CSSF 22/806, outsourcing and cloud for Luxembourg financial entities.
The CSSF Circular 22/806 (amended by CSSF 25/883) consolidates into a single framework the requirements for outsourcing by Luxembourg supervised entities: governance, contracts, monitoring of sub-providers, exit plans, and cloud-specific requirements. Since 17 January 2025, it articulates with the DORA Régulation (EU 2022/2554).
Circular contents
All 31 sections, in the order of the official text. Each one is analysed separately, with the official text and Luxgap practical guidance.
- I.1. Chapitre 1 - Définitions, abréviations et acronymes
- I.2. Chapitre 2 - Champ d’application et proportionnalité
- I.3.1. Sous-chapitre 3.1 - Principes généraux régissant les dispositifs
- I.3.2. Sous-chapitre 3.2 - Externalisation intragroupe
- I.4.1.1. Section 4.1.1 - Externalisation
- I.4.1.2. Section 4.1.2 - Fonctions critiques ou importantes
- I.4.1.3. Section 4.1.3 - Dispositifs d’externalisation relatifs aux fonctions de
- I.4.1.4. Section 4.1.4 - Dispositifs d’externalisation relatifs à la fonction
- I.4.2.1. Section 4.2.1 - Dispositifs de bonne gouvernance et risque de tiers
- I.4.2.2. Section 4.2.2 - Dispositifs de gouvernance sains pour l’externalisation
- I.4.2.3. Section 4.2.3 - Politique d’externalisation
- I.4.2.4. Section 4.2.4 - Conflits d’intérêts
- I.4.2.5. Section 4.2.5 - Plans de poursuite de l’activité
- I.4.2.6. Section 4.2.6 - Fonction d’audit interne
- I.4.2.7. Section 4.2.7 - Exigences en matière de documentation
- I.4.2.8. Section 4.2.8 - Conditions de surveillance de l’externalisation
- I.4.3.1. Section 4.3.1 - Analyse préalable à l’externalisation
- I.4.3.2. Section 4.3.2 - Phase contractuelle
- I.4.3.3. Section 4.3.3 - Contrôle des fonctions externalisées
- I.4.3.4. Section 4.3.4 - Plans de sortie
- II. Partie II - Exigences relatives aux dispositifs
- II.1. Chapitre 1 - Dispositifs d’externalisation en matière de TIC
- II.1.1. Sous-chapitre 1.1 - Exigences applicables aux Entités
- II.1.2. Sous-chapitre 1.2 - Exigences applicables aux PSF de support
- II.2. Chapitre 2 - Dispositifs d’externalisation en matière de TIC
- II.2.1.1. Section 2.1.1 - Terminologie spécifique
- II.2.1.2. Section 2.1.2 - Définition de « cloud computing »
- II.2.1.3. Section 2.1.3 - Conditions d’application du chapitre
- II.2.2. Sous-chapitre 2.2 - Les exigences à respecter pour une
Who is concerned?
All CSSF-supervised entities that outsource a function or service: crédit institutions, investment firms, payment and electronic money institutions (LSF and LSP), management companies under article 125-1 of the UCITS law, and support PFS (financial-sector ICT providers under articles 29-3, 29-5 and 29-6 of the LSF).
The circular goes beyond the EBA scope: the CSSF chose to extend convergence to all Luxembourg financial entities to align national practice.
Key obligations
- Map all outsourcing arrangements, identify those covering critical or important functions.
- Outsourcing policy approved by the management body, reviewed at least annually, covering provider selection, risk management, monitoring and exit.
- Contractual phase with minimum clauses: SLAs, audits, sub-outsourcing chain, confidentiality, data return, applicable law, jurisdiction.
- Continuous monitoring of the provider: performance indicators, incidents, access control, regulatory compliance, certifications.
- Exit plans tested and documented for every critical outsourced function, with scénarios for in-housing and switching to another provider.
- Specific cloud requirements: data location, encryption, audit rights, multi-tenant constraints, CSSF notification before deploying a new cloud solution on a critical function.
- CSSF notification mandatory for any material outsourcing or cloud on a critical function, before go-live.
Deadlines
The 22/806 circular has been in force since 30 June 2022 (initial date of application) and was amended by CSSF 25/883 to align with DORA. Since 17 January 2025, in-scope financial entities apply DORA as primary régulation; CSSF 22/806 remains applicable as a complement for national specifics (notification, support PFS, Luxembourg intragroup arrangements).
Sanctions for non-compliance
The CSSF wields the full toolkit of Luxembourg financial law: compliance orders, administrative sanctions, restrictions or suspension of authorisation, pecuniary sanctions, up to withdrawal of authorisation for serious breaches. Sanctions are aligned with the law of 5 April 1993 on the financial sector.
Beyond formal sanctions, a 22/806 breach at a CSSF inspection can block a project (cloud deployment refused, outsourcing frozen) or compromise a prior authorisation (new service, new activity, M&A).
How Luxgap helps
We support CSSF entities, PFS and funds on the full outsourcing lifecycle:
- Audit of your current setup: mapping, gap analysis versus 22/806 and DORA.
- Drafting of the outsourcing policy, standard contract clauses, testable exit-plan templates.
- Setting up the outsourcing register (criticality, certifications, exit horizon).
- Preparing CSSF notifications for critical functions and cloud, managing the dialogue with your CSSF relationship manager.
- Annual testing of exit plans under real conditions, documented and enforceable.
- Articulation with DORA: ICT provider register, ICT incident management, digital operational résilience testing (TLPT).
Let's discuss your situation.
This topic is handled case by case. Get in touch to discuss it: reply within one business day, no commitment.
Contact us →