Live Updates

Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915) (Updated)

AI Analysis

CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.

Key dates

2020-08-25
Circular CSSF 20/750 was originally published, establishing CSSF expectations for ICT and security risk management.
2025-01-17
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector became applicable to DORA-defined financial entities supervised by the CSSF.
2025-04-09
Circular CSSF 25/881 amended Circular 20/750, narrowing it primarily to non-DORA entities and moving PSP-specific requirements to Circular CSSF 25/880.
2026-08-27
Circular CSSF 26/915 was published and applies with immediate effect; DORA-equivalent third-country branches are removed from Circular 20/750 and addressed through the DORA-related CSSF framework.

Suggested considerations

  • Firms with Luxembourg third-country branches should document an entity-by-entity DORA scoping analysis, including the classification of the non-EU head-office undertaking under Article 2(1)(a) to (t) of Regulation (EU) 2022/2554 and the relevance of Article 2(2).
  • Affected branches should consider retiring Circular 20/750 as their primary ICT framework and mapping controls instead to DORA and the applicable CSSF circulars, including Circular CSSF 25/882 on ICT third-party services and Circular CSSF 25/893 on major ICT-related incidents and significant cyber threats.
  • Firms should review ICT third-party inventories, contracts, due diligence files, exit strategies and, where relevant, the DORA Register of Information so that all ICT services are captured regardless of whether the arrangement is formally classified as outsourcing.
  • Entities remaining within Circular 20/750 should consider confirming that the management body has approved the ICT and security risk-management framework and that it is reviewed at least annually.
  • Remaining in-scope entities should consider refreshing their annual ICT and security risk assessment, critical-function and information-asset mapping, threat and vulnerability monitoring, access controls, patching, backup, recovery, incident-response and business-continuity documentation.
  • Compliance teams may wish to verify that critical ICT systems undergo security testing at least annually, non-critical systems are tested regularly and at least every three years, and critical business continuity arrangements are tested at least annually.
  • Branches and PSP-related entities should consider validating incident-reporting channels and escalation procedures, including the CSSF alternative email channel for exceptional technical failures where the prescribed DORA reporting channel cannot be used.
  • Firms should consider preserving evidence of proportionality assessments, control testing, audit findings, remediation, management-body reporting and staff security training for CSSF supervisory review.

What changed

Circular 26/915 applies with immediate effect and removes DORA-equivalent third-country branches from the scope of Circular 20/750. A third-country branch is treated as DORA-relevant where, in the jurisdiction of its head office, the undertaking would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554, subject to the applicable exclusions and Article 2(2) conditions. The affected branches are instead brought into the scope of the CSSF circulars addressing DORA ICT third-party services, major ICT-related incident and significant cyber-threat reporting, and related DORA reporting requirements. For entities that remain within Circular 20/750, the framework continues to require proportionate ICT governance, management-body accountability, annual ICT and security

Compliance impact

The immediate-effect scope change is operationally significant for third-country branches because applying the wrong framework could result in duplicated controls, incomplete DORA reporting, or failure to maintain DORA third-party and incident-reporting records. For entities remaining under Circular 20/750, the CSSF continues to expect a documented, independently controlled and annually reviewed I

Who is affected

  • Luxembourg branches of third-country credit institutions that would qualify as DORA-covered entities in their home jurisdiction
  • Luxembourg branches of third-country investment firms that would qualify as DORA-covered entities in their home jurisdiction
  • Luxembourg branches of third-country payment institutions and electronic money institutions that would qualify as DORA-covered entities in their home jurisdiction
  • Luxembourg branches of other third-country undertakings corresponding to entities listed in Article 2(1)(a) to (t) of DORA
  • Luxembourg support professionals of the financial sector and specialised professionals of the financial sector remaining outside DORA
  • POST Luxembourg when providing payment services
  • CSSF-supervised non-DORA entities that remain within Circular CSSF 20/750
  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • Circular CSSF 25/882 on requirements on the use of ICT third-party services for financial entities subject to DORA
  • Circular CSSF 25/893 on reporting of major ICT-related incidents and significant cyber threats under DORA
  • Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment
  • Circular CSSF 22/806 on outsourcing arrangements
  • EBA Guidelines EBA/GL/2019/04 on ICT and security risk management, as amended by EBA/GL/2025/02
  • Law of 10 November 2009 on payment services

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

Requirements regarding information and communication technology (ICT) and security risk management

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankBroker DealerPayment ProviderAll Firms
View Original on CSSF Back to Feed

Share this update