Pideeco
InfoNEWS

Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated) on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)

CSSF strengthens requirements for ICT third-party services under DORA CSSF Circular 25/882 sets out practical requirements for DORA-covered financial entities using ICT third-party services, including notifications for arrangements supporting critical or important functions and the maintenance of a register of information. The circular was updated on 27 August 2026 to include relevant third-country branches within its scope.

27 Aug 2026LU_CSSF