← Back to updates
CSSF

CSSF

Commission de Surveillance du Secteur Financier

High Impact

CSSF Circular 25/882 sets DORA ICT third-party reporting and cloud-service instructions for Luxembourg financial entities

Published

Aug 27, 2026

Effective

Apr 9, 2025

Topics

DORA, ICT third-party risk, Outsourcing, Cloud computing, Register of information, Critical or important functions, Professional secrecy, Operational resilience

Executive Summary

CSSF Circular 25/882, as amended by Circular CSSF 26/915, operationalises selected DORA ICT third-party requirements for CSSF-supervised financial entities in Luxembourg. The circular confirms that DORA has applied from 17 January 2025 and gives practical instructions for notifying planned ICT service arrangements supporting critical or important functions, submitting the DORA register of information, and applying Luxembourg-specific controls for ICT operations and cloud services. The highest operational impact is on procurement, outsourcing governance, cloud operating models, regulatory reporting and professional-secrecy controls. In-scope entities must notify relevant planned arrangements at least three months before they take effect, reduced to one month where the provider is a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS. They must also submit the register of information annually, with a special first 2025 collection window. The circular applies immediately and should be treated as a near-term control and reporting implementation priority rather than a policy-only update.

What Changed

newCSSF notification lead time for critical or important ICT arrangements

Previous

DORA required timely information to the competent authority, but the supplied circular is the CSSF instruction specifying local submission timing and use of CSSF website instructions and forms.

New

Financial entities must submit the notification at least three months before the planned arrangement takes effect, reduced to one month when using a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS. Late or incorrectly submitted projects are considered not notified.

newAnnual CSSF submission window for the DORA register of information

Previous

DORA Article 28(3) required financial entities to maintain and update a register of information on ICT third-party contractual arrangements.

New

The register for year n must include arrangements contracted until the end of year n and be submitted between 28 February and 31 March of year n+1. For the first 2025 collection, the register covers arrangements contracted until 31 March 2025 and must be submitted between 1 April and 15 April 2025.

newLuxembourg-specific controls for ICT operations and professional secrecy

Previous

General Luxembourg professional-secrecy and support-PFS rules existed under the LFS and LPS frameworks.

New

Access to data subject to professional secrecy must comply with Article 41(2a) LFS or Article 30(2a) LPS where applicable. Certain ICT management or operations services in Luxembourg may be provided only by an Article 29-3 LFS authorised provider, a credit institution, or a qualifying intra-group entity.

newAccounting-system backup requirement for systems located outside Luxembourg

Previous

The source does not identify a prior DORA-specific CSSF requirement of the same scope; it notes a similar tailored requirement for UCI administrators in Circular CSSF 22/811.

New

Financial entities using an accounting system located outside Luxembourg must have, at each day-end, a secure readable backup of accounting positions, including client positions, enabling autonomous preparation of balance sheet, profit and loss statement and client positions. The backup must be stored in Luxembourg premises, an EEA group entity or another EEA service provider.

newCloud computing classification and cloud officer expectation

Previous

DORA and its ICT risk-management RTS set broad ICT third-party and competence requirements, but the circular provides CSSF-specific cloud classification and cloud-officer instructions.

New

A service is treated as cloud computing only where the five listed characteristics and two additional access and automation conditions are met. The resource operator must designate a qualified employee as cloud officer, and the financial entity must know the cloud officer’s name where resource operation is outsourced.

Business Impact

Who is affected

Directly affected

CSSF-supervised DORA financial entities listed in the circular, including credit institutions, investment firms, payment and e-money institutions, crypto-asset service providers, market infrastructures, fund managers, internally managed funds, IORPs, benchmark administrators, crowdfunding service providers and qualifying third-country branches; Chapter 2 does not apply to Luxembourg branches of EU-headed financial entities or significant credit institutions prudentially supervised by the ECB.

Indirectly affected

ICT third-party service providers, Luxembourg support PFS, cloud service providers, resource operators, group service companies, outsourcing managers, legal advisers, internal audit, ICT security teams and accounting service providers supporting in-scope entities.

Jurisdictions

Luxembourg, European Union, European Economic Area

Business processes

ICT third-party onboarding and contract approval, Critical or important function assessment, DORA register-of-information maintenance and annual submission, Cloud service classification and resource-operation governance, Professional-secrecy access assessment for ICT providers, Accounting-system backup controls for non-Luxembourg hosting, Regulatory reporting remediation and resubmission following CSSF data-quality requests

Estimated effort

Medium

Compliance risk

High

Affected Reports

DORA Article 28(3) notification of planned contractual arrangements for ICT services supporting critical or important functionsNotification to CSSF when a function has become critical or importantDORA register of information on ICT third-party contractual arrangementsCorrected register-of-information resubmission following CSSF data-quality requestDaily end-of-day accounting-position backup control for accounting systems located outside Luxembourg
FieldValidation rule
Critical or important function statusNotifications are required for planned ICT arrangements supporting critical or important functions and when a function becomes critical or important.
Planned contractual arrangement effective dateThe notification must be submitted at least three months before the arrangement takes effect, or one month where the arrangement uses a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 LFS.
ICT third-party contractual arrangement population in the registerThe register must cover all contractual arrangements on the use of ICT services provided by ICT third-party service providers at entity level and, where relevant, sub-consolidated and consolidated levels.
Register cut-off date and submission periodThe year n register must include arrangements contracted until the end of year n and be submitted between 28 February and 31 March of year n+1; the first 2025 collection covers arrangements contracted until 31 March 2025 and is submitted between 1 April and 15 April 2025.
Cloud-resource operation and cloud officer ownershipThe resource operator must designate a qualified employee as cloud officer; where the financial entity outsources resource operation, it must know the name of the resource operator’s cloud officer.

Recommended Actions

7 suggested next steps· derived from source analysis
  1. 1
    Confirmed actionStep 1 of 7

    update outsourcing intake procedures so any ICT service supporting a critical or important function is routed to CSSF notification at least three months before go-live, or one month for qualifying Luxembourg support PFS arrangements.

  2. 2
    Confirmed actionStep 2 of 7

    maintain the DORA register of information continuously and schedule the annual CSSF submission window of 28 February to 31 March, including controls for prompt correction and resubmission if CSSF requests data fixes.

  3. 3
    Confirmed actionStep 3 of 7

    identify whether Chapter 2 applies to each Luxembourg entity or branch, particularly EU branches and significant credit institutions supervised by the ECB, before assigning reporting responsibilities.

  4. 4
    Confirmed actionStep 4 of 7

    validate provider eligibility for Luxembourg ICT management or operations services subject to Article 29-3 LFS and document professional-secrecy compliance under Article 41(2a) LFS or Article 30(2a) LPS where relevant.

  5. 5
    Confirmed actionStep 5 of 7

    implement or evidence daily readable end-of-day backups of accounting and client positions where accounting systems are located outside Luxembourg, with storage in an allowed Luxembourg or EEA location.

  6. 6
    AI generatedStep 6 of 7

    classify each cloud arrangement against the circular’s cloud characteristics and additional access/automation conditions to distinguish cloud services from resource operation services.

  7. 7
    AI generatedStep 7 of 7

    appoint, document and train the cloud officer for internal resource operation, and capture the resource operator’s cloud officer name where resource operation is outsourced.

Timeline

other

Dec 14, 2022

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector was adopted.

other

Mar 13, 2024

Commission Delegated Regulation (EU) 2024/1774 specifying ICT risk-management tools, methods, processes and policies under DORA was adopted.

publication

Nov 8, 2024

The Joint ESA decision referenced by the circular for register reporting alignment was published.

publication

Jan 15, 2025

CSSF communiqué on DORA entry into application was published, referenced by the circular for the first-year register collection derogation.

effective date

Jan 17, 2025

DORA provisions became applicable to CSSF-supervised financial entities in scope of DORA.

implementation

Date not specified

First 2025 register-of-information collection window; the register must cover arrangements contracted until 31 March 2025.

effective date

Apr 9, 2025

Circular CSSF 25/882 was dated and applies with immediate effect.

implementation

Date not specified

Annual register-of-information submission window for year n registers, which must contain arrangements contracted until the end of year n and be submitted in year n+1.

Sources

AI-generated analysis is based on the following primary sources. Always verify against the official publication.

Related Evidence

Verified source support for this analysis

The evidence agent checks whether the drafted finding is supported by official publications and relevant public source material.

Receive updates like this by email

Get AI-generated analysis for the regulators and topics you care about.

Pulse is built by Datox. Datox automates AIFMD Annex IV and SEC Form PF reporting end to end.

See the Datox platform