The classic trap
Article 2 of CSSF circular 25/892 activates the obligation under Article 11(10) of the DORA Regulation: upon CSSF request, the financial entity must provide an estimate of the aggregated annual costs and losses caused by major ICT-related incidents. The trap is not knowing the obligation, but meeting it in the exact prescribed format: the template in Annex I of the Guidelines (gross costs and losses, financial recoveries for the reference year). In practice, the CSSF penalises the inability to produce reliable, traceable data within deadline, because most entities never aggregate these costs continuously: they discover them on the day of the request, with figures rebuilt by hand and not defensible.
What the CSSF actually expects
- An aggregated annual estimate, not isolated incident-by-incident figures, covering all major ICT-related incidents of the reference year.
- A costing aligned with the Guidelines scope: gross costs (remediation, downtime, hardware replacement, internal resources) AND gross losses, distinguished from financial recoveries (insurance, indemnities, contractual clauses).
- Reporting via the exact Annex I template, without reinterpreting the line items.
- A documented methodology, consistent year over year, since the CSSF fully applies the Guidelines in its administrative practice to foster European supervisory convergence: any deviation is visible.
- The capacity to produce the data on request, meaning at any time, without a multi-week reconstruction project.
The real risk is non-traceability: an amount stated without an audit trail linking each euro to a classified major incident is indefensible during a review.
How Luxgap automates this risk
Our Luxgap Incident Cost Aggregator turns the annual cost and loss estimate into a living register, fed continuously, instead of a task rebuilt on the day of the CSSF request. The tool connects to your DORA incident register, your ITSM tools (ServiceNow, Jira Service Management), your accounting (Sage BOB 50, Odoo, SAP) and your insurance policies to automatically attach each cost to the major incident that generated it.
- Detects each incident classified as major under DORA and automatically opens an associated cost record, fed in real time.
- Aggregates gross costs (remediation, downtime, valued internal hours, hardware replacement) and gross losses while isolating financial recoveries, following the exact scope of Annex I of the Guidelines.
- Reconciles Sage BOB 50 or Odoo accounting entries with incidents to ensure every declared euro is tied to a verifiable audit trail.
- Generates the reporting template for gross costs, losses and recoveries of the reference year, pre-filled and ready to submit to the CSSF.
- Produces a timestamped, sealed PDF report, defensible during a CSSF review, demonstrating the methodology and multi-year consistency of the estimates.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real incidents, with a free blind audit within 48h to measure your exposure before any commitment.