Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

22 articles found · #cssf

CSSF 26/906: strengthened governance and risk — an ISO 27001 ISMS to evidence NIS 2

CSSF 26/906 tightens governance and risk for payment/e-money institutions, with compliance due by 30 June 2026. A certified ISO 27001 ISMS operationalizes these requirements and NIS 2 Article 21.

CSSF 26/904: stronger ICT evidence — inventory/CMDB becomes essential

CSSF Circular 26/904 tightens investment firms’ self‑assessment by requiring concrete evidence on ICT organization. An automated inventory and a relational CMDB are the most reliable way to demonstrate effective control.

CSSF 26/914: AMLA supervision — the ICT inventory becomes vital

CSSF 26/914 identifies entities eligible for AMLA’s direct supervision. Governance and traceability tighten: a reliable, continuous inventory/CMDB is now essential to evidence NIS 2/ISO 27001 controls.

CSSF 25/893: reporting a major incident in 4h with EDR/XDR

CSSF Circular 25/893 formalizes DORA reporting for major ICT incidents and significant cyber threats. A well‑tuned EDR/XDR stack speeds up detection, classification, and 4h/72h/1‑month notifications.

Processors: CNPD (Art. 28 GDPR) vs CSSF 22/806 — two contractual layers

CSSF’s 9 April 2025 update widens the gap with the CNPD/EDPB approach: beyond the GDPR DPA, financial entities must add access/audit clauses, prudential notifications, reversibility, and cloud-specific requirements.

CSSF 26/906: governance and DORA-grade immutable backups by June 30

CSSF 26/906 requires PSPs/EMIs to reassess governance and risk management by 30 June 2026. Immutable, isolated backups are the DORA-proof of ransomware resilience.

European Commission cloud attack — CSPM as a key control under CSSF 22/806

On March 27, 2026, the European Commission confirmed an intrusion and data exfiltration affecting Europa.eu’s cloud infrastructure. How CSPM meets CSSF 22/806 requirements and prevents such scenarios.

DORA — Third-country branches: ICT register due by June 30

DORA’s final stretch in Luxembourg: third‑country bank branches must submit their ICT register to the CSSF by June 30, 2026 at the latest. Here is how to get it done this week.

CSSF — Axios compromised (31/03/2026): EDR/XDR to detect and notify under DORA

The CSSF warns about the Axios supply‑chain compromise and reminds firms to notify a major ICT incident under Circular 25/893 (DORA). Here is how an EDR/XDR stack helps detect, contain, and notify on time.

GDPR Article 28: Belgian DPA fines SWDE — your DPA must be rock-solid

On 12 May 2026, the Belgian DPA fined SWDE €86,000, including €1,000 for lacking an Article 28-compliant DPA. Key takeaway: without a complete DPA, any outsourced processing leaves the controller non-compliant.

CSSF 25/880 — the 2026 PSP ICT Assessment requires continuous VM

The CSSF opened the 2026 “PSD2 – PSP ICT Assessment” campaign: every PSP must submit an up‑to‑date ICT risk assessment via eDesk. Continuous vulnerability management aligns with NIS 2 Art. 21 and DORA Arts. 25–27.

ANSSI risk analysis on encryption: actions for GDPR Art. 32 and CSSF 22/806

On 27/05/2026, ANSSI released an encryption risk analysis. This article turns the guidance into an at‑rest and in‑transit architecture aligned with GDPR Art. 32 and CSSF 22/806, including a post‑quantum roadmap.

Page 1 / 2 Older →