The classic trap
Article 1 of CSSF circular 24/847 sets out the definitions and the scope, and this is exactly where most supervised entities go wrong. The trap is not textual, it is about scope: many entities believe they fall under a single framework when 24/847 in fact articulates three regimes at once (the DORA regulation, the SRI Law transposing NIS, and CSSF regulation N 24-01). The CSSF sanctions entities that failed to correctly qualify their status from the start: a CSSF-regulated fintech that assumes it is outside DORA scope, or an entity still applying the logic of the now repealed circular 11/504, reporting under the wrong basis, within the wrong deadline, against the wrong threshold.
The qualification test: which framework do you really fall under?
Your entity qualification drives everything else: the classification threshold, the notification deadline and the receiving authority. Always verify:
- Are you a financial entity within the meaning of DORA art. 2? Then major ICT incidents fall under DORA art. 19 (initial notification within a very short deadline).
- Are you an operator of essential services (OES) or a digital service provider (DSP) under the SRI Law / NIS? The framework and deadlines differ.
- Do you fall under CSSF regulation N 24-01 for incidents outside DORA scope?
- Have you correctly applied circular 20/750 (ICT risk management) upstream, which conditions your ability to detect and classify?
- Have you purged any operational reference to the repealed circular 11/504 from your internal procedures?
A wrong initial qualification contaminates the entire notification chain: miscalibrated severity threshold, a major incident treated as significant, a breach of the DORA art. 19 deadline without even realising it.
How Luxgap automates this risk
Our Luxgap Regime Mapper makes qualification errors impossible by automatically determining under which framework (DORA, SRI Law, CSSF regulation N 24-01) each ICT incident of your entity must be reported, and within which deadline. The tool cross-references your CSSF prudential status, your ICT service mapping and your risk management references (circular 20/750) to produce an opposable qualification matrix, without requiring your CISO to interpret three regulations in parallel.
- Classifies your entity automatically against DORA art. 2, the SRI Law (OES/DSP) and CSSF regulation N 24-01, and flags cases of overlapping regimes.
- Detects obsolete references to the repealed circular 11/504 in internal procedures imported from SharePoint or Confluence and suggests the updated 24/847 wording.
- Computes in real time, for a given incident, the applicable classification threshold and the most stringent notification deadline (DORA art. 19 versus SRI Law).
- Generates a timestamped decision tree that documents, for each incident, the retained framework and its justification, opposable to the CSSF during an inspection.
- Alerts your teams via Teams or email as soon as a change in prudential status or a new ICT service modifies your notification scope.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your exposure before any commitment.