Pideeco
NoticeGUIDELINE

CSSF and Luxembourg authorities publish NIS2 incident handling rulebooks

The HCPN/ANSSI/GOVCERT.LU, CIRCL, CSSF and ILR have jointly published a set of rulebooks providing operational guidance for handling cybersecurity incidents under Article 14(5) of Luxembourg's NIS2 Act. The rulebooks cover detection, containment, investigation, remediation, evidence keeping, post-incident activities and communication for specific incident scenarios, and are primarily aimed at entities subject to the NIS2 Act. They are hosted on GitHub and are non-binding, without prejudice to existing notification obligations.

28 Sep 2026LU_CSSF

Related updates

InfoNEWS

CSSF clarifies professional secrecy and its legal exceptions

The CSSF has published a communiqué (French only) recalling the legal framework governing its professional secrecy obligation and the exceptions to it. The clarification responds to questions about the limits on the CSSF's ability to communicate publicly on its supervisory work, notably in light of its numerous publications of administrative sanctions. The communiqué confirms that secrecy is an institutional, public-order regime whose exceptions must be expressly provided for by law.

02 Oct 2026

ImportantGUIDELINE

CSSF publishes additional operational instructions on DORA major ICT incident reporting

On 29 September 2026, the CSSF drew the attention of financial entities to the operational instructions issued by the European Supervisory Authorities (EBA, EIOPA and ESMA) on reporting major ICT-related incidents under DORA (Regulation (EU) 2022/2554). The CSSF also published its own supplementary operational instructions, which aim to improve the quality of information submitted, streamline the reporting process and reduce subsequent exchanges with the supervisor. Entities within the CSSF's DORA perimeter are expected to take due account of these practical instructions.

29 Sep 2026

InfoNEWS

ESMA’s DORA incident reporting - operational instructions

The ESAs have published operational instructions for reporting major ICT-related incidents under DORA. The instructions aim to improve data quality, reporting consistency and supervisory efficiency. The CSSF has also issued additional practical instructions for Luxembourg entities. Financial entities should review their incident management and reporting processes to ensure that reports contain complete and sufficiently detailed information. The instructions do not replace DORA’s existing legal requirements.

29 Sep 2026