DORA: CSSF tightens major ICT incident reporting
CSSF releases additional operational instructions for DORA major ICT incident reporting. Deadlines, content and data quality are tightened, aligning with the EU framework.
On 29 September 2026, the CSSF issued additional operational instructions for reporting major ICT-related incidents under DORA. The aim: more complete, better structured, EU‑harmonised reports, to be applied immediately by Luxembourg financial entities.
Key points
- Who — CSSF clarifies expectations to improve the quality and effectiveness of major ICT incident notifications.
- What — Complementary instructions add to the ESAs’ guidance to reduce supervisory back‑and‑forth and align data with the EU framework.
- Where — Luxembourg, submissions via the CSSF eDesk portal.
- When — ESAs instructions on 16 September 2026; CSSF publication on 29 September 2026.
- How fast — Binding time limits: initial notification ≤ 4 h after classification (and ≤ 24 h after detection), interim report ≤ 72 h after the initial, final report ≤ 1 month after the last interim.
Legal basis
- Regulation (EU) 2022/2554 “DORA” — Article 19 (management and reporting of incidents) with three deliverables (initial, interim, final). See the DORA framework, Chapter III for classification and notification.
- Level 2 — Commission Delegated Regulation (EU) 2025/301 specifies content and timelines: 4 h/24 h for initial, 72 h for interim, 1 month for final.
- EU level — ESAs’ Operational Instructions (16/09/2026) detail supervisory expectations and EU‑wide data harmonisation.
What changes for Luxembourg entities
- Lower tolerance on timing and quality — CSSF expects better structured, complete initial notifications aligned with ESAs templates, including outside business hours for major or cross‑border incidents.
- Content matters as much as speed — Provide precise context, scope, materiality criteria, containment measures, business/customer impacts and preliminary economic indicators.
- Immediate EU alignment — Incident/cyber, compliance, DPO and IT risk teams must use common criteria and taxonomies. For local implementation, see DORA in Luxembourg (CSSF).
Actions to take this week
- Test your 24/7 alert chain — Update escalation so “major” classification and initial filing occur within 4 h (≤ 24 h after detection). Run a timed tabletop and set on‑call and backup roles.
- Pre‑populate DORA templates — Build a “major incident” kit (entity identifiers, contacts, critical systems/activities, impact matrices, trigger criteria) aligned with ESAs templates and CSSF notes.
- Calibrate classification and evidence — Align internal thresholds with DORA RTS/ITS and document decisions and timestamps (detection, classification, submissions).
- Strengthen operational resilience — Enhance BCP/DRP exercises and IT‑business coordination; our experts can help with business continuity and DORA resilience tailored to your context.
Bottom line
CSSF immediately tightens expectations: meeting the 4 h / 24 h / 72 h / 1 month deadlines is not enough without impeccable content quality. Prepare templates, backup roles and classification evidence in strict alignment with DORA and ESAs instructions.
Need assistance
For local DORA setup or a 24/7 escalation drill, our team can help. Reach out via our contact page.
Article generated by Luxgap regulatory watch. For tailored guidance on this topic, contact us.
How Luxgap can help
External CISO
Appoint us as your information security officer: we take operational ownership of policy, governance, risk, audits and incidents, with NIS 2 or DORA where they apply.
See the CISO mandateA question on this topic?
Our team usually replies within one business day. Configure your quote or write to us.
Build my quote →