2025-05-28
Added · Updated
Financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s) of DORA, along with Payment Service Providers not in the scope of DORA, must classify and report major ICT-related incidents and significant cyber threats using the criteria and materiality thresholds in the RTS on classification. These entities are required to submit notifications via the CSSF eDesk Portal or API interface within the time limits specified in Article 5 of the RTS on incident reporting, with aggregated reporting explicitly prohibited. The circular applies with immediate effect to most financial entities, rendering Circulars CSSF 24/847 and CSSF 21/787 no longer applicable to them, while PSPs not under DORA have a six-month transition period during which the previous circulars remain applicable.
More like this from CSSF
We email you every new CSSF publication the day it's published.