Circular CSSF 25/883 (as amended by Circular CSSF 26/915) (Updated)
AI Analysis
Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.
Key dates
- 2025-01-17
- DORA began applying to financial entities within its scope, subject to the relevant provisions and transitional arrangements.
- 2025-04-09
- Circular CSSF 25/883 was published and applied with immediate effect, amending Circular CSSF 22/806 and introducing the DORA-based division between ICT and business-process outsourcing.
- 2025-12-17
- The European Commission confirmed through a DORA Q&A that DORA applies to qualifying third-country branches in an EU Member State.
- 2026-06-30 Deadline
- CSSF-extended submission date for the 2026 DORA register of information for third-country branches of credit institutions headquartered in a third country; entities were invited to submit on a best-efforts basis.
- 2026-08-27
- Circular CSSF 26/915 was published and applied with immediate effect, confirming the DORA treatment of qualifying Luxembourg third-country branches and updating Circular CSSF 22/806 accordingly.
- 2027-03-31 Deadline
- Target CSSF submission deadline for the DORA register of information for affected third-country branches following the initial 2026 collection.
Suggested considerations
- Firms should classify each outsourcing arrangement as ICT or non-ICT and determine whether the entity and arrangement fall within DORA, Circular 22/806, or both regimes in their respective areas of application.
- DORA entities should consider moving ICT arrangements from their Circular 22/806 outsourcing inventory and controls into the DORA ICT third-party register, while retaining Circular 22/806 controls for business-process outsourcing.
- Non-DORA entities should consider continuing to apply the full Circular 22/806 framework to ICT and business-process outsourcing, including due diligence, governance, critical-or-important assessments, monitoring, sub-outsourcing and exit planning.
- Third-country branches should assess whether their head office would qualify under Article 2(1)(a) to (t) of DORA and, if so, align ICT governance, contractual arrangements, registers and reporting with DORA rather than relying solely on Circular 22/806.
- Compliance teams may wish to review cloud contracts and avoid carrying forward legacy EEA governing-law or hosting clauses where DORA now provides the applicable framework, while preserving enforceable audit, access, cooperation, security, business-continuity and exit rights.
- Firms should use the revised CSSF notification form for new critical or important ICT outsourcing arrangements and preserve evidence supporting the three-month notification period, or the one-month period for arrangements involving a support PSF.
- Firms should consider validating that existing ICT outsourcing notifications remain complete under the applicable DORA register-of-information requirements, even though Circular 25/883 does not require their re-submission.
- Affected third-country branches should consider submitting and maintaining the DORA register of information through the CSSF process, with the 2027 collection requiring data quality suitable for the 31 March 2027 submission deadline.
What changed
From 9 April 2025, DORA entities generally no longer apply the ICT-outsourcing provisions of Circular CSSF 22/806 to ICT arrangements; those arrangements are governed by DORA, including its ICT third-party risk-management, contractual, register-of-information and oversight requirements, together with Circular CSSF 25/882. Circular 22/806 continues to apply to business-process outsourcing by DORA entities, and continues to apply in full to non-DORA entities, including their ICT outsourcing. Chapter 16 management companies remain subject to Circular 22/806 for ICT outsourcing. The amendments remove or adapt certain legacy cloud-specific requirements, including EEA governing-law and EEA hosting or resilience provisions that are superseded by the DORA framework. Previously notified ICT-outsour
Compliance impact
The impact is material for outsourcing inventories, contractual templates, ICT governance, regulatory registers and third-country branch assessments, although Circular 25/883 does not require previously notified ICT outsourcing arrangements to be re-notified. Misclassification may result in applying the wrong control framework, incomplete DORA registers or failures to meet CSSF notification and ov
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
amending Circular CSSF 22/806 on outsourcing arrangements
Published by CSSF . Read the full notice at the source for the authoritative text.