CSSF 26/906 · Summary
← Law overview
Partie I - Définitions et champ d’application
Partie I - Définitions et champ d’application
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie II - Dispositif en matière d’administration centrale, de
Partie III - Entrée en vigueur
Luxgap guidance · DPO & CISO
How to comply
The classic trap Article II.5.3 is a proportionality trap: the CSSF does not settle for a server inventory, it sanctions the mismatch between your actual technical resources and the complexity of your activities. The most overlooked point is the last sentence: the institution must minimise manual tasks that generate errors. During an inspection, a critical process run on Excel with copy-paste between systems is systematically flagged as a technical infrastructure deficiency, even if no incident has yet occurred.
The 'necessary, sufficient and appropriate' test: what the CSSF checks The CSSF applies a three-step grid to your material and technical resources. Each term is a distinct gateway to sanction.
Necessary : each activity and each associated risk must have a dedicated technical resource, mapped and documented.Sufficient : capacity (storage, redundancy, licences, support staff) must absorb peaks and growth without degradation.Appropriate : the tool must match the actual nature, scale and complexity, neither under-sized nor a disproportionate gadget.Minimisation of manual tasks : any critical process relying on manual entry or transfer must be identified, traced and covered by an automation plan or compensating control.Support and control functions : they must have effective, tooled access to data, not a mere theoretical right.How Luxgap automates this risk Our Luxgap Manual Task Radar makes the blind spot of Article II.5.3's last sentence impossible: it detects, maps and scores every risky manual task in your real processes, before the CSSF finds it. The agent cross-references your M365 flows (Excel, Power Automate, SharePoint), your Sage BOB 50 exports, your Odoo connectors and your Azure Sentinel logs to reconstruct the effective operational chain, without asking your teams to describe their procedures.
Automatically detects critical processes run outside systems (shared Excel workbooks, cross-application copy-paste, manual email sends) through analysis of M365 and SharePoint metadata. Calculates an operational risk score per process by cross-referencing volume, frequency and absence of four-eyes control, aligned with the CSSF nature/scale/complexity grid. Classifies each technical resource against the necessary, sufficient and appropriate test and flags under-sized capacity or missing redundancy. Alerts in real time on Teams whenever a new critical manual flow appears or a Power Automate automation fails. Produces a timestamped, sealed PDF report, enforceable before the CSSF during an inspection, demonstrating the adequacy of the administrative and technical infrastructure. Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams prepare a demonstration on your real processes, with a free blind audit within 48h to measure your exposure before any commitment.
Need help with this article?
Our team (lawyers + cyber engineers) gives you the concrete stuff. Reply within 24 business hours.
📄 Request a template
🤝 Help getting compliant
🔎 Request a review