Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated)
AI Analysis
Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).
Key dates
- 2025-01-17
- DORA became applicable to financial entities within its scope, subject to the specific DORA provisions and technical standards applicable to each entity.
- 2025-04-09
- Circular CSSF 25/881 was published and took effect, removing DORA financial entities from Circular 20/750 and retaining 20/750 for entities outside DORA; PSP-specific provisions were reorganised under Circular 25/880.
- 2026-06-30 Deadline
- CSSF extended the first Register of Information submission for Luxembourg branches of third-country credit institutions to this date on a best-efforts basis; the CSSF indicated that the required level of quality should be achieved for the 2027 submission.
- 2026-08-27
- Circular CSSF 26/915 was published, confirming the DORA treatment of qualifying third-country branches and removing them from the full scope of Circular 20/750 and related overlapping circular provisions.
- 2027-03-31 Deadline
- Target date identified by the CSSF for the required-quality Register of Information submission by Luxembourg branches of third-country credit institutions.
Suggested considerations
- Firms should classify each Luxembourg entity and branch against DORA Article 2 and the amended scope of Circular 20/750, including an assessment of whether a third-country head office would qualify under DORA Article 2(1)(a) to (t).
- Compliance teams may wish to determine whether the entity should operate under DORA rather than 20/750, and document the rationale, legal-entity perimeter and treatment of any Luxembourg branch.
- Firms remaining within Circular 20/750 should consider reviewing their ICT and security-risk-management framework, governance approvals, risk assessments, incident processes, business-continuity arrangements and control testing against the continuing requirements.
- Payment service providers should consider replacing references to the PSP provisions formerly contained in Circular 20/750 with the applicable requirements in Circular CSSF 25/880 and EBA/GL/2025/02.
- Third-country branches treated as DORA entities should consider validating their DORA governance, ICT-risk framework, incident-reporting arrangements, ICT contractual inventory and Register of Information processes, taking account of CSSF reporting communications.
- Firms should update policies, regulatory inventories, outsourcing and ICT-third-party registers, training materials and regulatory mapping to distinguish DORA obligations from the residual Circular 20/750 obligations.
- Compliance teams may wish to retain evidence of the scope assessment and implementation date, because the 2025 amendment was effective immediately and the 2026 amendment changes the treatment of a previously identified 20/750 population.
What changed
Circular 25/881 provides that DORA financial entities supervised by the CSSF no longer fall within Circular 20/750; for entities covered by 20/750 but outside DORA, the circular continues to apply in full. Payment-service-provider-specific ICT and security-risk provisions were removed from 20/750 and regrouped in Circular CSSF 25/880, reflecting the revised EBA Guidelines on ICT and security risk management for payment service providers, including EBA/GL/2025/02. Circular 26/915 amends 20/750 and related CSSF ICT circulars to remove Luxembourg third-country branches from the relevant 20/750 scope where they qualify as DORA financial entities by reference to the activities of their third-country head office; those branches are instead treated as subject to DORA. The remaining 20/750 populat
Compliance impact
The principal impact is perimeter and framework migration rather than a wholly new ICT-control standard: entities in DORA must avoid relying on residual 20/750 requirements where DORA governs, while non-DORA entities retain substantive 20/750 obligations. The CSSF and market commentary indicate that misclassification may create gaps in DORA governance, ICT-third-party documentation, incident repor
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
Published by CSSF . Read the full notice at the source for the authoritative text.