← All cheat sheets

CSSF CIRCULARS (ICT / DORA)

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

The CSSF (Commission de Surveillance du Secteur Financier) is
Luxembourg's financial supervisor. This sheet maps the ICT- and
DORA-relevant circulars, what each covers, and how the April/May 2025
updates realigned the pre-DORA circulars. Reference for LU
financial-sector compliance and consulting work.

DORA PRECEDENCE (from 17 Jan 2025)#

# For DORA entities, DORA + its RTS/ITS take precedence over any
# OVERLAPPING elements in prior CSSF circulars. Non-overlapping
# provisions of those circulars remain applicable.
# Contact: ictrisksupervision@cssf.lu

CORE PRE-DORA CIRCULARS (amended)#

# CSSF 20/750  ICT and security risk management
#              -> ICT-risk parts superseded by DORA for DORA entities
# CSSF 22/806  Outsourcing arrangements
#              -> ICT outsourcing parts repealed for DORA entities;
#                 business-process outsourcing still applies
# CSSF 24/847  ICT-related incident reporting framework
#              -> superseded by DORA reporting for DORA entities

2025 REALIGNMENT CIRCULARS (Apr 2025)#

# CSSF 25/880  Update package (ICT risk / third parties realignment)
# CSSF 25/881  Update package (realignment)
# CSSF 25/882  Requirements on use of ICT third-party services for
#              DORA entities - practical modalities for notifications
#              of new critical/important arrangements + Register of
#              Information; retains still-relevant 22/806 elements
# CSSF 25/883  Amends 22/806: for DORA entities it now applies only to
#              BUSINESS-PROCESS outsourcing; fully applies to non-DORA
#              entities for both business-process and ICT outsourcing

2025 INCIDENT / COST CIRCULARS (May 2025)#

# CSSF 25/892  Financial entities must, on request, provide an
#              estimation of aggregated annual costs/losses of major
#              ICT-related incidents (per ESA guidelines template)
# CSSF 25/893  Reporting of major ICT-related incidents and significant
#              cyber threats under DORA - the LU submission modalities.
#              Replaces the eDesk "24/847 Major ICT-related incident"
#              procedure for DORA entities
# CSSF 21/769  Governance/security for telework (central admin +
#              substance in LU; cross-border commuters return on short
#              notice) - relevant to frontalier setups
# CSSF 21/787  PSD2 major incident reporting (Sofie channel)
# Note: significant institutions also report significant cyber
#       incidents directly to the ECB where applicable

OUTSOURCING NOTIFICATION LOGIC (post-DORA)#

# - Arrangements already notified under 22/806: NOT re-submitted
# - Pre-17-Jan-2025 ICT arrangements not previously notified (not
#   critical/important): NOT notified, BUT must appear in the RoI
# - New critical/important ICT third-party arrangements: notify per
#   25/882 modalities
# - Non-DORA entities: continue notifying per 22/806 as amended by 25/883

INCIDENT REPORTING (DORA, via 25/893)#

# Major incident timeline (DORA RTS): initial 4h (max 24h from
# detection) -> intermediate 72h -> final 1 month
# Significant cyber threats: voluntary notification
# See DORA-RTS-ITS.txt for classification criteria + thresholds

WHO IS IN SCOPE#

# "DORA entities": CSSF-supervised financial entities in DORA scope
#   (credit institutions, investment firms, PSPs, fund managers,
#   crypto-asset service providers, etc.)
# "Non-DORA entities": other CSSF-supervised entities - remain on the
#   amended 20/750 / 22/806 regime for the relevant topics

EXAMPLES#

# Map a client's existing 22/806 outsourcing register to DORA RoI
# Confirm incident-reporting playbook points to 25/893 modalities
# Verify new critical ICT arrangements are notified under 25/882
# Check telework governance vs 21/769 for frontalier staff

NOTES#

- The CSSF explicitly published 25/880-25/883 to remove DORA overlap
  and add clarity; read 25/882 and 25/883 together
- 24/847 is effectively retired for DORA entities' ICT incident
  reporting - do not build new processes on it
- Circular numbers and scope evolve; verify the current text on
  cssf.lu before citing in a client deliverable
- Pair with DORA-RTS-ITS.txt (EU standards) and TIBER-EU.txt (TLPT)
- Practitioner reference, not legal advice

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.