Circular CSSF 25/892 (as amended by Circular CSSF 26/915) (Updated)
AI Analysis
CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.
Key dates
- 2025-05-19
- The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
- 2025-05-31
- Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
- 2026-08-27
- Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.
Suggested considerations
- Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
- Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
- Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
- Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
- Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
- Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
- Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
- Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.
What changed
From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report. Entities should calculate each incident separately, report gross costs and losses and financial recoveries in thousands of currency units, and aggregate the results; net costs do not need to be reported separately. Relevant incidents include those classified as major under Commission Delegated Regulation (EU) 2024/1772 whose final report was submitted during the reference year, as well as earlier major inciden
Compliance impact
The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irres
Who is affected
Related regulations
References
AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
Published by CSSF . Read the full notice at the source for the authoritative text.