2024-01-05
Added · Updated
Supervised Entities must classify ICT-related incidents based on specific criteria and notify the CSSF when incidents are classified as major or significant. Major incidents require submission of initial, intermediate, and final notifications via a new digital form within defined time limits, with classification required no later than 24 hours after detection. Entities subject to the NIS Law as Operators of Essential Services or Digital Service Providers must also report significant incidents under this framework. The circular applies to credit institutions, payment institutions, investment firms, and other financial sector entities in Luxembourg.
More like this from CSSF
We email you every new CSSF publication the day it's published.