Live Updates

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated)

AI Analysis

Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).

Key dates

2025-01-17
DORA became applicable to financial entities within its scope, subject to the specific DORA provisions and technical standards applicable to each entity.
2025-04-09
Circular CSSF 25/881 was published and took effect, removing DORA financial entities from Circular 20/750 and retaining 20/750 for entities outside DORA; PSP-specific provisions were reorganised under Circular 25/880.
2026-06-30 Deadline
CSSF extended the first Register of Information submission for Luxembourg branches of third-country credit institutions to this date on a best-efforts basis; the CSSF indicated that the required level of quality should be achieved for the 2027 submission.
2026-08-27
Circular CSSF 26/915 was published, confirming the DORA treatment of qualifying third-country branches and removing them from the full scope of Circular 20/750 and related overlapping circular provisions.
2027-03-31 Deadline
Target date identified by the CSSF for the required-quality Register of Information submission by Luxembourg branches of third-country credit institutions.

Suggested considerations

  • Firms should classify each Luxembourg entity and branch against DORA Article 2 and the amended scope of Circular 20/750, including an assessment of whether a third-country head office would qualify under DORA Article 2(1)(a) to (t).
  • Compliance teams may wish to determine whether the entity should operate under DORA rather than 20/750, and document the rationale, legal-entity perimeter and treatment of any Luxembourg branch.
  • Firms remaining within Circular 20/750 should consider reviewing their ICT and security-risk-management framework, governance approvals, risk assessments, incident processes, business-continuity arrangements and control testing against the continuing requirements.
  • Payment service providers should consider replacing references to the PSP provisions formerly contained in Circular 20/750 with the applicable requirements in Circular CSSF 25/880 and EBA/GL/2025/02.
  • Third-country branches treated as DORA entities should consider validating their DORA governance, ICT-risk framework, incident-reporting arrangements, ICT contractual inventory and Register of Information processes, taking account of CSSF reporting communications.
  • Firms should update policies, regulatory inventories, outsourcing and ICT-third-party registers, training materials and regulatory mapping to distinguish DORA obligations from the residual Circular 20/750 obligations.
  • Compliance teams may wish to retain evidence of the scope assessment and implementation date, because the 2025 amendment was effective immediately and the 2026 amendment changes the treatment of a previously identified 20/750 population.

What changed

Circular 25/881 provides that DORA financial entities supervised by the CSSF no longer fall within Circular 20/750; for entities covered by 20/750 but outside DORA, the circular continues to apply in full. Payment-service-provider-specific ICT and security-risk provisions were removed from 20/750 and regrouped in Circular CSSF 25/880, reflecting the revised EBA Guidelines on ICT and security risk management for payment service providers, including EBA/GL/2025/02. Circular 26/915 amends 20/750 and related CSSF ICT circulars to remove Luxembourg third-country branches from the relevant 20/750 scope where they qualify as DORA financial entities by reference to the activities of their third-country head office; those branches are instead treated as subject to DORA. The remaining 20/750 populat

Compliance impact

The principal impact is perimeter and framework migration rather than a wholly new ICT-control standard: entities in DORA must avoid relying on residual 20/750 requirements where DORA governs, while non-DORA entities retain substantive 20/750 obligations. The CSSF and market commentary indicate that misclassification may create gaps in DORA governance, ICT-third-party documentation, incident repor

Who is affected

  • Support PFS authorised under the Luxembourg Law of 5 April 1993 on the financial sector
  • Specialised PFS authorised under the Luxembourg Law of 5 April 1993 on the financial sector
  • POST Luxembourg in its relevant financial-services capacity
  • Luxembourg branches of third-country credit institutions
  • Luxembourg branches of third-country investment firms
  • Luxembourg branches of third-country payment institutions and electronic-money institutions
  • DORA financial entities supervised by the CSSF, including credit institutions, investment firms, payment institutions, electronic-money institutions, fund managers, crypto-asset service providers, trading venues, central counterparties and central securities depositories
  • Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)
  • Commission Delegated Regulation (EU) 2024/1774 supplementing DORA with regard to ICT risk-management tools, methods, processes and policies
  • Commission Implementing Regulation (EU) 2024/295 establishing implementing technical standards for the Register of Information
  • EBA/GL/2025/02 on ICT and security risk management for payment service providers
  • Luxembourg Law of 5 April 1993 on the financial sector

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankBroker DealerPayment ProviderAll Firms
View Original on CSSF Back to Feed

Share this update