← All articles

consultant

DORA Art. 28: Register of Information — CSSF expectations for 2026

The CSSF opened eDesk and set a DORA Register of Information submission window from 11 February to 31 March 2026. Content is standardized by ITS (EU) 2024/2956 and subject to strict validation rules.

Verified fact — The CSSF opened the eDesk portal and set the first 2026 submission window for the DORA Register of Information (RoI) from 11 February to 31 March 2026. Takeaway — The required granularity is set by ITS (EU) 2024/2956 and enforced through strict validation rules. See the CSSF notice: eDesk portal open and the ITS: Implementing Regulation (EU) 2024/2956.

The case

On 11 February 2026, the CSSF opened its eDesk portal to collect the RoI required by Article 28(3) of the DORA Regulation (EU) 2022/2554. Financial entities under its supervision had to submit their RoI by 31 March 2026 (third‑country branches of banks: 30 June 2026 on a best‑effort basis). This collection also stems from CSSF Circular 25/882. Reference: CSSF communication.

At EU level, the format and data fields are set by Implementing Regulation (EU) 2024/2956 of 29 November 2024, establishing standardized templates under Article 28(9) DORA. The CSSF page ICT and cyber risk – for DORA entities explicitly refers to this text and the practical documentation (taxonomy, validations) published by the ESAs. For background, see our page on the DORA framework and operational resilience.

Legal reasoning

  • Primary legal basis. Article 28(3) DORA requires each financial entity to maintain and update, at entity, sub‑consolidated and consolidated levels, a register of all contractual arrangements for the use of ICT services provided by third‑party providers. It also requires annual reporting of indicators on new agreements and timely notification to the supervisor for any agreement supporting a critical or important function. Ref.: CSSF DORA page.
  • Content standardization. Under Article 28(9) DORA, the Commission adopted, via ITS 2024/2956, detailed templates specifying required granularity: identification of each ICT provider, each contractual arrangement, supported ICT functions and services, sub‑outsourcing chains, countries, and critical/important flags. See the ITS 2024/2956.
  • Luxembourg specifics. The CSSF reminds that the RoI must be available and submitted annually (and at any time upon request), that planned arrangements supporting critical/important functions must be notified in advance (timelines set in Circular 25/882), and that submission follows ESA/CSSF validation rules (taxonomy, controls, error messages). Ref.: CSSF guidance.
  • ESA clarifications. The EBA/ESAs DORA Q&A clarifies how the Article 28(3) annual communication (statistics on new agreements) complements other obligations (RoI, planned arrangement notifications): Q&A 2025_7309.

What this changes in practice

  1. A machine‑readable, contract‑level inventory. The RoI aggregates standardized attributes for each ICT relationship (provider identifiers — LEI where available —, ICT service type, linkage to functions, critical/important status, sub‑outsourcing chain, countries, key dates, contractual references). ESA/CSSF validations test completeness and cross‑table consistency. See the ITS 2024/2956.
  2. Governance of the critical chain. The “critical/important functions” and “sub‑outsourcing” fields turn the RoI into a map of operational dependencies, used by the CSSF and ESAs (including EU oversight of critical ICT providers). Expect targeted questions where the same sub‑contractor concentrates several critical functions. To structure this, consider our business continuity and DORA resilience service.
  3. A sustained annual cadence. The 2026 window set the tone: eDesk submission, automatic controls, then corrective exchanges as needed. Stabilize an annual process (data quality, domain ownership, xBRL‑CSV/CSV tooling, pre‑submission checks) and an organizational trigger to notify timely any project touching a critical/important function. CSSF ref.: RoI update. For local context, see DORA in Luxembourg (CSSF).

Concrete examples (Luxembourg)

  • HR SaaS contract with hosting sub‑outsourced to a non‑EU hyperscaler, supporting payroll (often “important”): keep the RoI up to date, notify in advance if payroll is important, and verify country/sub‑contractor/reversibility fields. Ref.: CSSF DORA page.
  • Core‑banking migration to a European provider with a long sub‑outsourcing chain: prepare full mapping of sub‑outsourcers and materiality documentation, then notify three months before signing if the function is “critical”. Ref.: CSSF guidance.

Frequent pitfalls

  1. Confusing a vendor register with the DORA RoI. A procurement list is not enough: it typically lacks function mapping, the critical/important flag, the sub‑outsourcing chain and required identifiers (e.g., LEI). Result: ESA/CSSF validation rejections. See the ITS 2024/2956.
  2. Forgetting the consolidation level. DORA requires an RoI at entity, sub‑consolidated and consolidated levels. CSSF guidance tables help determine the correct submission level; a wrong scope triggers inconsistencies and corrective requests. Ref.: CSSF guidance.
  3. Skipping prior notification of planned arrangements. The annual RoI does not replace the obligation to inform the supervisor in a timely manner before any agreement supporting a critical/important function (timelines set by 25/882). ESA Q&A confirms complementarity: Q&A 2025_7309.
  4. Underestimating sub‑outsourcing. Partial or poorly linked chains cause consistency errors. CSSF provides an interpretation and error‑resolution guide: CSSF guidance (PDF).
  5. Missing identifier and country fields. Validations frequently reject missing identifiers (LEI, country code) or formats not aligned with the taxonomy. Test exports against ESA rules before eDesk submission. Ref.: CSSF DORA page.

Official sources

  • CSSF — Register of information submission window — eDesk: notice
  • CSSF — Register of Information collection — Update (31.03.2026): update
  • EUR‑Lex — Implementing Regulation (EU) 2024/2956: text
  • CSSF — ICT and cyber risk – for DORA entities: reference page
  • CSSF — Guidance for interpretation and resolution of CSSF error messages (PDF): document
  • EBA/ESAs — DORA Q&A (e.g., 2025_7309): Q&A

In practice, anchor your setup on ITS 2024/2956 and CSSF guidance: a complete and correct RoI is both a regulatory must and a lever to master your ICT dependencies. In Luxembourg, the CSSF now scrutinizes data quality — and the operational “story” they tell. To reinforce governance and resilience, our outsourced CISO leadership can complement your program.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →