA and the Joint ESA Guidelines JC/GL/2024/34, and reporting of major ICT-related incidents and significant cyber threats.
Compliance impact
The impact is high for affected Luxembourg third-country branches because Circular 26/915 makes DORA-specific ICT third-party, incident-reporting and operational-resilience obligations immediately applicable and removes reliance on legacy ICT frameworks. Non-compliance may create supervisory findings, missed DORA reporting deadlines and deficiencies in ICT third-party oversight or incident governance; the CSSF does not describe a new penalty schedule in this publication.
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).
Key dates
2025-01-17
DORA became applicable to financial entities within its scope, subject to the specific DORA provisions and technical standards applicable to each entity.
2025-04-09
Circular CSSF 25/881 was published and took effect, removing DORA financial entities from Circular 20/750 and retaining 20/750 for entities outside DORA; PSP-specific provisions were reorganised under Circular 25/880.
2026-06-30 Deadline
CSSF extended the first Register of Information submission for Luxembourg branches of third-country credit institutions to this date on a best-efforts basis; the CSSF indicated that the required level of quality should be achieved for the 2027 submission.
2026-08-27
Circular CSSF 26/915 was published, confirming the DORA treatment of qualifying third-country branches and removing them from the full scope of Circular 20/750 and related overlapping circular provisions.
2027-03-31 Deadline
Target date identified by the CSSF for the required-quality Register of Information submission by Luxembourg branches of third-country credit institutions.
Suggested considerations
Firms should classify each Luxembourg entity and branch against DORA Article 2 and the amended scope of Circular 20/750, including an assessment of whether a third-country head office would qualify under DORA Article 2(1)(a) to (t).
Compliance teams may wish to determine whether the entity should operate under DORA rather than 20/750, and document the rationale, legal-entity perimeter and treatment of any Luxembourg branch.
Firms remaining within Circular 20/750 should consider reviewing their ICT and security-risk-management framework, governance approvals, risk assessments, incident processes, business-continuity arrangements and control testing against the continuing requirements.
Payment service providers should consider replacing references to the PSP provisions formerly contained in Circular 20/750 with the applicable requirements in Circular CSSF 25/880 and EBA/GL/2025/02.
Third-country branches treated as DORA entities should consider validating their DORA governance, ICT-risk framework, incident-reporting arrangements, ICT contractual inventory and Register of Information processes, taking account of CSSF reporting communications.
Firms should update policies, regulatory inventories, outsourcing and ICT-third-party registers, training materials and regulatory mapping to distinguish DORA obligations from the residual Circular 20/750 obligations.
Compliance teams may wish to retain evidence of the scope assessment and implementation date, because the 2025 amendment was effective immediately and the 2026 amendment changes the treatment of a previously identified 20/750 population.
What changed
Circular 25/881 provides that DORA financial entities supervised by the CSSF no longer fall within Circular 20/750; for entities covered by 20/750 but outside DORA, the circular continues to apply in full. Payment-service-provider-specific ICT and security-risk provisions were removed from 20/750 and regrouped in Circular CSSF 25/880, reflecting the revised EBA Guidelines on ICT and security risk management for payment service providers, including EBA/GL/2025/02.
Compliance impact
The principal impact is perimeter and framework migration rather than a wholly new ICT-control standard: entities in DORA must avoid relying on residual 20/750 requirements where DORA governs, while non-DORA entities retain substantive 20/750 obligations. The CSSF and market commentary indicate that misclassification may create gaps in DORA governance, ICT-third-party documentation, incident reporting and Register of Information submissions, with potential supervisory findings and related remediation or enforcement consequences.
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
AI Analysis
Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.
Key dates
2025-01-17
DORA became applicable to in-scope financial entities, according to the CSSF implementation communication referenced by Circular CSSF 25/882.
2025-04-09
Circular CSSF 25/882 was published and applied with immediate effect.
2025-04-01 Deadline
The first exceptional CSSF register submission window opened for arrangements contracted up to 31 March 2025.
2025-04-15 Deadline
The first exceptional CSSF register submission window closed.
2026-08-27
Circular CSSF 26/915 was published and immediately amended Circular CSSF 25/882 to include qualifying third-country branches in Luxembourg.
2027-03-31 Deadline
Latest date for submission of the register covering arrangements contracted through the end of 2026, under the recurring annual window running from 28 February to 31 March of the following year.
Suggested considerations
Firms should assess whether Luxembourg third-country branches now fall within the amended scope by comparing the branch’s undertaking and head-office activities with the DORA categories in Article 2(1)(a) to (t) and documenting the conclusion.
Compliance teams may wish to inventory all ICT third-party arrangements, including digital, data, cloud, infrastructure and operational services that may not qualify as outsourcing under prior CSSF terminology.
Firms should consider updating ICT third-party approval workflows so arrangements supporting critical or important functions are notified through the CSSF-prescribed form at least three months before commencement, or one month before commencement where the provider is an eligible Luxembourg support PFS.
Firms should maintain an accurate register of information at individual, sub-consolidated and consolidated levels, with controls for prompt correction when requested by the CSSF and the ability to provide the register outside the annual submission window.
Compliance and outsourcing teams may wish to reassess contractual access to professional-secrecy data against Article 41(2a) LFS or Article 30(2a) LPS and verify that Luxembourg ICT management or operations providers hold the required Article 29-3 LFS authorisation or qualify for an applicable exception.
Firms using cloud services should confirm that the resource operator has designated a suitably qualified cloud officer and that internal cloud, information-security and third-party oversight responsibilities are clearly allocated.
Third-country branches should consider implementing the requirements immediately because Circular CSSF 26/915 provides no transition period, while preserving evidence of governance, notification and register controls for supervisory review.
What changed
Circular CSSF 26/915 includes in Circular CSSF 25/882’s scope all Luxembourg third-country branches of undertakings covered by the specified DORA financial-entity categories where the head office would qualify as a DORA entity under Article 2(1)(a) to (t) in the relevant third country. The requirements apply to ICT services broadly, not only arrangements that meet a traditional outsourcing definition.
Compliance impact
The amendment materially increases the population subject to Luxembourg’s ICT third-party controls because qualifying third-country branches must comply immediately, without a transition period. Non-compliance may leave arrangements formally untreated as notified and expose firms to supervisory measures, binding measures and administrative sanctions, while firms remain fully responsible for compliance and for the resilience and governance of their ICT third-party providers.
amending Circular CSSF 22/806 on outsourcing arrangements
AI Analysis
Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.
Key dates
2025-01-17
DORA began applying to financial entities within its scope, subject to the relevant provisions and transitional arrangements.
2025-04-09
Circular CSSF 25/883 was published and applied with immediate effect, amending Circular CSSF 22/806 and introducing the DORA-based division between ICT and business-process outsourcing.
2025-12-17
The European Commission confirmed through a DORA Q&A that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF-extended submission date for the 2026 DORA register of information for third-country branches of credit institutions headquartered in a third country; entities were invited to submit on a best-efforts basis.
2026-08-27
Circular CSSF 26/915 was published and applied with immediate effect, confirming the DORA treatment of qualifying Luxembourg third-country branches and updating Circular CSSF 22/806 accordingly.
2027-03-31 Deadline
Target CSSF submission deadline for the DORA register of information for affected third-country branches following the initial 2026 collection.
Suggested considerations
Firms should classify each outsourcing arrangement as ICT or non-ICT and determine whether the entity and arrangement fall within DORA, Circular 22/806, or both regimes in their respective areas of application.
DORA entities should consider moving ICT arrangements from their Circular 22/806 outsourcing inventory and controls into the DORA ICT third-party register, while retaining Circular 22/806 controls for business-process outsourcing.
Non-DORA entities should consider continuing to apply the full Circular 22/806 framework to ICT and business-process outsourcing, including due diligence, governance, critical-or-important assessments, monitoring, sub-outsourcing and exit planning.
Third-country branches should assess whether their head office would qualify under Article 2(1)(a) to (t) of DORA and, if so, align ICT governance, contractual arrangements, registers and reporting with DORA rather than relying solely on Circular 22/806.
Compliance teams may wish to review cloud contracts and avoid carrying forward legacy EEA governing-law or hosting clauses where DORA now provides the applicable framework, while preserving enforceable audit, access, cooperation, security, business-continuity and exit rights.
Firms should use the revised CSSF notification form for new critical or important ICT outsourcing arrangements and preserve evidence supporting the three-month notification period, or the one-month period for arrangements involving a support PSF.
Firms should consider validating that existing ICT outsourcing notifications remain complete under the applicable DORA register-of-information requirements, even though Circular 25/883 does not require their re-submission.
Affected third-country branches should consider submitting and maintaining the DORA register of information through the CSSF process, with the 2027 collection requiring data quality suitable for the 31 March 2027 submission deadline.
What changed
From 9 April 2025, DORA entities generally no longer apply the ICT-outsourcing provisions of Circular CSSF 22/806 to ICT arrangements; those arrangements are governed by DORA, including its ICT third-party risk-management, contractual, register-of-information and oversight requirements, together with Circular CSSF 25/882. Circular 22/806 continues to apply to business-process outsourcing by DORA entities, and continues to apply in full to non-DORA entities, including their ICT outsourcing. Chapter 16 management companies remain subject to Circular 22/806 for ICT outsourcing.
Compliance impact
The impact is material for outsourcing inventories, contractual templates, ICT governance, regulatory registers and third-country branch assessments, although Circular 25/883 does not require previously notified ICT outsourcing arrangements to be re-notified. Misclassification may result in applying the wrong control framework, incomplete DORA registers or failures to meet CSSF notification and oversight expectations; the CSSF and market commentary indicate that DORA entities should treat Circular 22/806 primarily as the business-process outsourcing framework, while non-DORA entities retain...
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
AI Analysis
CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.
Key dates
2025-05-19
The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
2025-05-31
Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
2026-08-27
Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.
Suggested considerations
Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.
What changed
From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report.
Compliance impact
The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irrespective of the classification trigger, increasing the importance of coordination between ICT, operational risk, finance and regulatory reporting teams.
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
AI Analysis
CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.
Key dates
2025-01-17
DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
2025-05-28
Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
2025-11-28 Deadline
End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
2026-08-27
Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.
Suggested considerations
Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.
What changed
DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month...
Compliance impact
The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immediate integration of local branch incident reporting into DORA governance and response arrangements.
CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.
Key dates
2022-04-22
Circular CSSF 22/806 was published and replaced or amended specified earlier CSSF and IML outsourcing, governance and control circulars.
2022-06-30
Circular CSSF 22/806 became applicable according to the CSSF implementation framework.
2025-01-17
DORA Regulation (EU) 2022/2554 became applicable to in-scope financial entities, creating the primary EU framework for ICT third-party risk management.
2025-04-09
Circular CSSF 25/883 was published; the amended Circular 22/806 applies to outsourcing arrangements entered into, reviewed or amended on or after this date.
2025-12-17
The European Commission confirmed that DORA also applies to qualifying third-country branches in an EU Member State where the third-country head-office entity would fall within DORA Article 2(1)(a) to (t).
2026-08-27
Circular CSSF 26/915 was published and the CSSF webpage consolidated the amended version of Circular 22/806, confirming the DORA treatment of qualifying Luxembourg third-country branches.
Suggested considerations
Firms should map each outsourcing and third-party technology arrangement against the applicable regime: DORA, Circular 22/806 business-process outsourcing requirements, or the full Circular 22/806 framework for non-DORA entities.
Compliance teams may wish to review whether Luxembourg third-country branches have a head-office activity that corresponds to a DORA Article 2(1)(a) to (t) financial entity and document the resulting DORA scope assessment.
Firms should update outsourcing policies, risk assessments, governance approvals, materiality or criticality assessments, due-diligence files, monitoring controls and exit strategies to reflect the split between DORA ICT third-party risk management and Circular 22/806 business-process outsourcing.
Firms should maintain or update the DORA register of information for ICT third-party arrangements where DORA applies, and reconcile it with the outsourcing inventory and CSSF notification processes.
Firms should review legacy cloud contracts and remove reliance on the repealed Circular 22/806 EEA-law and EEA-resilience clauses where DORA is the applicable ICT third-party regime, while retaining contract terms needed to satisfy DORA and any applicable national requirements.
Non-DORA entities should consider whether their existing contracts still address Circular 22/806 requirements for access and audit rights, sub-outsourcing, confidentiality, data location, business continuity, termination and exit.
Management companies authorised solely under Article 125-1 should consider retaining the full Circular 22/806 control framework for ICT outsourcing rather than assuming that DORA displaces it.
Firms should assess whether outsourcing arrangements entered into, reviewed or amended from 9 April 2025 require remediation or re-papering under the amended framework.
What changed
Circular 25/883 amended Circular 22/806 following DORA Regulation (EU) 2022/2554 becoming applicable on 17 January 2025. For entities subject to DORA, the ICT-outsourcing provisions of Circular 22/806 were largely repealed or displaced by DORA's ICT third-party risk-management requirements, while Circular 22/806 remains applicable to business-process outsourcing.
Compliance impact
The impact is high for firms with complex ICT and outsourcing models because misclassification can lead to the wrong contractual, governance, register and notification framework, and because DORA brings direct requirements for ICT third-party risk management and supervisory oversight. Independent market commentary from EY, Deloitte, Baker McKenzie and Luxembourg industry bodies reads the amendments as a practical division between DORA-regulated ICT services and Circular 22/806 business-process outsourcing, with particular remediation needs for investment managers, non-DORA entities and...
Requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.
Key dates
2020-08-25
Circular CSSF 20/750 was originally published, establishing CSSF expectations for ICT and security risk management.
2025-01-17
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector became applicable to DORA-defined financial entities supervised by the CSSF.
2025-04-09
Circular CSSF 25/881 amended Circular 20/750, narrowing it primarily to non-DORA entities and moving PSP-specific requirements to Circular CSSF 25/880.
2026-08-27
Circular CSSF 26/915 was published and applies with immediate effect; DORA-equivalent third-country branches are removed from Circular 20/750 and addressed through the DORA-related CSSF framework.
Suggested considerations
Firms with Luxembourg third-country branches should document an entity-by-entity DORA scoping analysis, including the classification of the non-EU head-office undertaking under Article 2(1)(a) to (t) of Regulation (EU) 2022/2554 and the relevance of Article 2(2).
Affected branches should consider retiring Circular 20/750 as their primary ICT framework and mapping controls instead to DORA and the applicable CSSF circulars, including Circular CSSF 25/882 on ICT third-party services and Circular CSSF 25/893 on major ICT-related incidents and significant cyber threats.
Firms should review ICT third-party inventories, contracts, due diligence files, exit strategies and, where relevant, the DORA Register of Information so that all ICT services are captured regardless of whether the arrangement is formally classified as outsourcing.
Entities remaining within Circular 20/750 should consider confirming that the management body has approved the ICT and security risk-management framework and that it is reviewed at least annually.
Remaining in-scope entities should consider refreshing their annual ICT and security risk assessment, critical-function and information-asset mapping, threat and vulnerability monitoring, access controls, patching, backup, recovery, incident-response and business-continuity documentation.
Compliance teams may wish to verify that critical ICT systems undergo security testing at least annually, non-critical systems are tested regularly and at least every three years, and critical business continuity arrangements are tested at least annually.
Branches and PSP-related entities should consider validating incident-reporting channels and escalation procedures, including the CSSF alternative email channel for exceptional technical failures where the prescribed DORA reporting channel cannot be used.
Firms should consider preserving evidence of proportionality assessments, control testing, audit findings, remediation, management-body reporting and staff security training for CSSF supervisory review.
What changed
Circular 26/915 applies with immediate effect and removes DORA-equivalent third-country branches from the scope of Circular 20/750. A third-country branch is treated as DORA-relevant where, in the jurisdiction of its head office, the undertaking would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554, subject to the applicable exclusions and Article 2(2) conditions.
Compliance impact
The immediate-effect scope change is operationally significant for third-country branches because applying the wrong framework could result in duplicated controls, incomplete DORA reporting, or failure to maintain DORA third-party and incident-reporting records. For entities remaining under Circular 20/750, the CSSF continues to expect a documented, independently controlled and annually reviewed ICT risk framework, with deficiencies capable of generating supervisory remediation and broader CSSF enforcement consequences.
CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...
FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.
Key dates
18 June 2025
- FATF adopts modifications to Recommendation 16 to enhance payment transparency, including strengthened travel‑rule standards
24 June 2026
- FATF launches public consultation on guidance for the implementation of the updated Recommendation 16
21 August 2026 Deadline
- FATF public consultation period closes; this is the deadline for private‑sector contributions highlighted by the CSSF
End 2030
- FATF’s revised Recommendation 16 framework is expected to be fully effective, with jurisdictions having implemented the standard into national law or regulation by this date
Suggested considerations
Map and document all existing and planned cross‑border payment and value‑transfer flows (including virtual asset transfers) to identify where FATF Recommendation 16 and travel‑rule obligations currently apply or will apply by 2030.
Review the June 2025 FATF modifications to Recommendation 16 and the current consultation materials, and perform a gap analysis against your existing AML/CTF, KYC and payments data standards, including thresholds, data fields, and monitoring use‑cases.
Establish an internal project for travel‑rule implementation and enhancement that spans AML, operations, technology, legal and data‑protection teams, with explicit ownership and governance.
Strengthen beneficiary‑side transaction‑monitoring rules to use incoming travel‑rule data for sanctions, fraud and AML detection, including controls to identify misdirected or unusual payments based on name, location, and other attributes.
Review and, where necessary, update customer due diligence and KYC procedures to ensure the availability and verification of data fields that will be required to travel with transactions (for example, address, town and country, identification numbers, date of birth).
What changed
*(Based on the CSSF notice plus the 2025 FATF revisions to Recommendation 16 and existing travel‑rule standards; details may be further refined by the new guidance now under consultation.)*
FATF is issuing implementation guidance for the updated Recommendation 16, which already increased obligations regarding payment transparency, including more granular beneficiary data and expanded...
Cross‑border payments and value transfers above 1,000 USD/EUR are expected to include additional mandatory beneficiary information, such as beneficiary name, account or unique reference, and at least...
Beneficiary institutions are given enhanced responsibilities to use travel‑rule information (not just receive it) for transaction monitoring, including detecting misdirected payments and indicators...
The revised travel rule continues to apply to both traditional wire transfers and value transfers involving virtual assets, reinforcing that Virtual Asset Service Providers (VASPs) must collect,...
Compliance impact
Non‑compliance with the revised travel‑rule expectations will materially increase the risk of supervisory criticism, enforcement action, and restrictions on cross‑border business, especially in higher‑risk client segments and payment corridors. Failure to implement adequate data‑collection and monitoring capabilities may also compromise sanctions and AML controls, leading to heightened legal, financial and reputational exposure.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
implementing Article 8a(1) of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
This is a critical supply chain attack targeting the widely used Axios HTTP client library, which is central to many architectures. The compromise of the build pipeline can result in remote code execution, credential theft, and lateral movement within the information system.
This regulatory update from the CSSF focuses on improving financial education and empowerment, particularly for women, through a walking challenge program. It covers consumer protection, sustainability, and technology aspects relevant to banks, wealth managers, and fintechs.
This regulatory update from the CSSF relates to disruptions on the eDesk platform, which is likely a critical operational system for financial firms. The impact could be widespread across banking, investment management, and wealth management firms, as well as fintechs that rely on the eDesk platform.
Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)
Why this matters
This regulatory update from the CSSF provides details on the submission timeframe and process for the DORA register of information, which is relevant for banking, investment management, and wealth management firms. It covers operational resilience, reporting, and technology/cyber topics.
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
AI Analysis
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
Key dates
30 April 2025 Deadline
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
May 2025
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
11 February 2026
- Publication date of this error guidance (last updated 10/02/2026)
Suggested considerations
Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
What changed
- Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Compliance impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM.
This regulatory update warns about online financial frauds and scams in an artificial intelligence world, which is highly relevant for banking, investment management, and wealth management firms, as well as fintechs and crypto exchanges that operate in the digital finance space.
This regulatory update from the CSSF provides guidance for 'finfluencers' on responsible promotion, which is relevant for investment management firms, wealth managers, banks, and fintechs that engage in digital marketing and social media activities.
This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.
This regulatory update from the CSSF in Luxembourg focuses on the use of artificial intelligence in the financial sector, which impacts banking, investment management, and wealth management firms.