Live Updates

Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated)

AI Analysis

Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.

Key dates

2025-01-17
DORA became applicable to in-scope financial entities, according to the CSSF implementation communication referenced by Circular CSSF 25/882.
2025-04-09
Circular CSSF 25/882 was published and applied with immediate effect.
2025-04-01 Deadline
The first exceptional CSSF register submission window opened for arrangements contracted up to 31 March 2025.
2025-04-15 Deadline
The first exceptional CSSF register submission window closed.
2026-08-27
Circular CSSF 26/915 was published and immediately amended Circular CSSF 25/882 to include qualifying third-country branches in Luxembourg.
2027-03-31 Deadline
Latest date for submission of the register covering arrangements contracted through the end of 2026, under the recurring annual window running from 28 February to 31 March of the following year.

Suggested considerations

  • Firms should assess whether Luxembourg third-country branches now fall within the amended scope by comparing the branch’s undertaking and head-office activities with the DORA categories in Article 2(1)(a) to (t) and documenting the conclusion.
  • Compliance teams may wish to inventory all ICT third-party arrangements, including digital, data, cloud, infrastructure and operational services that may not qualify as outsourcing under prior CSSF terminology.
  • Firms should consider updating ICT third-party approval workflows so arrangements supporting critical or important functions are notified through the CSSF-prescribed form at least three months before commencement, or one month before commencement where the provider is an eligible Luxembourg support PFS.
  • Firms should maintain an accurate register of information at individual, sub-consolidated and consolidated levels, with controls for prompt correction when requested by the CSSF and the ability to provide the register outside the annual submission window.
  • Compliance and outsourcing teams may wish to reassess contractual access to professional-secrecy data against Article 41(2a) LFS or Article 30(2a) LPS and verify that Luxembourg ICT management or operations providers hold the required Article 29-3 LFS authorisation or qualify for an applicable exception.
  • Firms using cloud services should confirm that the resource operator has designated a suitably qualified cloud officer and that internal cloud, information-security and third-party oversight responsibilities are clearly allocated.
  • Third-country branches should consider implementing the requirements immediately because Circular CSSF 26/915 provides no transition period, while preserving evidence of governance, notification and register controls for supervisory review.

What changed

Circular CSSF 26/915 includes in Circular CSSF 25/882’s scope all Luxembourg third-country branches of undertakings covered by the specified DORA financial-entity categories where the head office would qualify as a DORA entity under Article 2(1)(a) to (t) in the relevant third country. The requirements apply to ICT services broadly, not only arrangements that meet a traditional outsourcing definition. Financial entities must ensure compliance with professional-secrecy requirements under Article 41(2a) of the Law of 5 April 1993 on the financial sector or Article 30(2a) of the Law of 10 November 2009 on payment services, as applicable. ICT arrangements supporting critical or important functions must generally be notified to the CSSF at least three months before taking effect; arrangements w

Compliance impact

The amendment materially increases the population subject to Luxembourg’s ICT third-party controls because qualifying third-country branches must comply immediately, without a transition period. Non-compliance may leave arrangements formally untreated as notified and expose firms to supervisory measures, binding measures and administrative sanctions, while firms remain fully responsible for compli

Who is affected

  • Luxembourg branches of qualifying third-country credit institutions
  • Luxembourg branches of qualifying third-country investment firms
  • Luxembourg branches of qualifying third-country payment institutions and electronic money institutions
  • Luxembourg branches of qualifying third-country crypto-asset service providers
  • Luxembourg branches of qualifying third-country central securities depositories and central counterparties
  • Luxembourg management companies and Luxembourg branches of investment fund managers
  • Luxembourg-authorised alternative investment fund managers and internally managed alternative investment funds
  • Institutions for occupational retirement provision, administrators of critical benchmarks and crowdfunding service providers subject to DORA
  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • Commission Delegated Regulation (EU) 2024/1773
  • Commission Implementing Regulation (EU) 2024/295
  • Law of 5 April 1993 on the financial sector, including Articles 29-3 and 41(2a)
  • Law of 10 November 2009 on payment services, including Article 30(2a)
  • Regulation (EU) 2023/1114 on markets in crypto-assets
  • Law of 17 December 2010 relating to undertakings for collective investment
  • Law of 12 July 2013 on alternative investment fund managers
  • MiFID II
  • AIFMD

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankAsset ManagerFintechCrypto Exchange
View Original on CSSF Back to Feed

Share this update