Live Updates

Circular CSSF 25/892 (as amended by Circular CSSF 26/915) (Updated)

AI Analysis

CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.

Key dates

2025-05-19
The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
2025-05-31
Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
2026-08-27
Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.

Suggested considerations

  • Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
  • Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
  • Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
  • Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
  • Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
  • Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
  • Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
  • Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.

What changed

From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report. Entities should calculate each incident separately, report gross costs and losses and financial recoveries in thousands of currency units, and aggregate the results; net costs do not need to be reported separately. Relevant incidents include those classified as major under Commission Delegated Regulation (EU) 2024/1772 whose final report was submitted during the reference year, as well as earlier major inciden

Compliance impact

The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irres

Who is affected

  • Luxembourg-authorised credit institutions
  • Luxembourg investment firms
  • Luxembourg payment institutions and electronic money institutions
  • Luxembourg crypto-asset service providers and issuers of asset-referenced tokens
  • Luxembourg management companies, AIFMs and internally managed alternative investment funds
  • Luxembourg central securities depositories and central counterparties
  • Luxembourg branches of third-country undertakings that would qualify under DORA Article 2(1)(a) to (t)
  • Luxembourg crowdfunding service providers, critical benchmark administrators, trading-venue operators, APAs and ARMs within the stated scope
  • Regulation (EU) 2022/2554 (DORA), Articles 2(1), 3(60), 11(10) and 11(11)
  • Commission Delegated Regulation (EU) 2024/1772
  • Commission Implementing Regulation (EU) 2025/302
  • Commission Delegated Regulation (EU) 2024/1774
  • Regulation (EU) 2023/1114 (MiCA)
  • Law of 5 April 1993 on the financial sector
  • Law of 10 November 2009 on payment services
  • Law of 12 July 2013 on alternative investment fund managers

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)

Published by CSSF . Read the full notice at the source for the authoritative text.

View Original on CSSF Back to Feed

Share this update