Live Updates

eRegister by eDesk – a new gateway to public data

Launch of the public API for the consultation of fund identification data

Why this matters

This is an informational announcement about a new CSSF service (eRegister by eDesk) providing API access to fund identification data. It describes a voluntary, opt-in tool requiring prior agreement rather than imposing binding obligations.

All Firms
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 26/915

on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg

AI Analysis

CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 27 February 2027
BankBroker DealerPayment Provider
Crypto Exchange
🇱🇺 CSSF News Urgency: high Significant

Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

No description available.

AI Analysis

CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankPayment ProviderInsurance
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated)

on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)

AI Analysis

Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankAsset ManagerFintech
Crypto Exchange
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 25/883 (as amended by Circular CSSF 26/915) (Updated)

amending Circular CSSF 22/806 on outsourcing arrangements

AI Analysis

Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2027
BankBroker DealerAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: medium

Circular CSSF 25/892 (as amended by Circular CSSF 26/915) (Updated)

Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)

AI Analysis

CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
All FirmsBankAsset Manager
Payment Provider
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 25/893 (as amended by Circular CSSF 25/915) (Updated)

on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)

AI Analysis

CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 31 May 2025
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high Significant

Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915) (Updated)

on outsourcing arrangements

AI Analysis

CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Compliance Deadline: 31 December 2022
BankAsset ManagerPayment Provider
All Firms
🇱🇺 CSSF Guidance Urgency: high

Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915) (Updated)

Requirements regarding information and communication technology (ICT) and security risk management

AI Analysis

CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Effective Date: 27 August 2026
BankBroker DealerPayment Provider
All Firms

Evolving opportunities and risks in artificial intelligence and its adoption

No description available.

Why this matters

CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...

All Firms
🇱🇺 CSSF Consultation Urgency: medium Significant

Public consultation by FATF by 21 August 2026 on guidance to increase payment transparency - “travel rule”

No description available.

AI Analysis

FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Deadline: 21 August 2026
BankPayment ProviderCrypto Exchange
Fintech
🇱🇺 CSSF News Urgency: critical

Active supply chain attack targeting Axios NPM

No description available.

Why this matters

This is a critical supply chain attack targeting the widely used Axios HTTP client library, which is central to many architectures. The compromise of the build pipeline can result in remote code execution, credential theft, and lateral movement within the information system.

BankFintechAsset Manager
Wealth Manager

Take control of your finances, one step at a time

No description available.

Why this matters

This regulatory update from the CSSF focuses on improving financial education and empowerment, particularly for women, through a walking challenge program. It covers consumer protection, sustainability, and technology aspects relevant to banks, wealth managers, and fintechs.

BankWealth ManagerFintech
🇱🇺 CSSF News Urgency: high

eDesk – Disruptions on Monday 16 March 2026

No description available.

Why this matters

This regulatory update from the CSSF relates to disruptions on the eDesk platform, which is likely a critical operational system for financial firms. The impact could be widespread across banking, investment management, and wealth management firms, as well as fintechs that rely on the eDesk platform.

BankWealth ManagerFintech
🇱🇺 CSSF News Urgency: medium

DORA – Submission timeframe for register of information – eDesk Portal open as of 11 February 2026

Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)

Why this matters

This regulatory update from the CSSF provides details on the submission timeframe and process for the DORA register of information, which is relevant for banking, investment management, and wealth management firms. It covers operational resilience, reporting, and technology/cyber topics.

BankAsset ManagerWealth Manager
🇱🇺 CSSF Guidance Urgency: high

Guidance for interpretation and resolution of CSSF error messages related to the submission of the DORA register

Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.

AI Analysis

This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Response Due: 31 March 2026
BankFintechPayment Provider
🇱🇺 CSSF News Urgency: critical

Active exploitation of vulnerabilities on Ivanti Endpoint Manager Mobile (EPMM)

CVE-2026-1281 & CVE-2026-1340

Why this matters

The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM.

BankWealth ManagerFintech
🇱🇺 CSSF Warning Urgency: high

Online financial frauds and scams in an artificial intelligence world

No description available.

Why this matters

This regulatory update warns about online financial frauds and scams in an artificial intelligence world, which is highly relevant for banking, investment management, and wealth management firms, as well as fintechs and crypto exchanges that operate in the digital finance space.

BankWealth ManagerFintech
Crypto Exchange

Finfluencers – Tips for responsible promotion

No description available.

Why this matters

This regulatory update from the CSSF provides guidance for 'finfluencers' on responsible promotion, which is relevant for investment management firms, wealth managers, banks, and fintechs that engage in digital marketing and social media activities.

Asset ManagerWealth ManagerBank
Fintech
🇱🇺 CSSF News Urgency: high

Supply-chain attack using NPM packages

Press release 25/18

Why this matters

This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.

BankFintech
🇱🇺 CSSF News Urgency: medium

Second thematic review on the use of Artificial Intelligence in the Luxembourg financial sector

Press release 25/08

Why this matters

This regulatory update from the CSSF in Luxembourg focuses on the use of artificial intelligence in the financial sector, which impacts banking, investment management, and wealth management firms.

BankAsset ManagerWealth Manager
Fintech