The classic trap
Article 1 of CSSF circular 25/882 sets out the scope and general principles: it determines who is subject to the DORA requirements on third-party ICT services, and under what conditions an entity may rely on a provider. The classic trap is assuming this circular only concerns large credit institutions. In reality, it applies to a broad range of financial entities supervised by the CSSF (investment firms, payment institutions, fund managers, regulated fintechs). In practice the CSSF sanctions entities that have failed to properly delimit their scope, or that outsource critical or important functions without applying the expected governance principles.
The scope delimitation test: what the CSSF checks first
Before even looking at your contracts, the CSSF assesses your ability to correctly qualify each third-party ICT service. The sensitive points:
- Identifying whether the entity falls within DORA scope and therefore within circular 25/882 (a support PSF is not treated like a universal bank).
- Distinguishing mere reliance on a third party for ICT operations from the outsourcing of a critical or important function under Articles 28 and following of DORA.
- Maintaining a complete and up-to-date register of contractual arrangements, a prerequisite for any supervision.
- Ensuring the safekeeping of accounting positions and data continuity, even if the provider fails.
- Documenting the full chain of ICT subcontractors, including sub-subcontractors located outside the EU.
The recurring mistake: an overly narrow scope qualification that wrongly excludes services that are in fact critical, and which collapses at the first on-site inspection.
How Luxgap automates this risk
Our Luxgap DORA Scope Mapper makes the scope blind spot impossible: it automatically builds a complete map of your third-party ICT services and qualifies each relationship against Articles 28 and following of DORA and CSSF circular 25/882. The tool cross-references your Odoo contracts, your Sage BOB 50 accounting flows, your Active Directory, your cloud spend (AWS, Azure, eBRC, LuxConnect) and Microsoft Defender to reconstruct the real outsourcing chain, without asking your compliance officer to fill in a single spreadsheet.
- Automatically detects each ICT provider as soon as a contract, payment or access appears in your connected systems.
- Classifies each service as a critical or important function using the DORA grid and flags under-rated qualifications before a CSSF inspection.
- Determines whether your entity falls within the scope of circular 25/882 and generates the supporting scope memo.
- Continuously monitors the safekeeping of accounting positions and alerts on any data continuity break at a provider.
- Maps the full chain of ICT subcontractors, including non-EU flows, and flags transparency breaks.
- Produces a time-stamped PDF report, enforceable before the CSSF during an inspection, demonstrating the consistency of your scope delimitation.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your perimeter. Request a tailored quote and our teams will prepare a demonstration on your real perimeter, with a free blank audit within 48h to measure your exposure before any commitment.