The classic trap
CSSF Circular 20/758 applies to credit institutions and investment firms, and its scope chapter opens the door to the proportionality principle. The trap: believing that "proportionality" means "exemption". The CSSF penalises institutions that invoke their small size to avoid documenting their IT security choices, without ever having formalised the analysis that justifies those choices. Proportionality is not a vested right, it is a demonstration you must produce and keep up to date.
The 'proportionality' test: what the CSSF actually expects
Invoking proportionality without a documented file is the leading cause of findings during a CSSF on-site inspection. To hold up, your reasoning must cover:
- The nature, scale and complexity of your activity, quantified rather than merely declared.
- Your real IT risk profile: number of critical systems, cloud dependency, external exposure.
- An article-by-article justification of the relaxed requirements, with the compensating control retained.
- Proof that the decision was validated by authorised management and reviewed periodically.
- Consistency with the EBA guidelines (notably EBA/GL/2019/04 on ICT risk management) referenced by the circular.
An institution that has never formalised this reasoning finds itself, during an inspection, unable to defend why a given requirement was not applied. The CSSF then reclassifies the gap as plain non-compliance.
How Luxgap automates this risk
Our Luxgap Proportionality Defender turns your proportionality argument into an opposable file that is built and maintained automatically. The tool maps your real IT risk profile by cross-referencing your Active Directory, Microsoft Defender, Azure Sentinel and your application inventory, then generates the article-by-article reasoning the CSSF expects, without your compliance officer having to draft a single memo by hand.
- Automatically calculates your IT risk profile (number of critical systems, external exposure, cloud dependencies) from data pulled by Defender and Sentinel.
- Maps each requirement of CSSF 20/758 and the EBA guidelines onto your scope, and flags those where a proportionality claim is defensible or, on the contrary, risky.
- Generates for each relaxed requirement the quantified justification and associated compensating control, ready for management sign-off.
- Alerts as soon as a scope change (new activity, new critical system, volume increase) makes a proportionality claim obsolete.
- Produces a timestamped, sealed PDF report, opposable during a CSSF on-site inspection, demonstrating that your choices are reasoned and periodically reviewed.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your exposure before any commitment.