Repealed circular on 1 April 2024. It is no longer in force and has been replaced by CSSF 24/847. This page is kept for historical reference.
CSSF Circular 11/504 (repealed) on frauds and incidents due to external IT attacks.
REPEALED on 1 April 2024 and replaced by CSSF Circular 24/847. Kept for reference: former obligation to report frauds and IT attacks.
Who is concerned?
This circular is broken down into 2 sections analysed one by one, each with the official text and Luxgap practical guidance for compliance in Luxembourg.Key obligations
REPEALED on 1 April 2024 and replaced by CSSF Circular 24/847. Kept for reference: former obligation to report frauds and IT attacks.
Luxgap supports CSSF-supervised entities (banks, PFS, payment and e-money institutions, management companies, funds) in complying with this circular: gap analysis, policy and register updates, CSSF inspection readiness, articulation with the DORA Regulation and the NIS 2 framework where relevant.
Deadlines
See the official CSSF text for precise application dates. Most recent ICT circulars articulate with the DORA Regulation, applicable since 17 January 2025.
Sanctions for non-compliance
Non-compliance exposes entities to CSSF administrative sanctions: injunctions, pecuniary sanctions, restrictions or suspension of authorisation.
How Luxgap helps
REPEALED on 1 April 2024 and replaced by CSSF Circular 24/847. Kept for reference: former obligation to report frauds and IT attacks.
Luxgap supports CSSF-supervised entities (banks, PFS, payment and e-money institutions, management companies, funds) in complying with this circular: gap analysis, policy and register updates, CSSF inspection readiness, articulation with the DORA Regulation and the NIS 2 framework where relevant.
Let's discuss your situation.
This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.
Contact us →