Circular CSSF 25/893 (as amended by Circular CSSF 25/915) (Updated)
AI Analysis
CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.
Key dates
- 2025-01-17
- DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
- 2025-05-28
- Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
- 2025-11-28 Deadline
- End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
- 2026-08-27
- Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.
Suggested considerations
- Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
- Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
- Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
- PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
- Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
- Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
- Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
- Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.
What changed
DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month after the intermediate report. Significant cyber threats may be notified where the entity considers the threat relevant, using the applicable DORA process. Submissions are made through the CSSF eDesk
Compliance impact
The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immedia
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
Published by CSSF . Read the full notice at the source for the authoritative text.