CSSF 26/906: strengthened governance and risk — an ISO 27001 ISMS to evidence NIS 2
CSSF 26/906 tightens governance and risk for payment/e-money institutions, with compliance due by 30 June 2026. A certified ISO 27001 ISMS operationalizes these requirements and NIS 2 Article 21.
Excerpt — On 20 January 2026, the CSSF released Circular 26/906 tightening governance and risk management for payment and e-money institutions, with a latest compliance date of 30 June 2026. Here is how a certified ISO 27001 ISMS evidences these requirements and NIS 2 Article 21 for your boards.
Key facts
On 20 January 2026, the CSSF published Circular 26/906 “Central administration, internal governance and risk management,” applicable to payment and e-money institutions. It replaces older circulars (IML 95/120, 96/126, 98/143 and CSSF 04/155) and requires institutions to assess and revise their governance and risk management framework to be compliant by 30 June 2026. Focus areas include management body responsibilities, organization of internal control functions, management of conflicts of interest, the new product approval process, and safeguarding of funds. Official source: CSSF – Circular 26/906 release (20/01/2026).
In the same vein, on 7 July 2026 the CSSF warned about “opportunities and risks” tied to AI adoption, observing in financial institutions infrequent vulnerability scans and late patching versus the threat pace. This is an operational signal that expectations are tightening on demonstrable control of ICT and cybersecurity risks. Source: CSSF – Evolving opportunities and risks in AI (07/07/2026).
The applicable legal framework
Beyond Luxembourg sectoral law, two texts structure your obligations:
- CSSF Circular 26/906: strengthens management body accountability, the effectiveness of control functions (risk, compliance, audit), traceability of decisions (new products, conflicts of interest), and the ability to demonstrate risk management, including ICT.
- NIS 2 – Article 21: requires cybersecurity risk management measures based on an all-hazards approach, including at minimum policies/processes, incident management, business continuity, supply chain security, vulnerability management, access control and encryption. References: EUR‑Lex – Directive (EU) 2022/2555 NIS 2 and Commission Guidelines (Art. 4 NIS 2). For the technical implementation, see ENISA: ENISA – NIS 2 Technical Implementation Guidance.
Executive translation: CSSF requires provable governance of your risks; NIS 2 mandates minimum measures and clear roles/responsibilities up to the board. Both call for a formal, auditable and living management system. For a local overview, see our resource on NIS 2 in Luxembourg.
The technical solution: a certified ISO 27001 ISMS
Why: An ISO 27001:2022 Information Security Management System (ISMS) provides the procedural and documentary backbone required by CSSF 26/906 and systematically covers NIS 2 Art. 21 measures. It enables:
- A governance-anchored PDCA (Plan-Do-Check-Act) framework: security policy, roles, risk committees, management reviews, dashboards.
- Asset mapping (A.5.9) and critical processes (payments/issuance), a risk register aligned business-ICT, and proportionate controls.
- Annex A controls directly mapped to NIS 2 expectations:
- Access management (A.5.15–A.5.18), identities/privileges, segregation of duties;
- Business continuity and disaster recovery (A.5.30–A.5.31);
- Vulnerability management and patching (A.8.8–A.8.9);
- Supplier/supply chain security (A.5.19–A.5.21);
- Logging and monitoring (A.8.15–A.8.16);
- Cryptography (A.8.24–A.8.26).
- Evidence of effectiveness: metrics, internal audits, continuity tests and management reviews, addressing CSSF and NIS 2 expectations.
How it works in practice: The ISMS orchestrates governance (security committee reporting to the management body), risk management (method, risk acceptance), operationalization (access, hardening, vulnerabilities, incident response), compliance (NIS 2, GDPR, DORA) and evidence (reports, KPIs, audit trails). ENISA provides helpful mappings from Annex A to NIS 2 Art. 21: ENISA – NIS 2 Technical Implementation Guidance. To anchor this effort locally, see our ISO 27001 Luxembourg page.
How Luxgap delivers
- Our ISO 27001 governance: we act as Lead Implementer with a 12‑week roadmap to build or realign the ISMS to ISO 27001:2022, mapping each control to NIS 2 Article 21 and to CSSF 26/906 concrete expectations (roles, committees, board reporting, product approval, three lines of defense).
- Our outsourced DPO and CISO: we structure the quarterly management review, KPIs (vulnerabilities, patch SLAs, incidents), and prepare evidence packs for CSSF/NIS 2 inspections (policies, continuity plans, vendor registers). Need governance reinforcement? Explore our outsourced CISO service.
- Our PECB‑certifying trainings (ISO 27001, NIS 2): targeted sessions for boards and key function holders (risk, compliance, audit), focused on duties of oversight and metric interpretation.
Practically, we do not “sell” a badge: we implement the mechanisms (committees, processes, controls) that will last over time and evidence compliance with 26/906 + NIS 2.
Use case in Luxembourg or the EU
An e-money institution operating B2B aligned its governance to 26/906 in 6 weeks: creation of a security/risk committee reporting to the board, a unified risk register (business/ICT), a product approval procedure including security-by-design control and an NIS 2 Art. 21 checklist, monthly metrics (mean time to patch criticals, segmentation rate, EDR coverage), and a test plan (crisis exercises + restore). Outcome: evidence pack ready by 30 June 2026 and a decision to pursue ISO 27001 certification to anchor compliance.
First concrete steps
- Mandate the board: table in September an ISO 27001‑aligned security management review (risks, incidents, NIS 2 compliance), with recorded decisions.
- Map critical assets (A.5.9) and payment flows: deliver a “minimal viable” list in 10 days (systems, data, vendors) as the basis of your risk register.
- Set a monthly vuln/patch loop aligned with CSSF expectations (scan frequency + remediation SLAs), with metrics (SLA CVSS ≥ 9.x) and an approved exceptions plan.
- Formalize product approval: security‑by‑design checklist (access control, encryption, logging, testing), control functions’ opinions (risk, compliance) and a recorded management body decision.
- Launch the ISMS: policy, scope, risk method, treatment plan, Annex A ↔ NIS 2 Art. 21 mapping (leveraging ENISA) and certification timeline if relevant. For regulatory insights, see our NIS 2 directive page.
Official sources
- CSSF — Circular CSSF 26/906 release (20/01/2026)
- CSSF — Evolving opportunities and risks in AI (07/07/2026)
- EUR‑Lex — Directive (EU) 2022/2555 (NIS 2), Art. 21
- ENISA — NIS 2 Technical Implementation Guidance (technical mapping)
Contact us to build an ISO 27001 ISMS aligned with 26/906 + NIS 2 ahead of the deadline.
A question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →