The CSSF (Commission de Surveillance du Secteur Financier), Luxembourg’s financial regulator, has clarified that the Digital Operational Resilience Act (DORA) now applies to third-country branches operating in the Grand Duchy as of January 17, 2025. Following confirmation from the European Commission on December 17, 2025, the CSSF determined that foreign branches qualify for DORA compliance if their parent entities would be classified as financial entities under DORA’s Article 2(1)(a) to (t) provisions.

  • DORA Implementation Date: January 17, 2025
  • European Commission Confirmation: December 17, 2025
  • Key Regulatory Update: Circular CSSF 26/915 (August 27, 2026)
  • Affected Circulars: Six revised guidance documents covering ICT services, incident reporting, and outsourcing

To eliminate regulatory inconsistencies, the CSSF has updated six circulars governing financial supervision. Third-country branches have been removed from the scope of Circular CSSF 20/750 on ICT and security risk management and Circular CSSF 22/806 on outsourcing arrangements. Conversely, TCBs are now included in three DORA-specific circulars: requirements for ICT third-party services (CSSF 25/882), estimation of aggregated annual costs from major incidents (CSSF 25/892), and reporting of major ICT-related incidents and cyber threats (CSSF 25/893).

The regulatory update also addresses a practical gap identified by the CSSF. Financial entities may now use alternative communication channels to report major ICT-related incidents and significant cyber threats if prescribed methods are unavailable. Two amending circulars, CSSF 25/881 and CSSF 25/883, were modified to reflect these structural changes and prevent overlapping compliance obligations between legacy and DORA-era requirements.

The CSSF has designated two contact channels for clarification: ictrisksupervision@cssf.lu for general inquiries and banking_ict_risk@cssf.lu for third-country branches of credit institutions. The regulatory framework aims to establish uniform digital operational resilience standards across Luxembourg’s financial sector, regardless of whether entities are domestically established or branch operations of foreign firms.

By Gavriel Gavrielides

Gavriel Gavrielides is the Founder and Chief Editor of fintech-intelligence. An ACA-qualified finance executive, he previously served as Group CFO and Global Head of Accounting & Finance for a major international Forex broker with over 800 employees, following a foundational career as an auditor at a Big Four firm. Having spent over 15 years navigating complex international regulatory frameworks, scaling financial infrastructure, and managing global corporate strategies, Gavriel launched fintech-intelligence because he recognized that the traditional boundaries between finance and technology have completely dissolved. He saw a critical need for an industry publication driven by actual operational expertise rather than outside commentary. Today, Gavriel leverages his deep institutional background to cut through the market noise, delivering high-signal, deeply analytical insights into the technologies, regulations, and innovations reshaping the future of money. Connect with Gavriel on https://www.linkedin.com/in/gavriel-gavrielides-103734124/