CSSF CIRCULARS (ICT / DORA)
OVERVIEW#
The CSSF (Commission de Surveillance du Secteur Financier) is Luxembourg's financial supervisor. This sheet maps the ICT- and DORA-relevant circulars, what each covers, and how the April/May 2025 updates realigned the pre-DORA circulars. Reference for LU financial-sector compliance and consulting work.
DORA PRECEDENCE (from 17 Jan 2025)#
# For DORA entities, DORA + its RTS/ITS take precedence over any # OVERLAPPING elements in prior CSSF circulars. Non-overlapping # provisions of those circulars remain applicable. # Contact: ictrisksupervision@cssf.lu
CORE PRE-DORA CIRCULARS (amended)#
# CSSF 20/750 ICT and security risk management # -> ICT-risk parts superseded by DORA for DORA entities # CSSF 22/806 Outsourcing arrangements # -> ICT outsourcing parts repealed for DORA entities; # business-process outsourcing still applies # CSSF 24/847 ICT-related incident reporting framework # -> superseded by DORA reporting for DORA entities
2025 REALIGNMENT CIRCULARS (Apr 2025)#
# CSSF 25/880 Update package (ICT risk / third parties realignment) # CSSF 25/881 Update package (realignment) # CSSF 25/882 Requirements on use of ICT third-party services for # DORA entities - practical modalities for notifications # of new critical/important arrangements + Register of # Information; retains still-relevant 22/806 elements # CSSF 25/883 Amends 22/806: for DORA entities it now applies only to # BUSINESS-PROCESS outsourcing; fully applies to non-DORA # entities for both business-process and ICT outsourcing
2025 INCIDENT / COST CIRCULARS (May 2025)#
# CSSF 25/892 Financial entities must, on request, provide an # estimation of aggregated annual costs/losses of major # ICT-related incidents (per ESA guidelines template) # CSSF 25/893 Reporting of major ICT-related incidents and significant # cyber threats under DORA - the LU submission modalities. # Replaces the eDesk "24/847 Major ICT-related incident" # procedure for DORA entities
RELATED CIRCULARS#
# CSSF 21/769 Governance/security for telework (central admin + # substance in LU; cross-border commuters return on short # notice) - relevant to frontalier setups # CSSF 21/787 PSD2 major incident reporting (Sofie channel) # Note: significant institutions also report significant cyber # incidents directly to the ECB where applicable
OUTSOURCING NOTIFICATION LOGIC (post-DORA)#
# - Arrangements already notified under 22/806: NOT re-submitted # - Pre-17-Jan-2025 ICT arrangements not previously notified (not # critical/important): NOT notified, BUT must appear in the RoI # - New critical/important ICT third-party arrangements: notify per # 25/882 modalities # - Non-DORA entities: continue notifying per 22/806 as amended by 25/883
INCIDENT REPORTING (DORA, via 25/893)#
# Major incident timeline (DORA RTS): initial 4h (max 24h from # detection) -> intermediate 72h -> final 1 month # Significant cyber threats: voluntary notification # See DORA-RTS-ITS.txt for classification criteria + thresholds
WHO IS IN SCOPE#
# "DORA entities": CSSF-supervised financial entities in DORA scope # (credit institutions, investment firms, PSPs, fund managers, # crypto-asset service providers, etc.) # "Non-DORA entities": other CSSF-supervised entities - remain on the # amended 20/750 / 22/806 regime for the relevant topics
EXAMPLES#
# Map a client's existing 22/806 outsourcing register to DORA RoI # Confirm incident-reporting playbook points to 25/893 modalities # Verify new critical ICT arrangements are notified under 25/882 # Check telework governance vs 21/769 for frontalier staff
NOTES#
- The CSSF explicitly published 25/880-25/883 to remove DORA overlap and add clarity; read 25/882 and 25/883 together - 24/847 is effectively retired for DORA entities' ICT incident reporting - do not build new processes on it - Circular numbers and scope evolve; verify the current text on cssf.lu before citing in a client deliverable - Pair with DORA-RTS-ITS.txt (EU standards) and TIBER-EU.txt (TLPT) - Practitioner reference, not legal advice
CSSF CIRCULARS (ICT / DORA) CHEATSHEET ====================================== Source: https://cheatsheet.johlem.net OVERVIEW -------- The CSSF (Commission de Surveillance du Secteur Financier) is Luxembourg's financial supervisor. This sheet maps the ICT- and DORA-relevant circulars, what each covers, and how the April/May 2025 updates realigned the pre-DORA circulars. Reference for LU financial-sector compliance and consulting work. DORA PRECEDENCE (from 17 Jan 2025) ---------------------------------- # For DORA entities, DORA + its RTS/ITS take precedence over any # OVERLAPPING elements in prior CSSF circulars. Non-overlapping # provisions of those circulars remain applicable. # Contact: ictrisksupervision@cssf.lu CORE PRE-DORA CIRCULARS (amended) --------------------------------- # CSSF 20/750 ICT and security risk management # -> ICT-risk parts superseded by DORA for DORA entities # CSSF 22/806 Outsourcing arrangements # -> ICT outsourcing parts repealed for DORA entities; # business-process outsourcing still applies # CSSF 24/847 ICT-related incident reporting framework # -> superseded by DORA reporting for DORA entities 2025 REALIGNMENT CIRCULARS (Apr 2025) ------------------------------------- # CSSF 25/880 Update package (ICT risk / third parties realignment) # CSSF 25/881 Update package (realignment) # CSSF 25/882 Requirements on use of ICT third-party services for # DORA entities - practical modalities for notifications # of new critical/important arrangements + Register of # Information; retains still-relevant 22/806 elements # CSSF 25/883 Amends 22/806: for DORA entities it now applies only to # BUSINESS-PROCESS outsourcing; fully applies to non-DORA # entities for both business-process and ICT outsourcing 2025 INCIDENT / COST CIRCULARS (May 2025) ----------------------------------------- # CSSF 25/892 Financial entities must, on request, provide an # estimation of aggregated annual costs/losses of major # ICT-related incidents (per ESA guidelines template) # CSSF 25/893 Reporting of major ICT-related incidents and significant # cyber threats under DORA - the LU submission modalities. # Replaces the eDesk "24/847 Major ICT-related incident" # procedure for DORA entities RELATED CIRCULARS ----------------- # CSSF 21/769 Governance/security for telework (central admin + # substance in LU; cross-border commuters return on short # notice) - relevant to frontalier setups # CSSF 21/787 PSD2 major incident reporting (Sofie channel) # Note: significant institutions also report significant cyber # incidents directly to the ECB where applicable OUTSOURCING NOTIFICATION LOGIC (post-DORA) ------------------------------------------ # - Arrangements already notified under 22/806: NOT re-submitted # - Pre-17-Jan-2025 ICT arrangements not previously notified (not # critical/important): NOT notified, BUT must appear in the RoI # - New critical/important ICT third-party arrangements: notify per # 25/882 modalities # - Non-DORA entities: continue notifying per 22/806 as amended by 25/883 INCIDENT REPORTING (DORA, via 25/893) ------------------------------------- # Major incident timeline (DORA RTS): initial 4h (max 24h from # detection) -> intermediate 72h -> final 1 month # Significant cyber threats: voluntary notification # See DORA-RTS-ITS.txt for classification criteria + thresholds WHO IS IN SCOPE --------------- # "DORA entities": CSSF-supervised financial entities in DORA scope # (credit institutions, investment firms, PSPs, fund managers, # crypto-asset service providers, etc.) # "Non-DORA entities": other CSSF-supervised entities - remain on the # amended 20/750 / 22/806 regime for the relevant topics EXAMPLES -------- # Map a client's existing 22/806 outsourcing register to DORA RoI # Confirm incident-reporting playbook points to 25/893 modalities # Verify new critical ICT arrangements are notified under 25/882 # Check telework governance vs 21/769 for frontalier staff NOTES ----- - The CSSF explicitly published 25/880-25/883 to remove DORA overlap and add clarity; read 25/882 and 25/883 together - 24/847 is effectively retired for DORA entities' ICT incident reporting - do not build new processes on it - Circular numbers and scope evolve; verify the current text on cssf.lu before citing in a client deliverable - Pair with DORA-RTS-ITS.txt (EU standards) and TIBER-EU.txt (TLPT) - Practitioner reference, not legal advice
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.