Live Updates

Circular CSSF 26/915

AI Analysis

CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.

Key dates

2025-01-17
DORA became applicable to financial entities within the CSSF supervisory perimeter.
2025-12-17
The European Commission confirmed through DORA Q&A DORA102-3097 that DORA applies to qualifying third-country branches in an EU country.
2026-08-27
Circular CSSF 26/915 was published and its amendments took effect immediately.
2027-02-27 Deadline
The six-month transition period for PSPs not otherwise subject to DORA under Circular CSSF 25/893 is expected to end; the DORA incident-reporting framework then applies to those PSPs and Circular CSSF 21/787 is repealed for them.
2027-03-31 Deadline
Latest date in the annual CSSF register-of-information submission window for arrangements contracted during 2026, subject to the applicable CSSF collection process.

Suggested considerations

  • Firms should map each Luxembourg third-country branch against the DORA Article 2(1)(a) to (t) categories as the undertaking would be classified in the third country, documenting the legal-entity and regulatory-status analysis.
  • Compliance teams may wish to update the branch's regulatory inventory, DORA applicability assessment, governance documentation and responsibility matrices to reflect immediate inclusion where the qualifying test is met.
  • Affected branches should review ICT third-party-service contracts, the register of information and planned arrangements supporting critical or important functions, including whether CSSF notification was made at least three months before implementation or one month where the specified Luxembourg support-PFS exception applies.
  • Firms should distinguish ICT outsourcing from other outsourcing: ICT outsourcing should be managed under the DORA framework and Circular CSSF 25/882, while non-ICT outsourcing remains subject to Circular CSSF 22/806 Part I.
  • Incident-response teams should test the CSSF eDesk Portal and S3 API reporting channels and maintain a contingency process for notifying [email protected] by the applicable deadline if technical failure prevents use of the primary channel.
  • Firms should confirm that major ICT incidents are reported individually and that outsourced reporting arrangements preserve the firm's responsibility for timing, completeness and notification content.
  • Affected branches should assess whether they are microenterprises under DORA Article 3(60), since Circular CSSF 25/892 excludes microenterprises from its aggregated-cost estimation framework, except for trading venues, central counterparties, trade repositories and central securities depositories.
  • Where the branch is an EU branch rather than a third-country branch, firms should verify the home-Member-State allocation rules because the CSSF circulars generally exclude EU branches from the relevant Luxembourg reporting chapters.

What changed

The circular implements the European Commission's 17 December 2025 DORA Q&A position and includes qualifying third-country branches in the scope of Circulars CSSF 25/882 on ICT third-party services, 25/892 on aggregated annual costs and losses from major ICT incidents, and 25/893 on major ICT-related incident and significant cyber-threat reporting. Circular CSSF 20/750 is amended to remove qualifying third-country branches from its ICT and security risk-management requirements, while Circular CSSF 22/806 is amended so that Part II on ICT outsourcing no longer applies to them; Part I on non-ICT outsourcing remains applicable. The amendments also clarify that, where the prescribed CSSF incident-reporting channel is technically unavailable, a firm may notify [email protected] without

Compliance impact

The impact is high for affected third-country branches because the clarification brings them into DORA governance, ICT third-party-service, register-of-information, incident-reporting and loss-estimation regimes immediately, while removing reliance on Circulars 20/750 and 22/806 Part II for ICT matters. The CSSF states that missed notification deadlines or non-compliant arrangements may be treated

Who is affected

  • Luxembourg branches of third-country credit institutions
  • Luxembourg branches of third-country investment firms
  • Luxembourg branches of third-country payment institutions and electronic money institutions
  • Luxembourg branches of third-country crypto-asset service providers, asset-referenced token issuers, fund managers, central counterparties, central securities depositories and other undertakings within the DORA Article 2 scope
  • Regulation (EU) 2022/2554 (DORA)
  • Commission Delegated Regulation (EU) 2024/1774
  • Commission Implementing Regulation (EU) 2024/1773
  • Commission Delegated Regulation (EU) 2024/1772
  • Commission Implementing Regulation (EU) 2025/302
  • Commission Implementing Regulation (EU) 2025/301
  • Commission Delegated Regulation (EU) 2024/1778
  • Law of 5 April 1993 on the financial sector
  • Law of 10 November 2009 on payment services
  • Regulation (EU) 2023/1114 (MiCA)

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

What the CSSF said

on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg

Published by CSSF . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankBroker DealerPayment ProviderCrypto Exchange
View Original on CSSF Back to Feed

Share this update