The classic trap
Amendment 1 creates an entity qualification trap that the CSSF sanctions in practice during ISPL reviews and supervisory questionnaires. Many supervised entities still apply Circular CSSF 20/750 in full even though they have become financial entities within the meaning of Article 2 of DORA, while conversely entities outside DORA relax their vigilance believing DORA applies to them. The result: an ICT risk management framework that is miscalibrated, neither fully DORA nor fully 20/750, which the CSSF reclassifies as a failure of ICT governance. The blind spot is the moving boundary: a modified authorisation, a new regulated service, a change of status, and the entity shifts from one regime to the other without noticing.
The scope test: are you DORA, 20/750, or both?
The key argument before the CSSF rests on a precise, dated qualification of your status. Check each of these points:
- Are you a financial entity listed in Article 2 of DORA (credit institution, PSF, PSD, EMI, investment firm, fund manager, crypto-asset service provider, etc.) AND supervised by the CSSF? If so, Circular 20/750 no longer applies to you.
- Do you fall under the historical scope of 20/750 WITHOUT falling under DORA (for example certain support entities or specific statuses)? If so, Circular 20/750 continues to apply in full, including the EBA guidelines on ICT risk management.
- Have you documented the exact switch date and the DORA article grounding your qualification?
- Do your internal ICT policies still cite 20/750 even though you have moved under DORA (proportionality, ICT third-party register, resilience testing, incident notification)?
- Does your application mapping distinguish residual 20/750 requirements from the new DORA obligations (RTS/ITS)?
The CSSF expects an explicit mapping: which framework applies to which group entity, with proof of qualification. The absence of this mapping is in itself a signal of deficient ICT governance.
How Luxgap automates this risk
Our Luxgap Scope Boundary Mapper makes the scoping error impossible by automatically determining, entity by entity, whether you fall under DORA, CSSF 20/750, or both. The tool queries your CSSF authorisation status, your register of regulated activities and your legal entities (cross-referencing your ERP, your M365 directory and your governance data) to lock in a dated, defensible qualification, without the CISO having to fill in a single table.
- Classifies each group entity against Article 2 of DORA and the historical scope of CSSF 20/750, with the exact legal reference that grounds the qualification.
- Detects in real time any change of authorisation, new regulated service or status modification that could shift an entity from one regime to the other, and alerts the compliance officer via Teams.
- Generates the per-entity framework mapping: which residual 20/750 requirements, which DORA obligations (ICT risk management RTS/ITS, third-party register, resilience testing, incident notification) apply.
- Scans your internal ICT policies and flags obsolete references to CSSF 20/750 in entities now under DORA, or the reverse.
- Produces a timestamped and sealed PDF report, defensible before the CSSF during an inspection, demonstrating that your ICT risk management framework is calibrated on the correct framework.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS brick depending on your perimeter. Request a personalised quote and our teams will prepare a demonstration on your real structure, with a free blind audit within 48h to measure your exposure before any commitment.