← All articles

consultant

CSSF 25/903: Support PSF — the inventory/CMDB as key evidence

CSSF 25/903 strengthens 24/850 and requires structured evidence on support PSF ICT organization. An automated inventory/CMDB becomes central to trace assets, dependencies and controls, and to meet NIS 2 obligations.

On 23 December 2025, the CSSF issued Circular 25/903, strengthening Circular 24/850 by requiring support PSF to provide more structured evidence (descriptive report, self‑assessment questionnaire, auditor’s work) on their ICT organization and controls. Here is how an automated inventory/CMDB concretely meets these requirements and NIS 2 obligations.

Key facts

On 23/12/2025, the CSSF published Circular CSSF 25/903, which updates Circular 24/850 (support PSF) across three areas: the descriptive report, the self‑assessment questionnaire and the work/recommendation letter of the approved statutory auditor. In practice, 25/903 tightens expectations on the traceability of ICT assets, dependencies and applicable controls, and formalizes the format and submission schedule of this evidence to the CSSF. These requests apply to all support PSF under the LSF, including hosting, managed services, managed security and technical assistance providers operating in Luxembourg. Source: CSSF – release 25/903, text of 25/903 (PDF), 24/850 consolidated.

This tightening comes amid chained attacks via providers and IT tools. In April 2026, Snowflake customers were targeted after a third‑party SaaS integrator was compromised (token theft and access to data at multiple customers)—a typical case of poorly mapped dependency that hampers incident detection and notification for principals and their processors (BleepingComputer, 07/04/2026). In May 2026, The Register reported ongoing supply chain attacks in SAP/npm packages spreading credential stealers (The Register, 01/05/2026). These events highlight that without a reliable, up‑to‑date inventory of services, software and integrations, it is impossible to assess exposure, contain incidents and produce consistent regulatory reports.

The applicable legal framework

Three texts drive expectations:

  • CSSF Circulars 24/850 and 25/903: they define the content of the descriptive report, the self‑assessment questionnaire and the auditor’s work for support PSF, with a focus on describing ICT organization, assets, controls and dependencies (outsourcing, third‑party services) and on the ability to provide up‑to‑date evidence. Sources: CSSF – release 25/903, 25/903 (PDF), 24/850.
  • NIS 2, Article 21(2)(d): an obligation to identify and manage risks related to the ICT supply chain and relationships with digital service providers. This requires, for essential/important entities and providers alike, a comprehensive, traceable view of dependent components and flows. For local context and implementation, see NIS 2 requirements. Text: Directive (EU) 2022/2555 (NIS 2).
  • GDPR, Article 32: appropriate technical and organizational measures; in an incident, a systems and logs inventory is essential to demonstrate proportionality and to notify breaches (Articles 33–34). Text: GDPR.

The technical solution to deploy

Asset inventory + relational CMDB (Configuration Management Database): the building block that turns a static “who does what” into operational, auditable evidence aligned with CSSF circulars and NIS 2.

  • What it is: a unified repository that automatically captures and links equipment, VMs/containers, applications, microservices, technical accounts, certificates/keys, SaaS/API dependencies, providers (contracts, processing locations), network/Cloud flows, and associated controls (encryption, backups, MFA, logging, DLP, etc.).
  • How it works in practice:
    • Agent/agentless discovery across environments (on‑prem, VMware, AWS/Azure/GCP, M365, endpoints) + Cloud asset graph for managed services.
    • API ingestion from directories (IAM/IdP), EDR/XDR, vulnerabilities, DevOps tools, and critical SaaS (ITSM, CRM, data platform).
    • Modeling relationships (CMDB): application → components → external dependencies (SaaS/API) → data processed → security measures → evidence (logs, screenshots, change tickets).
    • Quality controls: completeness, freshness, consistency, with alerts when a non‑inventoried asset emits logs or traffic.
    • Exports aligned to CSSF templates: “descriptive report”, “self‑assessment questionnaire” views and the audit file for the auditor.
  • Reference standards: ISO 27001:2022 Annex A.5.9 (inventory of information assets), A.5.10 (asset ownership), A.8.16/A.8.23 (logging and monitoring), NIST CSF v2.0 ID.AM (Asset Management), CIS Controls 1 & 2 (Inventory and Control of Enterprise/Software Assets). To go further on certification, see ISO 27001 in Luxembourg.
  • Why now: attacks via SaaS integrations and IT tools keep rising; without a living map, you cannot quickly know which customers, environments or flows are affected, nor produce consistent CSSF reporting. 2026 examples: Snowflake/Anodot and npm/PyPI supply chain.

How Luxgap deploys this

  • Our ISO 27001 governance: our Lead Implementers design the CMDB data model tailored to your support PSF licenses and the appendices expected by 25/903; we define the inventory charter, data ownership and quality controls.
  • Our managed SOC: we connect the CMDB to your SIEM/EDR/XDR to correlate assets ↔ events. During incidents, we know which systems/data/providers are affected and extract evidence for the auditor and, if needed, for regulatory notifications. Explore our managed SOC capability.
  • Our outsourced DPO and CISO consultants: they align the inventory with GDPR Art. 30/32 and NIS 2 Art. 21(2)(d): processing register ↔ application assets ↔ flows ↔ measures; they prepare CSSF views (descriptive report, questionnaire) and a traceable remediation plan.

Case in Luxembourg or the EU

A multi‑cloud managed services support PSF (~150 regulated customers) had to update its descriptive report and questionnaire under 25/903. In six weeks, we:

  • Deployed auto‑discovery across 3 hyperscalers + M365 + private datacenter (~8,000 assets, 120 apps, 45 SaaS integrations).
  • Normalized CMDB relationships and mapped 100% of critical third‑party providers with their flows and data locations.
  • Correlated CMDB ↔ SIEM/EDR: detected and onboarded 12% “orphan” assets; cut or secured 4 undeclared SaaS flows (MFA/OAuth re‑scoped).
  • Produced CSSF views and an audit file ready for the auditor (evidence samples, timestamps, screenshots, CSV exports).

Result: submission approved without major iterations; measurable incident‑response gains (who is impacted?) during an alert tied to a compromised npm dependency, with containment in 48 hours.

Practical first steps

  1. List source systems for the inventory (Cloud, vCenter, AD/AAD, MDM, EDR, ITSM, critical SaaS) and validate required API access.
  2. Select a minimal viable CMDB model (assets, services, dependencies, suppliers, data, controls) and lock the glossary.
  3. Run automated discovery on a pilot scope (e.g., one Cloud environment + M365) and measure quality: completeness, freshness, duplicates.
  4. Link CMDB ↔ compliance: prepare “descriptive report”/“questionnaire” exports required by 25/903 and build the evidence set for the auditor.
  5. Wire in detection: integrate CMDB with SIEM/EDR to enrich alerts by service criticality and dependency mapping (and test on a supply chain attack scenario).

Official sources

To discuss your scope and CSSF timelines, tell us about your context.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →