Pideeco
InfoNEWS

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated) amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

CSSF updates ICT and security risk management requirements: CSSF Circular 25/881 amends the Luxembourg framework for ICT and security risk management to reflect the application of DORA and reduce regulatory overlap. It narrows the relevant EBA Guidelines and maintains specific requirements for PSPs and non-DORA entities. The circular was further amended in August 2026 to reflect DORA's application to certain third-country branches.

27 Aug 2026LU_CSSF

Related updates

InfoREPORT

CSSF publishes Q2 2026 statistics on Luxembourg investment fund managers

The CSSF has published its quarterly statistics on investment fund managers, reflecting the situation as at 30 June 2026. The publication covers authorised and other investment fund managers, assets under management, investment strategies and cross-border activities, including 108 authorised IFMs represented by a branch in one or more EU Member States. The statistics are informational and introduce no new compliance obligations.

21 Sep 2026

InfoNEWS

CSSF extends LMT activation module to notifications of suspension of redemptions

On 18 September 2026, the CSSF announced that, from 21 September 2026, the activation and deactivation of a suspension of redemptions only must be notified through the CSSF eDesk “LMT activation” module. The requirement applies to Luxembourg UCIs, SIFs and SICARs within the scope of the communication. While a redemption-only suspension is not itself an LMT under the Luxembourg Law of 3 March 2026, the CSSF has integrated it into the LMT notification module. Existing administrative and documentation requirements remain unchanged. Compliance action: ensure relevant procedures and responsible teams are ready to use the eDesk module as of 21 September 2026.

18 Sep 2026

ImportantNEWS

CSSF warns of active exploitation of CVE-2026-76461 in Cisco Secure Email Gateway

The CSSF has issued a communiqué alerting supervised entities to the active exploitation of CVE-2026-76461, a vulnerability in the email parsing component of Cisco AsyncOS Software for Cisco Secure Email Gateway that permits unauthenticated remote code execution with root privileges. The regulator reminds entities that such unauthorised malicious access qualifies as a major ICT-related incident requiring notification under Circular CSSF 25/893 (DORA) or CSSF 24/847, depending on entity type.

15 Sep 2026