Live Updates

Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915) (Updated)

AI Analysis

CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.

Key dates

2022-04-22
Circular CSSF 22/806 was published and replaced or amended specified earlier CSSF and IML outsourcing, governance and control circulars.
2022-06-30
Circular CSSF 22/806 became applicable according to the CSSF implementation framework.
2025-01-17
DORA Regulation (EU) 2022/2554 became applicable to in-scope financial entities, creating the primary EU framework for ICT third-party risk management.
2025-04-09
Circular CSSF 25/883 was published; the amended Circular 22/806 applies to outsourcing arrangements entered into, reviewed or amended on or after this date.
2025-12-17
The European Commission confirmed that DORA also applies to qualifying third-country branches in an EU Member State where the third-country head-office entity would fall within DORA Article 2(1)(a) to (t).
2026-08-27
Circular CSSF 26/915 was published and the CSSF webpage consolidated the amended version of Circular 22/806, confirming the DORA treatment of qualifying Luxembourg third-country branches.

Suggested considerations

  • Firms should map each outsourcing and third-party technology arrangement against the applicable regime: DORA, Circular 22/806 business-process outsourcing requirements, or the full Circular 22/806 framework for non-DORA entities.
  • Compliance teams may wish to review whether Luxembourg third-country branches have a head-office activity that corresponds to a DORA Article 2(1)(a) to (t) financial entity and document the resulting DORA scope assessment.
  • Firms should update outsourcing policies, risk assessments, governance approvals, materiality or criticality assessments, due-diligence files, monitoring controls and exit strategies to reflect the split between DORA ICT third-party risk management and Circular 22/806 business-process outsourcing.
  • Firms should maintain or update the DORA register of information for ICT third-party arrangements where DORA applies, and reconcile it with the outsourcing inventory and CSSF notification processes.
  • Firms should review legacy cloud contracts and remove reliance on the repealed Circular 22/806 EEA-law and EEA-resilience clauses where DORA is the applicable ICT third-party regime, while retaining contract terms needed to satisfy DORA and any applicable national requirements.
  • Non-DORA entities should consider whether their existing contracts still address Circular 22/806 requirements for access and audit rights, sub-outsourcing, confidentiality, data location, business continuity, termination and exit.
  • Management companies authorised solely under Article 125-1 should consider retaining the full Circular 22/806 control framework for ICT outsourcing rather than assuming that DORA displaces it.
  • Firms should assess whether outsourcing arrangements entered into, reviewed or amended from 9 April 2025 require remediation or re-papering under the amended framework.

What changed

Circular 25/883 amended Circular 22/806 following DORA Regulation (EU) 2022/2554 becoming applicable on 17 January 2025. For entities subject to DORA, the ICT-outsourcing provisions of Circular 22/806 were largely repealed or displaced by DORA's ICT third-party risk-management requirements, while Circular 22/806 remains applicable to business-process outsourcing. Circular 22/806 remains fully applicable to both ICT outsourcing and business-process outsourcing for non-DORA entities, and continues to apply fully to management companies authorised solely under Article 125-1 of Chapter 16 of Luxembourg's Law of 17 December 2010 on undertakings for collective investment. Circular 25/883 also removed certain cloud-specific contractual requirements, including the requirements that the contract be

Compliance impact

The impact is high for firms with complex ICT and outsourcing models because misclassification can lead to the wrong contractual, governance, register and notification framework, and because DORA brings direct requirements for ICT third-party risk management and supervisory oversight. Independent market commentary from EY, Deloitte, Baker McKenzie and Luxembourg industry bodies reads the amendment

Who is affected

  • Luxembourg-authorised credit institutions
  • Luxembourg-authorised investment firms
  • Luxembourg payment institutions and electronic money institutions
  • Luxembourg branches of qualifying third-country financial entities and other Luxembourg supervised entities, including UCITS management companies authorised solely under Article 125-1 of the UCI Law
  • Regulation (EU) 2022/2554 (DORA)
  • EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02)
  • Directive 2013/36/EU (CRD IV)
  • Directive (EU) 2015/2366 (PSD2)
  • Luxembourg Law of 17 December 2010 on undertakings for collective investment

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

on outsourcing arrangements

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankAsset ManagerPayment ProviderAll Firms
View Original on CSSF Back to Feed

Share this update