2026-08-27

Added

Circular CSSF 26/915 — on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

Third-country branches of financial entities are included within the scope of the Digital Operational Resilience Act (DORA) if they would qualify under Article 2(1)(a) to (t) of DORA in the third country where their head office is established. Third-country branches are removed from the scope of Circular CSSF 20/750 on ICT and security risk management and Part II of Circular CSSF 22/806 on ICT outsourcing, while being included in Circulars CSSF 25/882, 25/892, and 25/893 regarding ICT third-party services, incident cost estimation, and incident reporting. Point 9 of Circular CSSF 25/893 is modified to introduce an alternative communication channel for notifying major ICT-related incidents and cyber threats if the primary channel is technically impossible to use, and the provisions apply with immediate effect.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

CSSF published 1 document in the last 30 days. We email you each new one the day it's published.

Share