Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated)
AI Analysis
Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.
Key dates
- 2025-01-17
- DORA became applicable to in-scope financial entities, according to the CSSF implementation communication referenced by Circular CSSF 25/882.
- 2025-04-09
- Circular CSSF 25/882 was published and applied with immediate effect.
- 2025-04-01 Deadline
- The first exceptional CSSF register submission window opened for arrangements contracted up to 31 March 2025.
- 2025-04-15 Deadline
- The first exceptional CSSF register submission window closed.
- 2026-08-27
- Circular CSSF 26/915 was published and immediately amended Circular CSSF 25/882 to include qualifying third-country branches in Luxembourg.
- 2027-03-31 Deadline
- Latest date for submission of the register covering arrangements contracted through the end of 2026, under the recurring annual window running from 28 February to 31 March of the following year.
Suggested considerations
- Firms should assess whether Luxembourg third-country branches now fall within the amended scope by comparing the branch’s undertaking and head-office activities with the DORA categories in Article 2(1)(a) to (t) and documenting the conclusion.
- Compliance teams may wish to inventory all ICT third-party arrangements, including digital, data, cloud, infrastructure and operational services that may not qualify as outsourcing under prior CSSF terminology.
- Firms should consider updating ICT third-party approval workflows so arrangements supporting critical or important functions are notified through the CSSF-prescribed form at least three months before commencement, or one month before commencement where the provider is an eligible Luxembourg support PFS.
- Firms should maintain an accurate register of information at individual, sub-consolidated and consolidated levels, with controls for prompt correction when requested by the CSSF and the ability to provide the register outside the annual submission window.
- Compliance and outsourcing teams may wish to reassess contractual access to professional-secrecy data against Article 41(2a) LFS or Article 30(2a) LPS and verify that Luxembourg ICT management or operations providers hold the required Article 29-3 LFS authorisation or qualify for an applicable exception.
- Firms using cloud services should confirm that the resource operator has designated a suitably qualified cloud officer and that internal cloud, information-security and third-party oversight responsibilities are clearly allocated.
- Third-country branches should consider implementing the requirements immediately because Circular CSSF 26/915 provides no transition period, while preserving evidence of governance, notification and register controls for supervisory review.
What changed
Circular CSSF 26/915 includes in Circular CSSF 25/882’s scope all Luxembourg third-country branches of undertakings covered by the specified DORA financial-entity categories where the head office would qualify as a DORA entity under Article 2(1)(a) to (t) in the relevant third country. The requirements apply to ICT services broadly, not only arrangements that meet a traditional outsourcing definition. Financial entities must ensure compliance with professional-secrecy requirements under Article 41(2a) of the Law of 5 April 1993 on the financial sector or Article 30(2a) of the Law of 10 November 2009 on payment services, as applicable. ICT arrangements supporting critical or important functions must generally be notified to the CSSF at least three months before taking effect; arrangements w
Compliance impact
The amendment materially increases the population subject to Luxembourg’s ICT third-party controls because qualifying third-country branches must comply immediately, without a transition period. Non-compliance may leave arrangements formally untreated as notified and expose firms to supervisory measures, binding measures and administrative sanctions, while firms remain fully responsible for compli
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
Published by CSSF . Read the full notice at the source for the authoritative text.