DORA for Third-Country Branches in Luxembourg: Circular CSSF 26/915
On 27 August 2026 the CSSF issued Circular CSSF 26/915, applicable with immediate effect, to bring specified third-country branches into the CSSF circular framework for DORA. For Luxembourg purposes, the governing scope is the branch perimeter set out in Circular CSSF 26/915 and in each amended circular; the change is not a blanket head-office-only test for every non-EU branch.
The CSSF communiqué states that on 17 December 2025 the European Commission confirmed, via DORA Q&A 3097, the application of DORA to third-country branches and summarises the head-office condition by reference to Article 2(1), points (a) to (t). The underlying Q&A itself is framed around Article 2(1), points (a), (n) and (o), and Circular CSSF 26/915 gives effect to the CSSF’s stance for the CSSF-supervised branch categories specified in the Circular.
The mechanics are a partial relocation. Circular CSSF 26/915 removes qualifying third-country branches from Circular CSSF 20/750 in full and from Circular CSSF 22/806 only for ICT outsourcing under Part II; Part I remains applicable to outsourcing arrangements other than ICT outsourcing. It also adds the relevant third-country branches to Circulars CSSF 25/882, 25/892 and 25/893, subject to each circular’s own scope.
Related reading: DORA ICT Incident Reporting
The dates that frame the change
DORA applies from 17 January 2025, and the ESAs stated that DORA provides no transitional period. The CSSF says that the Commission confirmed the third-country-branch position on 17 December 2025 through Q&A 3097; the Q&A itself states that it clarifies existing legislation rather than creating new rights or obligations. Circular CSSF 26/915 applies with immediate effect from 27 August 2026 and amends the CSSF circular framework for the third-country branches within its scope.
The test that decides whether a branch is in DORA scope
Circular CSSF 26/915 Chapter 1 identifies in-scope third-country branches as branches of undertakings within the CSSF categories listed in points (a) to (j), with a head office that would qualify within the relevant DORA categories in Article 2(1), points (a) to (i), (k) to (m), (p), (r) and (s). Chapter 2 likewise treats third-country branches within those categories, and within Article 2(2), as financial entities subject to DORA for the purposes of the Circular and the circulars it amends.
The head-office classification therefore matters, but it is not the only Luxembourg-scope test. The branch must also fall within the CSSF-supervised third-country-branch categories specified by Circular CSSF 26/915. The CSSF communiqué uses an Article 2(1), points (a) to (t), head-office formulation, while the operative Circular defines the Luxembourg perimeter more specifically; the two should not be collapsed into a blanket head-office-only test.
Which circulars change, and in which direction
Circular CSSF 20/750 is removed in full for the relevant branches. Circular CSSF 22/806 remains applicable under Part I for outsourcing arrangements other than ICT outsourcing, while Part II on ICT outsourcing is removed. Circular CSSF 25/882 covers ICT third-party services; Circular CSSF 25/892 applies the Joint ESA Guidelines on aggregated annual costs and losses caused by major ICT-related incidents and excludes microenterprises as defined in DORA Article 3(60); and Circular CSSF 25/893 covers major ICT-related incident reporting and significant cyber threats.
To keep the framework internally consistent, the CSSF also amended the two amending circulars that had originally modified the pre-DORA texts when DORA entered into application: Circular CSSF 25/881, which amends Circular CSSF 20/750, and Circular CSSF 25/883, which amends Circular CSSF 22/806.
General ICT risk-management obligations for DORA entities arise under DORA and its applicable technical standards. Circular CSSF 25/882 provides CSSF requirements and practical instructions for ICT third-party services; Circular CSSF 25/892 concerns aggregated annual costs and losses caused by major ICT-related incidents where it applies; Circular CSSF 25/893 sets the CSSF incident and cyber-threat reporting modalities; and Circular CSSF 22/806 Part I remains relevant for outsourcing arrangements other than ICT outsourcing. The DORA register of information should therefore be mapped to the DORA framework for ICT third-party contractual arrangements, while the non-ICT outsourcing framework under Circular CSSF 22/806 Part I remains in place.
The incident-reporting precision for a blocked channel
Alongside the scope change, the CSSF added a precision on reporting major ICT-related incidents and significant cyber threats where an entity cannot use the prescribed communication channel. This sits on top of the DORA obligation itself. Under Article 19 of DORA, financial entities report a major ICT-related incident to the relevant competent authority through an initial notification, an intermediate report and a final report, and may notify significant cyber threats on a voluntary basis.
Article 19 anticipates technical impossibility for the initial notification. For Luxembourg filings, Circular CSSF 25/893 point 8 specifies submission through the CSSF eDesk procedure ‘DORA Major ICT-related Incident Notification’ or the CSSF API interface (S3). Point 9, as amended by Circular CSSF 26/915, provides that where technical impossibility prevents submission using the indicated channel, the entity must inform the CSSF by e-mail at ictrisksupervision@cssf.lu, without undue delay and no later than the applicable deadline for the notification or report, and explain why the alternative channel was used.
Where this sits next to the CRD VI branch regime
The DORA scope change is separate from Luxembourg’s prudential regime for third-country branches of credit institutions. Luxembourg has already transposed the main CRD VI package through the Law of 5 May 2026, published on 6 May 2026. The Law introduces the harmonised third-country-branch prudential framework, but the provisions concerning third-country branches and the third-country regime for banking services are subject to a transitional period and apply from 11 January 2027. The remaining CRD VI aspect concerning the independence of competent authorities is being transposed separately under draft law no 8705.
For DORA questions, the CSSF communiqué gives ictrisksupervision@cssf.lu as the general contact and banking_ict_risk@cssf.lu for third-country branches of credit institutions. The communiqué does not state that the two addresses correspond to different supervisory teams.
Frequently Asked Questions
Our head office is a non-EU asset manager that would not be a DORA financial entity. Is our Luxembourg branch caught?
If the head office would not qualify within the DORA categories relevant to Circular CSSF 26/915, the branch is outside the Circular’s third-country-branch scope on the stated assumption. However, the assessment is not a head-office-only exercise: the Luxembourg branch must also fall within the CSSF-supervised third-country-branch categories specified by Circular CSSF 26/915.
Does removal from Circular CSSF 20/750 mean our branch no longer has ICT risk obligations?
No. For a qualifying DORA third-country branch, Circular CSSF 20/750 is removed in full, but general ICT risk-management obligations apply under DORA and its applicable technical standards. Circular CSSF 25/882 addresses ICT third-party services, Circular CSSF 25/893 addresses incident and cyber-threat reporting, and Circular CSSF 25/892 concerns aggregated annual costs and losses from major ICT-related incidents where that circular applies. Circular CSSF 22/806 Part I continues to apply to outsourcing arrangements other than ICT outsourcing.
If we cannot submit an incident notification through the prescribed channel, can we wait until it is restored?
No. Circular CSSF 25/893 point 8 provides for submission through the CSSF eDesk procedure or the API interface (S3). Where technical impossibility prevents submission using the indicated channel, point 9 requires notification to ictrisksupervision@cssf.lu without undue delay and no later than the applicable notification or report deadline, together with the reason for using the alternative channel.
Which CSSF contact handles DORA questions for a credit-institution branch?
The CSSF communiqué gives ictrisksupervision@cssf.lu as the general contact and banking_ict_risk@cssf.lu for third-country branches of credit institutions.
Related Articles
- DORA ICT Incident Reporting: how the initial notification, intermediate and final report stages work under DORA.
- DORA Register of Information: what goes into the register of ICT third-party contractual arrangements and when it is due.
- CRD VI Luxembourg Transposition Law 2026: the separate authorisation and supervision regime for third-country branches of credit institutions.
- EBA Third-Country Branch Reporting: how third-country branch reporting fits the wider EBA framework.
- DORA Resilience Testing for Smaller Firms: how proportionality shapes DORA testing obligations.
Key Takeaways
- Circular CSSF 26/915 applies with immediate effect from 27 August 2026 and brings specified CSSF-supervised third-country branches into the DORA circular framework. Assess both the CSSF branch perimeter in Circular CSSF 26/915 and the relevant head-office classification; do not use Article 2(1)(a) to (t) as a standalone head-office-only scope test.
- Map general ICT risk-management controls to DORA and its applicable technical standards, ICT third-party controls to Circular CSSF 25/882, aggregated major-incident cost-and-loss processes to Circular CSSF 25/892 where in scope, and incident/cyber-threat reporting to Circular CSSF 25/893. Circular CSSF 20/750 is removed for qualifying DORA third-country branches, but Circular CSSF 22/806 Part I remains applicable to non-ICT outsourcing; Part II does not.
- Document the Circular CSSF 25/893 point 9 fallback before an incident occurs: where technical impossibility prevents use of the indicated submission channel, notify ictrisksupervision@cssf.lu without undue delay and no later than the applicable deadline, and explain the reason for using the alternative channel.
- Luxembourg has transposed the main CRD VI package through the Law of 5 May 2026; the new third-country-branch provisions apply from 11 January 2027. The DORA workstream remains separate, and the CSSF gives banking_ict_risk@cssf.lu for DORA questions concerning third-country branches of credit institutions.
Sources and References
- CSSF, Communique, “Application of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg”, 27 August 2026: cssf.lu
- Regulation (EU) 2022/2554 (DORA), Official Journal L 333, 27 December 2022, including Article 2 (scope) and Article 19 (reporting of major ICT-related incidents and voluntary notification of significant cyber threats): eur-lex.europa.eu
- Joint ESAs statement on DORA application (JC 2024 99), 4 December 2024, confirming the 17 January 2025 application date and the absence of a transitional period: esma.europa.eu
- European Commission answer to DORA Q&A DORA102-3097, hosted by EIOPA, concerning Article 2(1)(a), (n) and (o); Circular CSSF 26/915 of 27 August 2026 on the applicability of DORA to third-country branches in Luxembourg (PDF accessible from the CSSF communiqué above); and CSSF communiqué on the Law of 5 May 2026 transposing CRD VI.
Remapping a Luxembourg branch to the DORA circulars
For a qualifying third-country branch, reconcile general ICT risk-management controls to DORA and its applicable technical standards, ICT third-party controls to Circular CSSF 25/882, aggregated major-incident cost-and-loss processes to Circular CSSF 25/892 where in scope, and incident-reporting controls to Circular CSSF 25/893. Remove Circular CSSF 20/750 from the DORA third-country-branch mapping, retain Circular CSSF 22/806 Part I for outsourcing arrangements other than ICT outsourcing, and document the Circular CSSF 25/893 point 9 e-mail fallback for technical submission failures.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
