Circular CSSF 26/915
on the applicability of the Digital Operational Resililence Act (DORA) to third-country branches in Luxembourg
Related documents
-
28 May 2025 - Updated on 27 August 2026
Circular CSSF 25/893 (as amended by Circular CSSF 25/915)
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
-
28 May 2025 - Updated on 27 August 2026
Circular CSSF 25/892 (as amended by Circular CSSF 26/915)
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
-
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/883 (as amended by Circular CSSF 26/915)
amending Circular CSSF 22/806 on outsourcing arrangements
-
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/882 (as amended by Circular CSSF 26/915)
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
-
9 April 2025 - Updated on 27 August 2026
Circular CSSF 25/881 (as amended by Circular CSSF 26/915)
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
-
22 April 2022 - Updated on 27 August 2026
Circular CSSF 22/806 (as amended by Circulars CSSF 25/883 and CSSF 26/915)
on outsourcing arrangements
-
25 August 2020 - Updated on 27 August 2026
Circular CSSF 20/750 (as amended by Circulars CSSF 22/828, 25/881 and 26/915)
Requirements regarding information and communication technology (ICT) and security risk management