2025-05-28

Added · Updated

Circular CSSF 25/893 on reporting of major ICT-related incidents and significant cyber threats under DORA

Financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s) of DORA, along with Payment Service Providers not in the scope of DORA, must classify and report major ICT-related incidents and significant cyber threats using the criteria and materiality thresholds in the RTS on classification. These entities are required to submit notifications via the CSSF eDesk Portal or API interface within the time limits specified in Article 5 of the RTS on incident reporting, with aggregated reporting explicitly prohibited. The circular applies with immediate effect to most financial entities, rendering Circulars CSSF 24/847 and CSSF 21/787 no longer applicable to them, while PSPs not under DORA have a six-month transition period during which the previous circulars remain applicable.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

We email you every new CSSF publication the day it's published.

Topics
Share