CSSF
Commission de Surveillance du Secteur Financier
CSSF Circular 25/882 sets DORA ICT third-party reporting and cloud-service instructions for Luxembourg financial entities
Published
Aug 27, 2026
Effective
Apr 9, 2025
Topics
DORA, ICT third-party risk, Outsourcing, Cloud computing, Register of information, Critical or important functions, Professional secrecy, Operational resilience
Executive Summary
CSSF Circular 25/882, as amended by Circular CSSF 26/915, operationalises selected DORA ICT third-party requirements for CSSF-supervised financial entities in Luxembourg. The circular confirms that DORA has applied from 17 January 2025 and gives practical instructions for notifying planned ICT service arrangements supporting critical or important functions, submitting the DORA register of information, and applying Luxembourg-specific controls for ICT operations and cloud services. The highest operational impact is on procurement, outsourcing governance, cloud operating models, regulatory reporting and professional-secrecy controls. In-scope entities must notify relevant planned arrangements at least three months before they take effect, reduced to one month where the provider is a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS. They must also submit the register of information annually, with a special first 2025 collection window. The circular applies immediately and should be treated as a near-term control and reporting implementation priority rather than a policy-only update.
What Changed
Previous
DORA required timely information to the competent authority, but the supplied circular is the CSSF instruction specifying local submission timing and use of CSSF website instructions and forms.
New
Financial entities must submit the notification at least three months before the planned arrangement takes effect, reduced to one month when using a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS. Late or incorrectly submitted projects are considered not notified.
Previous
DORA Article 28(3) required financial entities to maintain and update a register of information on ICT third-party contractual arrangements.
New
The register for year n must include arrangements contracted until the end of year n and be submitted between 28 February and 31 March of year n+1. For the first 2025 collection, the register covers arrangements contracted until 31 March 2025 and must be submitted between 1 April and 15 April 2025.
Previous
General Luxembourg professional-secrecy and support-PFS rules existed under the LFS and LPS frameworks.
New
Access to data subject to professional secrecy must comply with Article 41(2a) LFS or Article 30(2a) LPS where applicable. Certain ICT management or operations services in Luxembourg may be provided only by an Article 29-3 LFS authorised provider, a credit institution, or a qualifying intra-group entity.
Previous
The source does not identify a prior DORA-specific CSSF requirement of the same scope; it notes a similar tailored requirement for UCI administrators in Circular CSSF 22/811.
New
Financial entities using an accounting system located outside Luxembourg must have, at each day-end, a secure readable backup of accounting positions, including client positions, enabling autonomous preparation of balance sheet, profit and loss statement and client positions. The backup must be stored in Luxembourg premises, an EEA group entity or another EEA service provider.
Previous
DORA and its ICT risk-management RTS set broad ICT third-party and competence requirements, but the circular provides CSSF-specific cloud classification and cloud-officer instructions.
New
A service is treated as cloud computing only where the five listed characteristics and two additional access and automation conditions are met. The resource operator must designate a qualified employee as cloud officer, and the financial entity must know the cloud officer’s name where resource operation is outsourced.
Business Impact
Who is affected
Directly affected
CSSF-supervised DORA financial entities listed in the circular, including credit institutions, investment firms, payment and e-money institutions, crypto-asset service providers, market infrastructures, fund managers, internally managed funds, IORPs, benchmark administrators, crowdfunding service providers and qualifying third-country branches; Chapter 2 does not apply to Luxembourg branches of EU-headed financial entities or significant credit institutions prudentially supervised by the ECB.
Indirectly affected
ICT third-party service providers, Luxembourg support PFS, cloud service providers, resource operators, group service companies, outsourcing managers, legal advisers, internal audit, ICT security teams and accounting service providers supporting in-scope entities.
Jurisdictions
Luxembourg, European Union, European Economic Area
Business processes
ICT third-party onboarding and contract approval, Critical or important function assessment, DORA register-of-information maintenance and annual submission, Cloud service classification and resource-operation governance, Professional-secrecy access assessment for ICT providers, Accounting-system backup controls for non-Luxembourg hosting, Regulatory reporting remediation and resubmission following CSSF data-quality requests
Estimated effort
Medium
Compliance risk
High
Affected Reports
| Field | Validation rule |
|---|---|
| Critical or important function status | Notifications are required for planned ICT arrangements supporting critical or important functions and when a function becomes critical or important. |
| Planned contractual arrangement effective date | The notification must be submitted at least three months before the arrangement takes effect, or one month where the arrangement uses a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS. |
| ICT third-party contractual arrangement population in the register | The register must cover all contractual arrangements on the use of ICT services provided by ICT third-party service providers at entity level and, where relevant, sub-consolidated and consolidated levels. |
| Register cut-off date and submission period | The year n register must include arrangements contracted until the end of year n and be submitted between 28 February and 31 March of year n+1; the first 2025 collection covers arrangements contracted until 31 March 2025 and is submitted between 1 April and 15 April 2025. |
| Cloud-resource operation and cloud officer ownership | The resource operator must designate a qualified employee as cloud officer; where the financial entity outsources resource operation, it must know the name of the resource operator’s cloud officer. |
Recommended Actions
- 1Confirmed actionStep 1 of 7
update outsourcing intake procedures so any ICT service supporting a critical or important function is routed to CSSF notification at least three months before go-live, or one month for qualifying Luxembourg support PFS arrangements.
- 2Confirmed actionStep 2 of 7
maintain the DORA register of information continuously and schedule the annual CSSF submission window of 28 February to 31 March, including controls for prompt correction and resubmission if CSSF requests data fixes.
- 3Confirmed actionStep 3 of 7
identify whether Chapter 2 applies to each Luxembourg entity or branch, particularly EU branches and significant credit institutions supervised by the ECB, before assigning reporting responsibilities.
- 4Confirmed actionStep 4 of 7
validate provider eligibility for Luxembourg ICT management or operations services subject to Article 29-3 LFS and document professional-secrecy compliance under Article 41(2a) LFS or Article 30(2a) LPS where relevant.
- 5Confirmed actionStep 5 of 7
implement or evidence daily readable end-of-day backups of accounting and client positions where accounting systems are located outside Luxembourg, with storage in an allowed Luxembourg or EEA location.
- 6AI generatedStep 6 of 7
classify each cloud arrangement against the circular’s cloud characteristics and additional access/automation conditions to distinguish cloud services from resource operation services.
- 7AI generatedStep 7 of 7
appoint, document and train the cloud officer for internal resource operation, and capture the resource operator’s cloud officer name where resource operation is outsourced.
Timeline
other
Dec 14, 2022
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector was adopted.
other
Mar 13, 2024
Commission Delegated Regulation (EU) 2024/1774 specifying ICT risk-management tools, methods, processes and policies under DORA was adopted.
publication
Nov 8, 2024
The Joint ESA decision referenced by the circular for register reporting alignment was published.
publication
Jan 15, 2025
CSSF communiqué on DORA entry into application was published, referenced by the circular for the first-year register collection derogation.
effective date
Jan 17, 2025
DORA provisions became applicable to CSSF-supervised financial entities in scope of DORA.
implementation
Date not specified
First 2025 register-of-information collection window; the register must cover arrangements contracted until 31 March 2025.
effective date
Apr 9, 2025
Circular CSSF 25/882 was dated and applies with immediate effect.
implementation
Date not specified
Annual register-of-information submission window for year n registers, which must contain arrangements contracted until the end of year n and be submitted in year n+1.
Sources
AI-generated analysis is based on the following primary sources. Always verify against the official publication.
- CircularCommission de Surveillance du Secteur FinancierApr 9, 2025Circular CSSF 25/882 as amended by Circular CSSF 26/915 on requirements on the use of ICT third-party services for Financial Entities subject to DORA ↗
https://www.cssf.lu/wp-content/uploads/cssf25_882eng.pdf
- RegulationEuropean UnionDec 14, 2022Regulation (EU) 2022/2554 on digital operational resilience for the financial sector ↗
https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Delegated Regulation / Regulatory Technical StandardsEuropean UnionMar 13, 2024Commission Delegated Regulation (EU) 2024/1774 with regard to regulatory technical standards specifying ICT risk management tools, methods, processes, and policies and the simplified ICT risk management framework ↗
https://eur-lex.europa.eu/eli/reg_del/2024/1774/oj
- CommuniquéCommission de Surveillance du Secteur FinancierJan 15, 2025Entry into application of DORA regulation on 17 January 2025 ↗
https://www.cssf.lu/en/2025/01/entry-into-application-of-dora-regulation-on-17-january-2025/
- Joint ESA DecisionEuropean Supervisory AuthoritiesNov 8, 2024Decision of the European Supervisory Authorities on the reporting by competent authorities to the ESAs of information registers under DORA ↗
https://www.eba.europa.eu/publications-and-media/press-releases/esas-publish-decision-information-registers-under-dora
Related Evidence
Verified source support for this analysis
The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.
Receive updates like this by email
Get AI-generated analysis for the regulators and topics you care about.