Live Updates

Circular CSSF 25/893 (as amended by Circular CSSF 25/915) (Updated)

AI Analysis

CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.

Key dates

2025-01-17
DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
2025-05-28
Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
2025-11-28 Deadline
End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
2026-08-27
Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.

Suggested considerations

  • Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
  • Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
  • Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
  • PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
  • Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
  • Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
  • Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
  • Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.

What changed

DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month after the intermediate report. Significant cyber threats may be notified where the entity considers the threat relevant, using the applicable DORA process. Submissions are made through the CSSF eDesk

Compliance impact

The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immedia

Who is affected

  • Luxembourg-authorised banks and credit institutions within DORA
  • Luxembourg investment firms, payment institutions and electronic money institutions within DORA
  • Luxembourg insurance and reinsurance undertakings, investment managers, fund managers and other CSSF-supervised financial entities within the DORA scope
  • Payment service providers subject to the Luxembourg Law of 10 November 2009 but outside DORA
  • Qualifying Luxembourg branches of third-country financial entities, including relevant third-country bank branches
  • Regulated crypto-asset service providers and other financial entities within DORA Article 2
  • Regulation (EU) 2022/2554 (DORA)
  • Commission Delegated Regulation (EU) 2024/1772
  • Commission Delegated Regulation (EU) 2025/301
  • Commission Implementing Regulation (EU) 2025/302
  • Directive (EU) 2022/2555 (NIS2 Directive)
  • Luxembourg Law of 10 November 2009 on payment services
  • Circular CSSF 24/847

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankAsset ManagerPayment ProviderAll Firms
View Original on CSSF Back to Feed

Share this update