Luxgap coverage GDPR NIS 2 DORA AI Act Whistleblowing CSSF 22/806 CSSF 25/883
Article M.0

Preamble, addressees and entry into force (9 April 2025)

CSSF Circular 25/883 amending CSSF 22/806 to align with DORA · CSSF 25/883

CSSF Circular 25/883 amends CSSF Circular 22/806 on outsourcing to align its requirements with Regulation (EU) 2022/2554 on digital operational resilience (DORA Regulation), applicable since 17 January 2025.

Addressees: credit institutions and PFS (LSF), payment and electronic money institutions (LSP), investment fund managers (CSSF 18/698), UCITS management companies (UCI Law), central counterparties (CCPs) including third-country CCPs of category 2 (EMIR), approved publication arrangements (APAs) and approved reporting mechanisms (ARMs) under derogation, market operators, central securities depositories (CSDs), administrators of critical benchmarks.

Entry into force: immediate, 9 April 2025. The circular shall be read together with CSSF 25/882 on requirements for using ICT third-party services for financial entities subject to DORA.

Purpose: avoid duplication between 22/806 and DORA, provide legal clarity to the market, reflect CSSF's commitment to effectively managing risks related to ICT third-party providers in the financial sector.

Luxembourg specificity
loi luxembourgeoise du 1er juillet 2024 portant mise en oeuvre du reglement (UE) 2022/2554 (DORA), combinee a la loi du 5 avril 1993 relative au secteur financier

In Luxembourg, the CSSF is the exclusive competent authority to enforce 25/883 and may conduct unannounced on-site inspections under the law of 5 April 1993 on the financial sector (articles 53 and 53-1). Failure to update the outsourcing framework after 9 April 2025 also exposes entities to DORA sanctions transposed by the law of 1 July 2024 implementing Regulation (EU) 2022/2554, which grants the CSSF administrative sanctioning powers of up to 1% of average daily worldwide turnover.

Luxgap practice: we recommend a 48-hour blind audit of supplier contracts to identify 25/883 + DORA gaps before the next CSSF RGS campaign, which systematically includes an ICT outsourcing section since 2025.