CSSF 26/906 · Summary
← Law overview
Partie I - Définitions et champ d’application
Partie I - Définitions et champ d’application
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie III - Entrée en vigueur
Article II.5.3.2
Section 5.3.2 - La fonction informatique
CSSF Circular 26/906 — Central administration, internal governance and risk management · CSSF 26/906
Section 5.3.2. La fonction informatique 98. Les établissements organisent leur fonction informatique de manière à en avoir le contrôle et à en assurer la robustesse, l’efficacité, la cohérence et l’intégrité. Pour ce faire, ils respectent les exigences du règlement (UE) 2022/2554 sur la résilience opérationnelle numérique du secteur financier et des circulaires CSSF relatives aux exigences en matière de gestion des risques liés aux TIC et à la sécurité. Ils maintiennent également à jour les informations et documents tels que demandés dans la circulaire CSSF 18/677 relative aux Orientations de l’Autorité bancaire européenne sur les informations à fournir dans le cadre de l’agrément d’établissements de paiement et d’établissements de monnaie électronique et pour l’enregistrement de prestataires de services d’information sur les comptes au titre de l’article 5, paragraphe 5, de la directive (UE) 2015/2366 (EBA/GL/2017/09).
99. Les établissements qui, en matière de fonction informatique, recourent aux services de prestataires de services doivent se référer à la circulaire CSSF 22/806 concernant l’externalisation.
Luxgap guidance · DPO & CISO
How to comply
The classic trap For the CSSF, the IT function is not a mere technical matter: it is a pillar of central administration. The classic trap is to assume that a signed DORA contract with a cloud provider is enough, when the CSSF actually sanctions the absence of effective control over the IT function. In practice, the institution must demonstrate that it masters its application mapping, its ICT dependencies and the consistency between CSSF circular 22/806 (outsourcing), Regulation (EU) 2022/2554 (DORA) and CSSF circular 18/677. An IT function that looks robust on paper but is neither documented nor tested is the most frequently raised finding during on-site inspections.
The 4 pillars the CSSF checks on your IT function Control : clear governance, assigned responsibilities, reporting line to authorised management, with no grey zone with external providers.Robustness : DORA compliance on ICT risk management, digital operational resilience testing and proven continuity plans.Consistency : documentary alignment between the 22/806 outsourcing register, the DORA register of information and the elements required by circular 18/677 (EBA/GL/2017/09) for payment and electronic money institutions.Integrity : change traceability, access management and security aligned with CSSF circulars on ICT risks.The most common breaking point: the 22/806 outsourcing register and the DORA register of information do not talk to each other, describe the same providers with different scopes, and expose the institution to a contradiction that can be held against it during an inspection.
How Luxgap automates this risk Our Luxgap ICT Function Cartographer makes inconsistency between your DORA, 22/806 and 18/677 obligations impossible by automatically rebuilding the real map of your IT function. The tool continuously queries your Microsoft Defender, Azure Sentinel, Active Directory, eBRC, LuxConnect environments and your Odoo contracts to materialise every ICT dependency, without asking the IT function to fill in a single spreadsheet.
Automatically detects every active ICT provider through your billing flows, Active Directory access and cloud consumption, then reconciles it with the 22/806 outsourcing register. Reconciles the DORA register of information and the 22/806 register in real time, and alerts via Teams as soon as a provider appears in one but not the other. Classifies each ICT function as critical or important according to the DORA grid and flags missing or expired resilience tests. Generates the authorisation file compliant with circular 18/677 (EBA/GL/2017/09), pre-filled for payment and electronic money institutions. Produces a timestamped and sealed PDF report, admissible before the CSSF during an on-site inspection, demonstrating the control, robustness, consistency and integrity of your IT function. Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.
Need help with this article?
Our team (lawyers + cyber engineers) gives you the concrete stuff. Reply within 24 business hours.
📄 Request a template
🤝 Help getting compliant
🔎 Request a review