CSSF Insider List Templates: Fields Dropped Under ITS 2026/1291
The CSSF publishes two templates for insider lists under Article 18 of the Market Abuse Regulation (MAR): the general “Template for insider lists and updating insider lists” and the template for issuers of financial instruments admitted to trading on SME growth markets. The legal format behind the CSSF insider list templates is set by Commission Implementing Regulation (EU) 2026/1291, which the Commission adopted on 12 June 2026 and which has been in force since 5 July 2026, repealing Implementing Regulation (EU) 2022/1210.
Article 18(1)(c) MAR requires an insider list to reach the competent authority as soon as possible once it is asked for, and a list still kept in the 2022 layout carries personal data the format no longer calls for while lacking the Ceased date that the permanent insiders section now records. The changes are few and specific: four personal-data fields leave the event-based template, the national identification number becomes the identifier with date of birth as a fallback, permanent insiders get an Obtained and a Ceased column, and an adviser firm is represented by one contact person.
SME growth market issuers have their own template under Annex II of the new regulation, and the legal text sets out which format applies to which list.
Related reading: ESMA Q&As May 2026: ESG Ratings, MiCAR, and MAR Answers
Key dates behind the CSSF insider list templates
- 14 November 2024: Regulation (EU) 2024/2809, the Listing Act regulation amending MAR, published in the Official Journal.
- 3 April 2025: ESMA consultation paper on the alleviated insider list format (ESMA74-1103241886-1096); comments closed on 3 June 2025.
- 5 September 2025: deadline in Article 18(9) MAR for ESMA to submit the draft implementing technical standards (ITS).
- 21 October 2025: ESMA final report with the draft ITS (ESMA74-268544963-1552).
- 12 June 2026: the Commission adopts Implementing Regulation (EU) 2026/1291.
- 15 June 2026: publication in the Official Journal.
- 5 July 2026: entry into force; Implementing Regulation (EU) 2022/1210 is repealed.
The order matters for anyone dating their own remediation. The format obligation attaches to the Implementing Regulation, which applies directly in every Member State, so lists drawn up or updated from 5 July 2026 are governed by the new annexes. The prescribed formats are those set out in the annexes to Implementing Regulation (EU) 2026/1291.
What the Annexes prescribe for the insider list formats
Annex I of Implementing Regulation (EU) 2026/1291 contains Template 1 for sections specific to individual pieces of inside information and Template 2 for the optional permanent-insiders section. Each template carries a date and time of creation, a date and time of the last update, and the date of transmission to the competent authority. In Template 1 the creation stamp is when the specific piece of inside information was identified, and Template 1 also opens with a description of that information; in Template 2 it is the creation of the permanent insiders section.
Below the header sit seven columns: first name(s) of the insider; surname(s) of the insider; professional telephone number(s), meaning the work direct line and work mobile numbers; function and reason for being insider; Obtained, the date and time the insider obtained access to the specific piece of inside information; Ceased, the date and time that access ended; and the national identification number (if applicable) or otherwise date of birth.
In Template 2, Obtained and Ceased refer to access to all inside information at all times. Annex I prescribes timestamps in UTC, dates in yyyy-mm-dd format, and professional telephone numbers in the format the annex sets out.
UTC is the timestamp rule that needs a conversion step. Luxembourg runs one hour ahead of UTC in winter and two hours ahead in summer, so a time copied straight from a meeting invitation or an email header lands an hour or two late on the list. For a section created at 09:15 local time on a July morning, the template expects 07:15 UTC.
The CSSF’s market abuse page states that the template for insider lists “can be found in Annex I of COM Reg 2026/1291” and refers SME growth market issuers to Annex II of the same regulation. Implementing Regulation (EU) 2022/1210 was repealed on 5 July 2026, and Article 3 of Implementing Regulation (EU) 2026/1291 provides that references to the repealed regulation are to be construed as references to Implementing Regulation (EU) 2026/1291.
The downloadable workbooks differ from the annexes in places. The CSSF’s SME growth market workbook has a creation line and a transmission line but no last-update line, and its Obtained and Ceased columns refer to access to all inside information at all times, whereas Annex II has three header fields and ties Obtained and Ceased to regular access to inside information. The CSSF’s general workbook describes the function and reason column without the Annex I prompt for a third-party service provider’s company name and address. Where a workbook and an annex differ, the annex sets the legal format.
MAR Article 18 itself stayed where it was
The Listing Act changed the format of insider lists without touching the duty to keep them. Article 18 MAR, as reproduced in Annex III of ESMA’s April 2025 consultation paper with the Listing Act amendments marked, still requires issuers and anyone acting on their behalf or on their account to draw up a list of everyone with access to inside information who works for them under a contract of employment or otherwise performs tasks giving that access, such as advisers, accountants or credit rating agencies. The list has to be updated promptly and provided to the competent authority as soon as possible on request.
The surrounding paragraphs are unchanged in substance. Article 18(2) requires reasonable steps so that each listed person acknowledges the legal and regulatory duties in writing and is aware of the sanctions for insider dealing and unlawful disclosure. Article 18(3) sets the minimum content: identity, reason for inclusion, date and time of access, and the date the list was drawn up. Article 18(4) names three update triggers (a change in a listed person’s reason for inclusion, a new person gaining access, and a person ceasing to have access) and requires each update to state the date and time of the triggering change. Article 18(5) requires the list to be kept for at least five years after it is drawn up or updated.
What changed is the mandate behind the format. Article 2(7) of Regulation (EU) 2024/2809 rewrote Article 18(9) so that ESMA had to review the ITS on the alleviated format used by SME growth market issuers and extend that format to all insider lists under paragraph 1 and under both subparagraphs of paragraph 6. Recital 72 of the amending regulation, as quoted by ESMA, explains the aim as avoiding “excessive regulatory burden, while maintaining the essential information for competent authorities to investigate market abuse breaches”. The Listing Act’s prospectus strand runs on a separate track; the prospectus side is covered in the prospectus disclosure guidelines article.
A more radical option was on the table and fell away. ESMA’s final report records a respondent pressing to delete event-based lists, as the Commission’s December 2022 Listing Act proposal had suggested. The adopted Level 1 text kept them, and the new ITS still requires a section for each piece of inside information.
Event-based lists: four fields out, one changed shape
Article 1 of Implementing Regulation (EU) 2026/1291, as summarised in the Malta Financial Services Authority’s circular of 6 July 2026, requires the event-based list under Article 18(1) MAR to be drawn up and kept up to date in accordance with Template 1 of Annex I. Compared with the 2022/1210 template, the changes look like this:
| Field in the 2022/1210 event-based template | Position under Template 1 of Implementing Regulation (EU) 2026/1291 |
|---|---|
| Surname(s) of the insider at birth | Removed |
| Company name and address | Removed as a field; ESMA placed third-party company details inside “Function and reason for being insider” |
| Personal telephone numbers | Removed |
| Personal full home address | Removed |
| Date of birth | Kept only as the fallback where a national identification number is not applicable |
| Professional telephone number(s) | Kept |
Recording date of birth for every insider is tempting because it is simple to collect, yet the format puts the national identification number first. A few consultation respondents told ESMA that national identification numbers are unevenly available across Member States and suggested accepting date of birth without that condition, or on its own; another respondent wanted both made mandatory. ESMA kept its position: all issuers report the insider’s national identification number whenever applicable, and date of birth only where no such number exists in that Member State. For a mixed team with insiders from several countries, the column can legitimately hold a number for one person and a date for the next.
Professional telephone numbers survived for a stated reason. Recital 9 of ESMA’s draft explains that telephone numbers let the competent authority act quickly and request data traffic records, and that the data should be supplied at the outset so an investigation is not compromised by follow-up requests. The template accordingly asks for the work direct telephone line and work mobile numbers. The recitals of the adopted Implementing Regulation (EU) 2026/1291 do not repeat that explanation.
Permanent insiders: Obtained, Ceased and no double entry
Under Article 1 of the new regulation, persons who, because of their function or position, have access to all inside information at all times may be listed in a permanent insiders section using Template 2 of Annex I. The section is optional, and two things about it changed.
The first is the date logic. The 2022 template had a single “Included” field. According to the MFSA’s summary of the adopted text, it has been replaced by Obtained, a Ceased field has been added, and a permanent insider who stops having access to all inside information is no longer removed from the section. The row stays, with the end date recorded. ESMA’s October 2025 draft still showed a single “Included” column for Template 2, so a list rebuilt to the ESMA draft in late 2025 is missing the Ceased column the final text requires.
The second is duplication. Recital 6, as the MFSA summarises it, says entities using the permanent section should not also list those people in the event-based sections, because the two lists rest on different assumptions: one captures people with access to all of the issuer’s inside information at all times, the other people with access to specific pieces of it. Article 1(2) of Implementing Regulation (EU) 2026/1291 makes the rule binding: where a permanent insiders’ section is drawn up and kept up to date, the persons listed in it shall not be included in the event-based sections, and the second subparagraph of Article 2(2) applies the same rule to SME growth market lists kept under the second subparagraph of Article 18(6) MAR. ESMA’s October 2025 draft had said only that permanent insiders did not need to be included in the event-based sections, so a list built to the draft wording that repeats them there does not match the adopted text.
The permanent section is also narrower than its name suggests. The test is access to all inside information at all times. ESMA’s final report records one respondent warning that many issuers place people in the permanent section who do not meet that threshold, and another asking ESMA to widen the definition to people with regular access to most inside information. ESMA kept the definition. A role that sees inside information deal by deal therefore belongs in the event-based sections, however senior the person holding it.
Advisers and service providers: one name per firm
Recital 4 of the new regulation settles a question that ESMA says it had earlier forwarded to the Commission as a Q&A before agreeing to deal with it in the ITS: where a legal person acting on behalf or on account of the issuer has access to inside information directly concerning that issuer, the issuer includes the details of only one natural person acting as contact person for that third-party service provider. ESMA’s final report adds where the firm’s identity goes. After respondents argued that dropping the company name and address field would make external providers hard to identify, ESMA decided that the company details of a third-party service provider are reported inside the “Function and reason for being insider” field, in all the insider lists.
The adopted Annex templates identify one natural person as contact person for the third-party service provider and require the provider’s company name and address in the function and reason field. A team working from a spreadsheet alone should check that its layout reflects this.
The single-contact rule leaves the adviser’s own obligation intact. Article 18(1) MAR applies to persons acting on the issuer’s behalf or on its account, so the law firm, bank or auditor still keeps its own insider list naming the staff who had access. ESMA’s reasoning was that the issuer cannot see how inside information circulates inside a third party, that the provider’s own list fills that gap, and that a competent authority can rebuild the full picture by requesting both lists. Separately, the second subparagraph of Article 18(2) leaves an issuer that asks another person to draw up and update its list fully responsible for compliance, with a standing right of access to that list.
SME growth market issuers: Annex II or Annex I
Article 18(6) MAR gives SME growth market issuers a choice of population, and the template follows from it. Under the first subparagraph, an issuer whose financial instruments are admitted to trading on an SME growth market may list only those persons who, because of their function or position within the issuer, have regular access to inside information. Article 2 of the new regulation sends that list to the template in Annex II. Under the second subparagraph, a Member State may, where justified by specific national market integrity concerns, require SME growth market issuers to list everyone referred to in Article 18(1)(a). Those lists use Template 1 of Annex I, with the option of a permanent section under Template 2.
Annex II of Implementing Regulation (EU) 2026/1291 prescribes three header fields (date and time of creation, date and time of the last update, and date of transmission to the competent authority), followed by seven columns. Its Obtained and Ceased fields record when the insider obtained and ceased to have regular access to inside information.
Form is lighter for SME issuers. Article 2(3) of Implementing Regulation (EU) 2026/1291 allows the Article 18(6) insider lists to be kept in any form that ensures the completeness, integrity and confidentiality of the information during transmission to the competent authority. A recital of the regulation explains that SME growth market issuers are not required to keep the list electronically where completeness, confidentiality and integrity are ensured. The CSSF’s market abuse page does not say whether Luxembourg has used the national option in the second subparagraph of Article 18(6), so that point is worth confirming with the CSSF before choosing between Annex II and Template 1.
Sending an insider list to the CSSF on request
The CSSF’s market abuse page says the list “shall be provided to the CSSF upon request as soon as possible”, sent through eRIIS where the entity has an account or by email to market.abuse@cssf.lu, and recommends protecting the documents with a password sent to the CSSF through a separate channel. Article 1(4) of Implementing Regulation (EU) 2026/1291 requires each competent authority to specify on its website the electronic means for transmitting an Article 18(1) insider list. The template’s “Date of transmission to the competent authority” field records the date on which the list is transmitted.
Article 1(3) of Implementing Regulation (EU) 2026/1291 requires an Article 18(1) insider list to be kept in an electronic form that meets three conditions at all times: access restricted to clearly identified persons who need it, information that is accurate and kept up to date, and access to previous versions. The third condition matters most in practice. A request about trading in a past window needs the list as it stood at that time, and a register that overwrites rows in place cannot answer it.
Insider lists also stay out of the public disclosure plumbing. Article 21a MAR, inserted by Regulation (EU) 2023/2869, routes inside information disclosed under Article 17(1) and (2) and transaction notifications published under Article 19(3) to the European single access point from 10 January 2028; our article on the ESAP first phase tracks that timetable. Insider lists are not among the Article 21a items and remain a confidential exchange with the competent authority. Crypto-assets sit in a separate market abuse title under MiCAR, which our MiCAR STOR reporting guide covers, and the CSSF’s insider list template page names MAR as its related regulation.
Proposals that did not make it into the format
ESMA received 19 responses to its April 2025 consultation, and several suggestions it declined explain why the CSSF files look the way they do.
Two respondents wanted the professional telephone number replaced by a professional email address. The template keeps the telephone field and has no email column. One respondent asked for times in the local time of the issuer’s head office as an alternative to UTC; the template keeps UTC.
Some respondents wanted the company name and address restored in the event-based template, and the compromise was to carry company details inside the function field for third-party providers. Another proposed an EU-wide electronic format with a central submission platform run by ESMA and a supervisor-only unique identifier for each insider. The ITS does neither, and transmission stays with each competent authority’s chosen channel.
The permanent section itself survived a challenge. A few respondents saw it as a source of overlapping records and suggested abolishing it or making it voluntary in favour of one event-based list, while the majority called it very useful for quickly identifying key individuals. ESMA kept it as an optional section.
Two retention clocks in one file
Retention now runs on two clocks. Article 18(5) MAR requires the list to be kept for at least five years after it is drawn up or updated. Article 1(5) of Implementing Regulation (EU) 2026/1291 sets a ceiling on the personal data: it is to be kept for no longer than five years after a person ceased to be on an Article 18(1) insider list. Article 2(4) applies the same five-year limit to the Article 18(6) lists of SME growth market issuers.
The clocks start from different events. With the Ceased column keeping departed permanent insiders on the list, each later update to the section restarts the Article 18(5) clock for the file, while the personal-data limit runs from the point at which the person ceased to be on the list. The instruments do not expressly say that the Ceased timestamp is that point in every case, so the interaction should be resolved before any automated row deletion is built. Neither the CSSF page nor the templates say how the CSSF expects the two periods to be reconciled.
Frequently Asked Questions
What happens to an event-based section opened before 5 July 2026 that is still live?
Implementing Regulation (EU) 2026/1291 entered into force on 5 July 2026, repealed Implementing Regulation (EU) 2022/1210 and contains no express transitional provision for existing insider-list sections. The Regulation requires Article 18(1) lists to be drawn up and kept up to date in accordance with the new templates. The Regulation does not say whether a section opened under the 2022/1210 format has to be converted at once or at its next update, so that timing is worth confirming with the CSSF before a live section is migrated.
Can an issuer keep collecting home addresses and personal phone numbers?
The template no longer asks for them, and recital 8 of Implementing Regulation (EU) 2026/1291 states that any processing of personal data for the purposes of the Regulation should comply with Union data protection law, naming Regulation (EU) 2016/679 for processing by competent authorities. Holding the removed fields would therefore need its own justification under the GDPR; the insider list format no longer supplies one.
Does the CSSF require its own template file, or can a system export be sent?
The legal format is the annex of Implementing Regulation (EU) 2026/1291. An export that carries the same header stamps and columns in the same formats matches the prescribed format. The UTC timestamp format and the transmission date field are the two entries worth checking against the annex in a system export.
A permanent insider moves to a role with access to only one project. How is that recorded?
The person stops having access to all inside information at all times, so the permanent section gets a Ceased timestamp. If the new role keeps access to a specific piece of inside information, the person then belongs in that event-based section with an Obtained time matching the role change. The ITS does not describe this move expressly; the sequence follows from the two templates.
The adviser’s contact person changes mid-deal. Is that an update?
A change in the third-party service provider’s named contact requires the insider-list information to remain accurate and up to date. The ITS does not expressly prescribe how the Obtained and Ceased timestamps should be populated solely because the designated contact person changes, so those timestamps should not automatically be equated with the contact-person replacement unless they also reflect the relevant access to inside information.
Do these templates apply beyond issuers?
Article 18(8) MAR extends paragraphs 1 to 5 to emission allowance market participants for inside information arising from their physical operations, and to auction platforms, auctioneers and auction monitors for auctions held under Regulation (EU) No 1031/2010. Recital 1 of Implementing Regulation (EU) 2026/1291 names the same actors as bound to draw up, and update promptly, an insider list in a specific format.
Is an issuer whose bonds trade on an MTF inside Article 18?
Article 18(7) applies to issuers that requested or approved admission to a regulated market, and, for an instrument traded only on an MTF or OTF, to issuers that approved its trading there or requested its admission to an MTF. An issuer whose instruments were taken onto an MTF without its request or approval is outside the scope of Article 18 for those instruments.
Related Articles
- ESMA Q&As May 2026: ESG Ratings, MiCAR, and MAR Answers: six ESMA answers from 28 May 2026, including the MAR Q&A on annual audits of STOR detection arrangements.
- ESAP First Phase: Where Regulated Disclosures Must Now Be Filed: which regulated disclosures route through collection bodies since ESAP data collection began on 10 July 2026.
- ESMA Prospectus Disclosure Guidelines: The 9 November 2026 Deadline: ESMA’s consultation on updated Prospectus Regulation disclosure guidelines and related Q&As.
- MiCAR STOR Reporting: How CASPs File Suspicious Transaction and Order Reports Under Article 92: market abuse surveillance and STOR filing with the CSSF for crypto-asset service providers.
- ESMA ESEF Taxonomy 2025: What Changes for 2026 IFRS Filings: the ESEF taxonomy update of 21 April 2026 and what issuers and software vendors need to change.
Key Takeaways
- Check every insider list section opened or updated since 5 July 2026 against Template 1 or Template 2 of Annex I.
- The event-based template no longer has fields for surname at birth, personal phone numbers or home address, and a third-party provider’s company details now go inside the function and reason field.
- Identifier logic: national identification number where one applies, date of birth only where none exists.
- Permanent section leavers keep their row with a Ceased timestamp, and permanent insiders come out of the event-based sections.
- One named contact per adviser firm, with the firm’s details written into the function column; the adviser runs its own list.
- SME growth market issuers: where Article 18(6), first subparagraph, MAR applies, use Annex II of Implementing Regulation (EU) 2026/1291, which records when each person obtained and ceased to have regular access to inside information. Where a Member State has exercised the option in Article 18(6), second subparagraph, the applicable format is Template 1 of Annex I, with the option of a permanent-insiders section under Template 2.
- Apply both retention requirements without treating the Ceased timestamp as an automatic deletion date: Article 18(5) MAR requires each insider list to be retained for at least five years after it is drawn up or updated, while Implementing Regulation (EU) 2026/1291 provides that personal data relating to a person on the insider list must be retained for no longer than five years after that person ceased to be on the list. The instruments do not expressly state that the Template Ceased timestamp is, in every case, the date on which the person ‘ceased to be on the list’, so the interaction should be resolved before implementing automated row deletion.
- Confirm the eRIIS account or the market.abuse@cssf.lu route, with a separate channel for the password, before a request arrives.
Sources and References
- CSSF, Template for insider lists and updating insider lists: https://www.cssf.lu/en/Document/templatefor-insider-lists-and-updating-insider-lists/
- CSSF, insider list workbook (Template_Insider_List.xlsx): https://www.cssf.lu/wp-content/uploads/Template_Insider_List.xlsx
- CSSF, SME growth market insider list workbook (Template_Insider_List_SME.xlsx): https://www.cssf.lu/wp-content/uploads/Template_Insider_List_SME.xlsx
- CSSF, Market abuse (insider lists, transmission channels, Law of 23 December 2016): https://www.cssf.lu/en/market-abuse/
- CSSF, Law of 23 December 2016 on market abuse (consolidated version): https://www.cssf.lu/fr/Document/loi-du-23-decembre-2016-1/
- Regulation (EU) No 596/2014 on market abuse (MAR), EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32014R0596
- Regulation (EU) 2024/2809 (Listing Act regulation amending MAR), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/2809/oj
- Commission Implementing Regulation (EU) 2026/1291 on the format of insider lists, EUR-Lex: https://eur-lex.europa.eu/eli/reg_impl/2026/1291/oj
- Commission Implementing Regulation (EU) 2022/1210 (repealed), EUR-Lex: https://eur-lex.europa.eu/eli/reg_impl/2022/1210/oj
- Regulation (EU) 2023/2869 (ESAP amendments, inserting Article 21a MAR), EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R2869
- Regulation (EU) 2016/679 (GDPR), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2016/679/oj
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCAR), Title VI, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2023/1114/oj
- Commission Regulation (EU) No 1031/2010 (emission allowance auctions, as referenced in Article 18(8) MAR; repealed and replaced by Commission Delegated Regulation (EU) 2023/2830), EUR-Lex: https://eur-lex.europa.eu/eli/reg/2010/1031/oj
- ESMA, Consultation Paper on draft ITS on the extension of the use of the alleviated format of insider lists, ESMA74-1103241886-1096 (3 April 2025): https://www.esma.europa.eu/sites/default/files/2025-04/ESMA74-1103241886-1096_Consultation_Paper_on_ITS_on_insider_lists.pdf
- ESMA, Final Report on the draft ITS on the extension of the use of the alleviated format of insider lists, ESMA74-268544963-1552 (21 October 2025): https://www.esma.europa.eu/sites/default/files/2025-10/ESMA74-268544963-1552_Final_Report_on_on_the_draft_implementing_technical_standards_on_the_extension_of_the_use_of_the_alleviated_format_of_insider_lists.pdf
- MFSA, Circular on Implementing Technical Standards on the Extension of the Use of the Alleviated Format of Insider Lists (6 July 2026): https://www.mfsa.mt/wp-content/uploads/2026/07/Implementing-Technical-Standards-on-the-Extension-of-the-Use-of-the-Alleviated-Format-of-Insider-Lists.pdf
Before the CSSF’s next insider list request
Article 18(1)(c) MAR requires the insider list to be provided to the competent authority as soon as possible upon request. The artifact to produce now is a test export of one open event-based section and the permanent section in the Implementing Regulation (EU) 2026/1291 layout: UTC timestamps, Ceased dates populated for leavers, one contact per adviser, and the “Date of transmission to the competent authority” field left blank until the list is transmitted and then populated with the actual transmission date.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
