Circular CSSF 26/915 on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg
CSSF clarifies DORA application to third-country branches: The CSSF has published Circular 26/915, confirming that certain third-country branches in Luxembourg fall within DORA's scope. The circular updates several CSSF requirements covering ICT risk management, ICT third-party services, outsourcing and major ICT incident reporting, with immediate effect.
Related updates
Circular CSSF 25/883 (as amended by Circular CSSF 26/915) (Updated) amending Circular CSSF 22/806 on outsourcing arrangements
CSSF aligns outsourcing requirements with DORA: CSSF Circular 25/883 amends the Luxembourg outsourcing framework to avoid overlap with DORA. For DORA entities, ICT outsourcing requirements under Circular 22/806 are largely replaced by DORA, while BPO remains covered. Non-DORA entities continue to apply the relevant ICT outsourcing and BPO requirements under Circular 22/806. The circular was updated on 27 August 2026.
27 Aug 2026
Circular CSSF 25/882 (as amended by Circular CSSF 26/915) (Updated) on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
CSSF strengthens requirements for ICT third-party services under DORA CSSF Circular 25/882 sets out practical requirements for DORA-covered financial entities using ICT third-party services, including notifications for arrangements supporting critical or important functions and the maintenance of a register of information. The circular was updated on 27 August 2026 to include relevant third-country branches within its scope.
27 Aug 2026
Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated) amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
CSSF updates ICT and security risk management requirements: CSSF Circular 25/881 amends the Luxembourg framework for ICT and security risk management to reflect the application of DORA and reduce regulatory overlap. It narrows the relevant EBA Guidelines and maintains specific requirements for PSPs and non-DORA entities. The circular was further amended in August 2026 to reflect DORA's application to certain third-country branches.
27 Aug 2026

