CSSF Tokenisation FAQ: Control Agents, Fund Registrars and DORA

RegReportingDesk card: CSSF, Commission de Surveillance du Secteur Financier, Luxembourg

On 2 October 2026 the CSSF published version 1 of its FAQ on tokenisation, a nine-page document with six questions about Luxembourg investment funds that issue units or shares on a distributed ledger and about the control agents created by Blockchain Law IV. The CSSF tokenisation FAQ splits its answers evenly: three for fund managers and UCI administrators, three for entities that want to act as control agent. Half of the answers point to a filing with the CSSF: an authorisation under Circular CSSF 22/811, a control agent notification under the Law of 6 April 2013 on dematerialised securities, or an ICT third-party notification under Circular CSSF 25/882.

The calendar is where a tokenised share class project can slip. The CSSF considers it highly likely that the control agent activity is a critical or important function under DORA, so outsourced smart contract work brings a separate ICT notice period into play beside the control agent notification. The FAQ itself warns that outsourcing notifications may affect the timing of the control agent notification because the applicable legal periods may differ.

The six answers cite Luxembourg company, securities and supervisory law, three CSSF circulars and DORA. MiCA and MiFID II appear nowhere in the text, and the CSSF website files the FAQ under ICT and cyber risk for DORA entities. The perimeter question still matters for anyone mapping tokenised instruments, and the EU texts answer it.

Related reading: BaFin and the MiCAR Perimeter: How Regulators Separate Tokenised Securities From Crypto-Assets

Notice periods the CSSF tokenisation FAQ puts on the critical path

Five procedural clocks run through the document and the circulars it cites. Four attach to events that come before a tokenised fund structure operates; the fifth is the annual DORA return that records what was set up.

  • Control agent notification: Article 21a(2) of the Dematerialised Securities Law (numbered Article 21bis(2) in the French consolidated text linked in Sources) requires notification to the CSSF at least two months before the control agent’s activities take place, containing the information necessary to demonstrate compliance with Article 21a(1). The CSSF FAQ further states that, for its assessment process, the period runs only once the CSSF has confirmed that the notification is complete.
  • ICT third-party arrangement supporting a critical or important function: notification at least three months before the planned arrangement takes effect, reduced to one month where the provider is a Luxembourg support PFS governed by Articles 29-3, 29-5 or 29-6 of the Law of 5 April 1993 on the financial sector (Circular CSSF 25/882, point 13; FAQ Q4 and Q6).
  • Outsourcing other than ICT outsourcing: where elements of the control agent activity are fully or partially outsourced, FAQ Q4 also refers to Circular CSSF 22/806. Point 59 of that circular requires an entity that intends to outsource a critical or important function, within the meaning of the circular, to notify the competent authority at least three months before the planned outsourcing comes into effect, reduced to one month when resorting to a Luxembourg support PFS governed by Articles 29-1 to 29-6 of the Law of 5 April 1993. Under point 2, Part I of the circular, which contains point 59, applies to credit institutions and investment firms when they perform outsourcing other than ICT outsourcing. Point 2 also refers significant credit institutions to the relevant ECB rules, if any, and applies Part I to Luxembourg branches of entities headquartered elsewhere in the EEA only where they outsource functions in areas for which the CSSF retains an oversight responsibility.
  • UCI administrator changing its operating model to use DLT: prior CSSF authorisation of any substantial change to the initial application (Circular CSSF 22/811, point 5; FAQ Q1). The FAQ gives no processing period for this step.
  • DORA register of information: annual submission to the CSSF between 28 February and 31 March, covering arrangements contracted up to the end of the previous year (Circular CSSF 25/882, point 18). Points 3 and 4 of the circular disapply its Chapter 2, which contains both this window and the point 13 notice periods, for Luxembourg branches of financial entities whose head office is in another EU Member State and for significant credit institutions for which the ECB is the prudential competent authority.

Two features of that list matter for planning. The control agent clock is conditional: the FAQ places a formal presentation of the operating model before the notification itself, and the two months only begin when the CSSF says the file holds everything it needs. And point 13 of Circular CSSF 25/882 treats an ICT notification sent late, or sent without the CSSF’s instructions and forms, as not notified at all; point 59 of Circular CSSF 22/806 does the same for an outsourcing notification sent late, or sent without the instructions and, where applicable, the forms on the CSSF website.

Where MiCA fits when a fund unit becomes a token

The FAQ defines tokenisation broadly: the digital representation of assets on distributed ledgers, or the issuance of traditional asset classes in tokenised form so they can be issued, stored and transferred on a distributed ledger. Fund units belong to the second group. The CSSF says it assesses tokenisation business models by how the technology is used, consistent with its technologically neutral approach.

MiCA draws its own boundary. Article 2(4)(a) of Regulation (EU) 2023/1114 states that the regulation does not apply to crypto-assets that qualify as financial instruments. Units in collective investment undertakings are listed as a financial instrument in point (3) of Section C of Annex I to MiFID II (Directive 2014/65/EU).

Read together, the two provisions mean that where the token qualifies as a unit in a collective investment undertaking and therefore as a financial instrument, MiCA does not apply to that token on the basis of Article 2(4)(a). The precise fund, securities and investment-services requirements applicable to the structure and its participants must be assessed separately. That reading comes from the EU texts; the CSSF FAQ leaves the point unaddressed. The CSSF’s own tagging is consistent with it: the FAQ page lists fund vehicles, fund managers, banks, investment firms and specialised PFS as the relevant audience, and CASPs and token issuers are absent from that list.

The margins are fact-specific. Article 2(5) of MiCA required ESMA to issue guidelines by 30 December 2024 on the conditions and criteria for qualifying crypto-assets as financial instruments, and our explainer on the ESMA guidelines for classifying crypto-assets as financial instruments walks through that test. A compliance map that routes every on-chain instrument to the MiCA workstream will misfile tokenised fund units, which belong with the fund and securities law teams.

The FAQ does create a place for the analysis. When an entity first contacts the CSSF about a tokenisation project, the CSSF invites it to include a legal qualification of the tokens to be issued, including the rights attached to them.

Q1 asks whether a UCI can issue units or shares natively on DLT, with no conventional record behind them. The answer is yes, provided the operating model complies with the regulatory framework that applies to that UCI. The more useful sentence follows: tokenised units may be issued in registered or dematerialised form within the meaning of the Law of 10 August 1915 on commercial companies, and the use of DLT as issuance and record-keeping infrastructure does not determine the legal form of the securities, nor the reverse.

The legal form then decides which rules attach. For registered units, any UCI administrator performing the registrar function may use DLT to maintain the unit or shareholder register. For dematerialised units, an eligible entity, such as the investment fund manager, a registrar agent or a credit institution authorised as UCI administrator, has to act as UCI administrator for the registrar function, and market participants have to meet every requirement the Dematerialised Securities Law sets for that form.

For the dematerialised route, the 2013 law matters in its own detail. Its definition of securities covers equity securities issued by Luxembourg companies limited by shares, expressly including units of a fonds commun de placement, and debt securities governed by Luxembourg law. Article 3 requires unlisted dematerialised securities of the same kind to be recorded at all times in a single issuance account held by a single settlement organisation, a single central account keeper or a single control agent.

For registered units the FAQ describes DLT as a way to maintain the unit or shareholder register, and says DLT use does not determine legal form. The Dematerialised Securities Law, including the Article 3 issuance-account rule, governs dematerialised securities, so those rules attach where the issuer chooses the dematerialised form.

The last paragraph of Q1 is aimed at UCI administrators. One planning a substantial change to its operating model as part of its use of DLT has to apply to the CSSF for authorisation of that change under point 5 of Circular CSSF 22/811. That point also covers advance notification of substantial changes to the delegation of critical or important operational tasks.

Control agent and registrar: the FAQ keeps both seats filled

Q2 asks whether appointing a control agent for dematerialised units removes the need for a registrar. The CSSF answers no. The form in which units are issued does not affect the need to appoint a UCI administrator in charge of the registrar function under Circular CSSF 22/811.

The two roles come from different texts. Article 1(10a) of the Dematerialised Securities Law (point 10bis in the French text) defines the control agent as an investment firm, a credit institution or a settlement organisation, designated by the issuer, whose activity consists of three tasks:

  • keeping the issuance account within or through a secure electronic recording mechanism, including a distributed ledger;
  • monitoring at all times the chain of holding of the dematerialised securities held in securities accounts on such a mechanism;
  • checking that the total issued for each issue in the issuance account equals the sum of the securities recorded in the account keepers’ securities accounts on that mechanism.

Points 19 and 20 of Circular CSSF 22/811 give the registrar function a wider job. It keeps the unit or shareholder register, and for each UCI it covers at least the reception and execution of subscription, redemption, transfer and cancellation orders, the application of subscription and redemption prices, calculation of the number of outstanding units or shares, reconciliation of subscription and redemption orders with the related cash flows, distribution of income and, where relevant, payments of proceeds to the Caisse de Consignation.

The word reconciliation appears on both sides, and the two meanings differ. The control agent’s check under point (c) is a securities count: units issued against units held. The registrar’s reconciliation matches subscription and redemption orders with cash. A control agent that runs a clean supply check on-chain has done nothing towards the cash reconciliation, and the FAQ assigns all residual tasks under points 19 and 20 to an eligible UCI administrator.

One entity can hold both seats. The FAQ gives the example of a credit institution authorised as UCI administrator under Circular CSSF 22/811 that has also notified its intention to act as control agent under Article 21a.

Eligibility is the trap on each side. Under Circular CSSF 22/811, administrative agents authorised under Part I, Chapter 2 of the Law of 5 April 1993 may cover only the NAV calculation and accounting function and the client communication function, and client communication agents only the latter, so neither can take the registrar seat. On the control agent side, the definition names three entity types. An investment fund manager can sit in the registrar seat, and the FAQ lists it as an example of an eligible UCI administrator, but it is not one of the three entity types the law names for the control agent role.

Running tokenised and traditional share classes with more than one registrar

Q3 confirms that several entities may act as UCI administrator for the registrar function of the same UCI where that UCI issues both tokenised and traditional units. The permission comes with five conditions, spread across the fund manager, the UCI and the administrators.

  • The split of tasks must not fragment the structure so much that the coordination and general supervisory function becomes difficult or impossible, and it must not add cost through unjustified duplication or complexity.
  • The investment fund manager must disclose the operating model, with its risks and implications, to investors. Under point 41 of Circular CSSF 22/811 the offering documents name every entity acting as UCI administrator for the UCI, together with its function.
  • An entity, either the investment fund manager or one of the UCI administrators, must keep a consolidated view of the units issued so that the other administration tasks can run, with NAV per share and the calculation of distributions or capital calls given as examples.
  • The investment fund manager or the UCI must manage the additional risks that the division of registrar responsibilities creates.
  • The structure must comply with the applicable law in full, including, where applicable, the obligation to keep a register of all registered shares at the UCI’s registered office containing the information required by the Law of 10 August 1915.

The third condition is the one an operating model can leave unowned. Two registrars, each reconciling its own book cleanly, still leave the NAV per share and any capital call calculation without a single unit count unless someone has been named to hold it. The FAQ leaves the choice between the fund manager and one of the administrators open.

Becoming a control agent: what makes the notification complete

Q4 sets out the procedure, starting with the sequence. The entity first presents its operating model to the CSSF, as described in the FAQ’s introduction, then notifies the CSSF under Article 21a(2) of the Dematerialised Securities Law at least two months before the activity starts. The notification has to carry enough information for the CSSF to verify the conditions in Article 21a(1).

Those conditions are organisational. The control agent needs solid internal governance arrangements: a clear organisational structure with well-defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor and report risks, adequate internal control mechanisms including sound administrative and accounting procedures, and IT systems with control and security arrangements suited to the three control agent tasks. At least one person responsible for its management must have adequate professional experience.

The regime is a notification with a power to prohibit. Under the third subparagraph of Article 21a(2), the CSSF may prohibit the activity where the notification lacks the information needed to verify compliance or where the legal requirements are not met. The FAQ then fixes the start of the two-month notification period: it begins to run only when the CSSF confirms to the applicant that the notification is complete, meaning it contains everything required for the assessment in a complete and clear manner.

Entities established in another EEA Member State face three further steps. Citing Article 2(10) of the Law of 23 December 1998, the FAQ says the CSSF must ensure that control agents established or operating as control agents in Luxembourg comply with Article 21a. An EEA entity must therefore inform the competent authority of its home Member State before notifying the CSSF, pass on any objection or comment from that authority, and make sure the CSSF can verify, before any control agent activity begins, that the home authority will help it obtain the information needed to check compliance, both at notification and throughout the life of the activity. The FAQ says this may take the form of bilateral cooperation arrangements between the authorities.

The FAQ treats all of these aspects as necessary conditions for the CSSF to consider the notification complete, so for an EEA entity the two-month period cannot start until they are met. Where the conditions are not met, or are no longer met, the FAQ says the CSSF may prohibit the entity from carrying out, or from continuing to carry out, control agent activities under the third subparagraph of Article 21a(2).

DORA applies to the whole entity, control agent activity included

Q5 starts from scope. The FAQ states that the entities referred to in Article 1(10a) fall within DORA (Regulation (EU) 2022/2554) under points (a), (e) and (g) of its Article 2(1), which cover credit institutions, investment firms and central securities depositories. The CSSF then takes the view, in light of two answers in the Joint ESA Q&A register, that these entities as a whole are subject to DORA, including in respect of the control agent activity.

The two ESA answers explain why the activity-level argument fails. Q&A DORA 136-3193 states that DORA defines its scope by type of entity, so it applies to the entity as a whole; where ICT systems, services or processes are shared between regulated and non-regulated activities, DORA obligations extend to them, and the answer sets no minimum percentage of regulated activity. Q&A DORA 137-3195 adds that when a legal entity qualifies as a financial entity under Article 2(1), the whole entity is subject to DORA, including its branches outside the EU, while non-EU subsidiaries are separate legal entities outside scope.

A bank or investment firm might be tempted to treat its control agent desk as an add-on outside the DORA programme because the activity is a creation of Luxembourg national law. The ESA answer leaves a narrow opening for non-regulated activities run on fully segregated ICT environments with contagion risk prevented. The CSSF’s answer on control agents makes no use of that opening, and places the control agent activity inside DORA without qualification.

The second half of Q5 links the two regimes. To meet the Article 21a(1) condition on information processing systems and their control and security arrangements, the entity must show those systems are suitable for its control agent duties, including by applying its DORA compliance framework to the control agent activity. The DORA evidence therefore feeds the control agent notification file. For fund administration groups mapping that framework, our DORA compliance checklist for Luxembourg fund administrators sets out the wider obligation set.

Smart contract providers and the critical-or-important-function presumption

Q6 answers the outsourcing question with a yes. A control agent may use a third-party service provider for technical support in the tokenisation of UCIs, and the FAQ names smart contract development and administration as examples.

The weight of the answer sits in the next sentence. The CSSF considers it highly likely that the control agent activity qualifies as a critical or important function within the meaning of Article 3(22) of DORA. That definition covers a function whose disruption would materially impair the financial performance of a financial entity or the soundness or continuity of its services and activities, or whose discontinued, defective or failed performance would materially impair continuing compliance with the conditions and obligations of its authorisation or its other obligations under financial services law.

Where an applicant plans ICT third-party arrangements to support the control agent activity, the FAQ directs it to Circular CSSF 25/882 and to the CSSF’s notification form, titled “Notification of an ICT third-party arrangement supporting a critical or important function as required under DORA”, within the applicable time limits. The circular grounds that notification in Article 28(3) of DORA, which requires financial entities to inform the competent authority in a timely manner about any planned contractual arrangement on ICT services supporting critical or important functions, and when a function has become critical or important.

The modality deserves care. “Highly likely” records the CSSF’s view and stops short of a legal classification; the FAQ itself refers to the applicant’s own self-assessment. The FAQ does attach a procedure to a different conclusion, though: an applicant whose self-assessment finds the activity is not a critical or important function is asked to tell the CSSF and give a substantiated rationale before any official notification, at the operating-model presentation.

The classification also travels into reporting. The register of information templates in Commission Implementing Regulation (EU) 2024/2956 record each function supported by ICT services provided by ICT third-party service providers in template B_06.01, with column B_06.01.0050 carrying the criticality or importance assessment as Yes, No or Assessment not performed (the column numbering follows the corrigendum published in the Official Journal on 19 September 2025, which corrected the codes originally printed for this template), and template B_07.01 collecting further assessment of ICT services that support a critical or important function, including the substitutability of the provider. Column B_06.01.0020 records the licensed activity from a closed list tied to the legal acts in Annex II of that regulation, with “support functions” used where a function is not linked to a registered or licensed activity. The FAQ does not say which entry a control agent function should carry, and that question is worth putting to the CSSF during the preliminary dialogue. Our DORA register of information guide covers how those templates connect.

Assembling the first CSSF file for a tokenised fund project

The FAQ’s introduction reads as a filing checklist. The CSSF invites entities to contact it as early as possible to open a preliminary dialogue, identify the applicable legal frameworks and licence needs, and surface obstacles early, possibly on the basis of a detailed presentation made before formal administrative procedures begin. Luxembourg-supervised entities go through their usual CSSF contact; other entities use the CSSF Innovation Hub at innovation@cssf.lu.

On first contact about a specific project, entities are invited to describe the whole project and the lifecycle of the assets involved, from issuance through trading, settlement and distribution. The CSSF lists what that description should contain:

  • a legal qualification of the tokens to be issued, including the rights attached;
  • a description of the activities of every stakeholder in the token lifecycle;
  • details of all contractual relationships, including outsourcing arrangements;
  • a preliminary assessment of the licence requirements the project may trigger and, if possible, the other administrative procedures it needs, with an outsourcing notification given as the example.

The FAQ frames this as an invitation, and the word matters less than the dependency it creates. Q4 makes the operating-model presentation the step that precedes the control agent notification, and Q6 asks that any rationale for treating the control agent function as not critical or important be given at that presentation. A presentation pack that omits the outsourcing map or the token qualification can therefore delay the control agent notification that Q4 places after it.

Frequently Asked Questions

Does the FAQ help a fund established outside Luxembourg that wants a Luxembourg control agent?

The FAQ’s six questions concern Luxembourg UCIs. The Dematerialised Securities Law defines the securities it covers as equity securities issued by Luxembourg companies limited by shares, including units of a fonds commun de placement, and debt securities governed by Luxembourg law. The definition is framed around Luxembourg-law issuers and instruments, so whether a foreign-law fund unit can use the regime is unclear from the text alone and is a point to raise with the CSSF before any notification is drafted.

Can units of one share class sit partly on a distributed ledger and partly in a conventional issuance account?

For dematerialised units, Article 3 of the Dematerialised Securities Law requires unlisted dematerialised securities of the same kind to be recorded at all times in a single issuance account held by a single settlement organisation, central account keeper or control agent. Splitting one class of dematerialised units across two issuance accounts would, as an interpretation of that rule rather than a CSSF statement, conflict with it. Q3’s multi-registrar model addresses a UCI with separate tokenised and traditional units, which is a different structure from one class split across two infrastructures.

What if the control agent function only becomes critical or important after launch?

Article 28(3) of DORA covers that case directly: financial entities must inform the competent authority in a timely manner when a function has become critical or important, in addition to notifying planned arrangements. Point 11 of Circular CSSF 25/882 repeats both limbs, so a reclassification after go-live is itself a notification trigger.

Does the FAQ address subscriptions and redemptions settled in stablecoins?

No. The FAQ is silent on the cash leg. An e-money token is a category of crypto-asset regulated by MiCA. A settlement design using an e-money token therefore requires a separate assessment of the MiCA requirements applicable to the token, its issuer and any relevant crypto-asset services, even where the fund unit itself qualifies for the Article 2(4)(a) financial-instrument exclusion. That belongs in the legal qualification and stakeholder description the CSSF asks for at first contact.

Is the FAQ final, and can the CSSF change its position?

The document is version 1, dated 2 October 2026. The CSSF describes it as a listing of recurrent questions with no aim of covering tokenisation exhaustively, says it will be updated progressively as issues arise, and reserves the right to adapt its approach on any covered matter at any time. It also states that the guidance is without prejudice to other legal and regulatory obligations, including AML obligations.

Key Takeaways

  • Where a planned ICT contractual arrangement supports a critical or important function and Chapter 2 of Circular CSSF 25/882 applies to the entity (points 3 and 4 exclude EU branches and ECB-supervised significant credit institutions), ensure that the notification timing under that circular is measured against the date on which that contractual arrangement is planned to come into effect: normally at least three months beforehand, or one month for the specified Luxembourg support PFS cases.
  • If the critical-or-important self-assessment for the control agent activity comes out negative, Q6 requests that the reasoning be given when presenting the operating model, ahead of any official notification.
  • Write into the operating model, before tokenised and traditional units launch side by side, which entity holds the consolidated unit count used for NAV per share and distributions.
  • Check the proposed registrar’s licence early: administrative agents and client communication agents are excluded from the registrar function under Circular CSSF 22/811.
  • For an EEA control agent candidate, start the home-authority step first; the CSSF treats its comments and the cooperation assurance as conditions of a complete file.
  • Where the control agent function is supported by an ICT service provided by an ICT third-party service provider and is therefore represented in template B_06.01, complete B_06.01.0050 with the entity’s criticality or importance assessment and determine the appropriate B_06.01.0020 licensed-activity entry under the ITS instructions.
  • Keep tokenised fund units with the fund and securities law owners in the compliance map, and put the MiCA Article 2(4)(a) reasoning into the token qualification sent to the CSSF.

Sources and References

What to file first for a tokenised share class

The document that unlocks the rest is the operating-model presentation to the CSSF. It carries the legal qualification of the tokens, the stakeholder and outsourcing map, the preliminary licence assessment and any argument against critical-or-important status. Under Q4 the control agent notification follows that presentation, and under Q6 an applicant that concludes the function is not critical or important is requested to give its rationale when presenting the operating model, so the presentation pack is the first artifact to produce.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • goAML Luxembourg: The CRF Reporting Workflow Explained

    Report Library › AML ReportinggoAML is Luxembourg’s electronic channel for suspicious-operation reporting and communication with the CRF; for lawyers, the platform integrates the Article 7 Bâtonnier filter before qualifying reports are forwarded to the CRF. In 2024 the CRF received significantly more suspicious reports than the prior year, according to its 2024 annual report. That…

  • EU Taxonomy Disclosure Simplification: The 12 August ESMA Deadline

    Updated July 2026In this guideDates that matter for the Taxonomy consultationHow the EU Taxonomy disclosure simplification review is structuredThe OpEx KPI faces the deepest cutWhat the EBA is asking banks and investment firmsGroup reporting: where aggregated KPIs breakInsurers and asset managers get a lighter reviewThe plumbing: ESRS, IFRS 8, materiality and the digital taxonomyWhat reporting…

  • FCA Crypto Authorisation: Building the Application Before 28 February

    Applications for FCA crypto authorisation opened at 9:00am on 30 September 2026, when the relevant application period set by the FCA’s direction under regulation 52 of the Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026 began. That period closes at 11:59pm on 28 February 2027. Firms apply through the FCA’s Connect system, and the…

  • AnaCredit v1.0.15: BCL Swaps the NUTS 3 Code List for January 2027

    On 1 October 2026 the Banque centrale du Luxembourg (BCL) published version 1.0.15 of its AnaCredit technical specifications together with a new SDMX schema package, and its reporting instructions page states that the AnaCredit v1.0.15 schemas are mandatory from reference date January 2027 (included) onwards. Credit institutions and foreign branches resident in Luxembourg therefore send…

  • MiCA Review: The EBA’s Priorities for Token Issuers and CASPs

    On 24 September 2026 the European Banking Authority published its response to the European Commission’s targeted consultation on the MiCA review, an exercise feeding into the review framework under Article 140 of Regulation (EU) 2023/1114. The EBA asks the Commission to prioritise five things: a dedicated regime for third-country multi-issuer stablecoin schemes, a fresh look…