Communiqué

Additional CSSF operational instructions on DORA major ICT-related incident reporting

The CSSF would like to draw the attention of financial entities to the publication of the European Supervisory Authorities’ (EBA, EIOPA, and ESMA) operational instructions regarding the reporting of major ICT-related incidents under Regulation (EU) 2022/2554 (DORA).

These instructions are intended to support competent authorities in their supervisory engagement, enhance data quality, and promote greater consistency across jurisdictions.

The CSSF expects financial entities to consider these practical instructions to facilitate the harmonised implementation of their incident reporting processes. The document detailing these operational instructions can be consulted through the following official channels:

In addition to the messages conveyed in the European Supervisory Authorities’ releases, the CSSF would like to highlight supplementary operational instructions to be taken into account to enhance the quality of information submitted in the DORA major ICT-related incident reports, improve the efficiency of the reporting process and reduce subsequent exchanges. Financial entities are expected to take due account of these practical instructions.