Live Updates

Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

AI Analysis

CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.

Key dates

2025-01-17
DORA began applying to in-scope financial entities supervised by the CSSF.
2025-12-17
The European Commission confirmed through DORA Q&A 102 that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF’s extended best-efforts deadline for the first register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2026-08-27
Circular CSSF 26/915 was published and took effect immediately; the listed CSSF circulars were amended to include or remove qualifying third-country branches as applicable.
2027-03-31 Deadline
Target date identified by CSSF for the required-quality register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2027-01-11
Relevant CRD VI third-country-branch provisions are scheduled to take effect, subject to national transposition and applicable transitional rules.

Suggested considerations

  • Firms should map each Luxembourg third-country branch against the counterfactual test in Circular 26/915: whether the head-office undertaking would qualify under Article 2(1)(a) to (t) of DORA if established in the relevant third country.
  • Affected branches should update their regulatory-perimeter inventories, governance documents, ICT-risk policies, outsourcing inventories, incident-classification procedures and DORA control testing to reflect immediate inclusion in the DORA-specific CSSF circulars.
  • Compliance teams may wish to separate non-ICT outsourcing, which remains subject to Part I of Circular CSSF 22/806, from ICT outsourcing, which is governed by DORA and Circular CSSF 25/882 rather than the legacy Part II framework.
  • Affected entities should validate their register-of-information process under DORA and Circular CSSF 25/882, including branch-level data, ICT third-party contracts, intra-group arrangements and submission ownership. The 30 June 2026 best-efforts deadline for third-country branches of credit institutions has passed, and firms should prepare for the 31 March 2027 collection and any CSSF remediation requests.
  • Incident-response teams should test access to the CSSF eDesk procedure and S3 API and document an escalation process for emailing [email protected] when technical impossibility prevents electronic submission.
  • Firms should assess whether they qualify for the microenterprise exclusion in Circular CSSF 25/892; the exclusion applies to entities employing fewer than 10 persons with annual turnover and/or annual balance-sheet total not exceeding EUR 2 million, subject to the DORA definition and exclusions for specified market infrastructures.
  • Third-country banking groups should coordinate DORA implementation with the CRD VI third-country-branch analysis, including the 11 January 2027 effective date for relevant CRD VI provisions, rather than assuming that the two regimes have identical scope or timing.

What changed

Qualifying third-country branches are added to the scope of Circulars CSSF 25/882, 25/892 and 25/893, covering DORA ICT third-party-service information and reporting, estimation of aggregated annual costs and losses from major ICT-related incidents under Article 11(11) of DORA and the Joint ESA Guidelines JC/GL/2024/34, and reporting of major ICT-related incidents and significant cyber threats. The relevant branches are removed from the DORA-inapplicable portions of Circulars CSSF 20/750 and 22/806: Circular 20/750 no longer applies to them, while Part II of Circular 22/806 concerning ICT outsourcing no longer applies; Part I concerning non-ICT outsourcing remains applicable. Qualifying branches are not required to include ICT outsourcing arrangements in the legacy Circular 22/806 register

Compliance impact

The impact is high for affected Luxembourg third-country branches because Circular 26/915 makes DORA-specific ICT third-party, incident-reporting and operational-resilience obligations immediately applicable and removes reliance on legacy ICT frameworks. Non-compliance may create supervisory findings, missed DORA reporting deadlines and deficiencies in ICT third-party oversight or incident governa

Who is affected

  • Luxembourg branches of third-country credit institutions that would qualify as DORA entities under Article 2(1)(a) of Regulation (EU) 2022/2554
  • Luxembourg branches of third-country investment firms that would qualify under Article 2(1)(h) or other applicable DORA categories
  • Luxembourg branches of third-country payment institutions and electronic money institutions that would qualify under Article 2(1)(d) or (e) of DORA
  • Luxembourg branches of third-country insurance or reinsurance undertakings and other third-country financial undertakings falling within the qualifying Article 2(1)(a) to (t) categories
  • CSSF-supervised DORA financial entities and their compliance, ICT-risk, outsourcing and incident-reporting functions
  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • Commission Delegated Regulation (EU) 2025/301 on ICT-related incident reporting
  • Commission Implementing Regulation (EU) 2025/302 on incident-reporting details and timelines
  • Joint ESA Guidelines JC/GL/2024/34 on aggregated annual costs and losses from major ICT-related incidents
  • Directive 2013/36/EU as amended by Directive (EU) 2024/1619 (CRD VI)
  • Directive 2009/138/EC (Solvency II)
  • Directive (EU) 2015/2366 (PSD2)

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

No description available.

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankPayment ProviderInsuranceAll Firms
View Original on CSSF Back to Feed

Share this update