2026-08-27
Added
Third-country branches of financial entities are included within the scope of the Digital Operational Resilience Act (DORA) if they would qualify under Article 2(1)(a) to (t) of DORA in the third country where their head office is established. Third-country branches are removed from the scope of Circular CSSF 20/750 on ICT and security risk management and Part II of Circular CSSF 22/806 on ICT outsourcing, while being included in Circulars CSSF 25/882, 25/892, and 25/893 regarding ICT third-party services, incident cost estimation, and incident reporting. Point 9 of Circular CSSF 25/893 is modified to introduce an alternative communication channel for notifying major ICT-related incidents and cyber threats if the primary channel is technically impossible to use, and the provisions apply with immediate effect.
More like this from CSSF
CSSF published 1 document in the last 30 days. We email you each new one the day it's published.