The classic trap
A date-of-application article looks harmless, but that is exactly where financial entities get caught. The CSSF rarely sanctions the substance of a circular in its first months, it sanctions the absence of an operational framework on 31 May 2025, the effective date. Under DORA, estimating the aggregated annual costs and losses caused by major ICT-related incidents (Article 11(11)) becomes a reportable obligation, and the regulator expects a documented methodology from the first relevant reporting period, not a promise of future compliance.
What the date of application actually triggers
The 31 May 2025 date is not a mere calendar formality. It sets the point from which your entity, as a CSSF-regulated fintech, a Luxembourg private bank or a support PSF, must be able to produce the expected deliverables. In practice, by that date, the authorities expect you to have:
- A cost and loss estimation methodology aligned with the JC/GL/2024/34 guidelines, documented and approved by authorised management.
- A major ICT incident register fed continuously, with direct and indirect cost categories broken down.
- An audit trail demonstrating that the framework was operational from the day of application, not reconstructed after the fact.
- The scope adjustment introduced by circular CSSF 26/915 taken into account.
The trap: believing that a circular applicable on 31 May 2025 grants a grace period. It grants none. A missing methodology on the date of application is an immediately observable non-compliance.
How Luxgap automates this risk
Our Luxgap DORA Loss Estimator turns the estimation of aggregated ICT incident costs and losses into a timestamped deliverable, enforceable before the CSSF from the date of application. The tool connects to your incident register (ServiceNow, Jira Service Management, Azure Sentinel, Microsoft Defender) and to your accounting systems (Sage BOB 50, SAP, Odoo) to automatically reconstruct the direct and indirect cost chain of each major incident, without your risk team filling in a single spreadsheet.
- Detects each incident classified as major in your ticketing tools and triggers the collection of associated cost items following the JC/GL/2024/34 grid.
- Calculates the annual aggregate of costs and losses, breaking down remediation, downtime, revenue loss and estimated reputational costs.
- Generates the estimation report aligned with the ESAs guidelines, prefilled and ready to submit to the CSSF.
- Alerts your CISO via Teams as soon as an incident crosses the DORA materiality threshold and affects the annual aggregate.
- Produces a cryptographically sealed audit trail proving the methodology was operational on 31 May 2025, enforceable during an inspection.
- Automatically integrates the scope adjustments introduced by circular CSSF 26/915.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real incidents, with a free blank audit within 48h to measure your exposure before any engagement.