Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
As of 17 January 2025, the provisions of the Digital Operational Resilience Act1 (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. On 17 December 2025, the European Commission confirmed, via an official DORA Q&A2, that DORA is also applicable to third-country branches (“TCBs”) in an EU country, if in the third country where their head office is established, they would qualify as entities listed under Article 2(1)(a) to (t) of DORA.
Consequently, an update of a series of circulars published or modified in 2025 is required to include TCBs in the DORA scope.
Furthermore, the CSSF included in the frame of this update a precision regarding the reporting of major ICT-related incidents and cyber threats in case entities cannot use the prescribed communication channel.
The modifications are visualised in purple in the below graphic:

The following modifications have been made to the enumerated circulars:
- Removal of TCBs from the scope of the following circulars (or part thereof):
-
25 August 2020 - Updated on 27 August 2026
Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915)
Requirements regarding information and communication technology (ICT) and security risk management Contact: Questions and comments regarding the “PSP ICT Assessment” form: pspictassessment@cssf.luCSSF circular -
22 April 2022 - Updated on 27 August 2026
Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915)
on outsourcing arrangements Link to the communiqué of 1 July 2022CSSF circular
- Inclusion of TCBs in the scope of the following circulars applicable to DORA entities:
-
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/882 (as amended by Circular CSSF 26/915)
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)CSSF circular -
28 May 2025 - Updated on 27 August 2026
Circular CSSF 25/892 (as amended by Circular CSSF 26/915)
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)CSSF circular -
28 May 2025 - Updated on 27 August 2026
Circular CSSF 25/893 (as amended by Circular CSSF 25/915)
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)CSSF circular
- To avoid inconsistencies and align with the above changes, modification of the two “amending circulars” which were used to modify the “pre-DORA CSSF circulars” when DORA entered into application:
-
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/881 (as amended by Circular CSSF 26/915)
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk managementCSSF circular -
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/883 (as amended by Circular CSSF 26/915)
amending Circular CSSF 22/806 on outsourcing arrangementsCSSF circular
For any further questions please contact ictrisksupervision@cssf.lu or, in case of third-country branches of credit intuitions banking_ict_risk@cssf.lu.
1 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011
2 Refer to DORA Q&A 102: DORA102 – 3097 – European Insurance and Occupational Pensions Authority
New Circular CSSF 26/915
-
27 August 2026
Circular CSSF 26/915
on the applicability of the Digital Operational Resililence Act (DORA) to third-country branches in LuxembourgCSSF circular