Preamble, addressees and entry into force (9 April 2025)
CSSF Circular 25/883 amending CSSF 22/806 to align with DORA · CSSF 25/883
CSSF Circular 25/883 amends CSSF Circular 22/806 on outsourcing to align its requirements with Regulation (EU) 2022/2554 on digital operational resilience (DORA Regulation), applicable since 17 January 2025.
Addressees: credit institutions and PFS (LSF), payment and electronic money institutions (LSP), investment fund managers (CSSF 18/698), UCITS management companies (UCI Law), central counterparties (CCPs) including third-country CCPs of category 2 (EMIR), approved publication arrangements (APAs) and approved reporting mechanisms (ARMs) under derogation, market operators, central securities depositories (CSDs), administrators of critical benchmarks.
Entry into force: immediate, 9 April 2025. The circular shall be read together with CSSF 25/882 on requirements for using ICT third-party services for financial entities subject to DORA.
Purpose: avoid duplication between 22/806 and DORA, provide legal clarity to the market, reflect CSSF's commitment to effectively managing risks related to ICT third-party providers in the financial sector.