CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them into Circulars CSSF 25/882, 25/892 and 25/893.

The mechanics are a re-mapping. Third-country branches, which the CSSF abbreviates to TCBs, come out of Circular CSSF 20/750 on ICT and security risk management in full, and out of the ICT-outsourcing half of Circular CSSF 22/806. They move into the three circulars built for DORA entities: 25/882 on the use of ICT third-party services, 25/892 on estimating the aggregated annual cost of major ICT incidents, and 25/893 on reporting those incidents and significant cyber threats. Run a branch’s ICT controls against a circular that, for it, no longer applies, and the branch is now measuring itself against the wrong rulebook.

Circular 26/915 amends seven circulars in one move: 20/750, 22/806, 25/881, 25/882, 25/883, 25/892 and 25/893. Most of what it does is scope work, with limited new substance. The single substantive addition sits inside the amendment to 25/893, and it is a fallback communication channel for incident notification when the primary channel cannot be reached. The re-mapping is the real task for branch compliance teams, with the fallback channel a smaller but genuine change worth logging.

Related reading: our guide to DORA ICT incident reporting

The dates that anchor Circular 26/915

Circular 26/915 itself applies immediately, but the circulars brought into scope contain reporting triggers and deadlines. Circular 25/882 sets the general prior-notification windows for planned ICT contractual arrangements supporting critical or important functions and requires annual submission of the register of information. Points 13, 17 and 18 contain the general rules, but the CSSF separately set the first 2026 register deadline for third-country branches of credit institutions at 30 June 2026 on a best-effort basis and identified 31 March 2027 for the next submission. Circular 25/892 is different: the aggregated annual cost-and-loss estimate is provided to the CSSF upon request.

Regulation (EU) 2022/2554 was adopted on 14 December 2022 and started to apply to CSSF-supervised financial entities on 17 January 2025. On 9 April 2025 the CSSF published Circulars 25/881, 25/882 and 25/883 to align the Luxembourg ICT and outsourcing framework with DORA; Circulars 25/892 and 25/893 on incident cost estimation and incident reporting followed in May 2025. Circular CSSF 26/915 states that on 17 December 2025 the European Commission confirmed DORA’s application to third-country branches; the underlying DORA102-3097 Q&A directly addresses Article 2(1)(a), (n) and (o), while the CSSF applies that stance to the TCB categories within its remit. Circular CSSF 26/915 followed on 27 August 2026, applying with immediate effect.

The immediate-effect wording in Chapter 3 of the circular matters for planning. There is no transitional runway. A branch that meets the definition is inside the DORA circulars from publication, so the re-mapping is a present obligation, in force from 27 August 2026.

How the Commission’s DORA position reached Luxembourg

EIOPA relayed the European Commission’s response under DORA102-3097, which states that DORA is applicable to third-country branches in an EU country. The published Q&A itself is framed around Article 2(1)(a), (n) and (o), and for point (o) states that DORA would not apply unless national law explicitly requires it. Circular CSSF 26/915 is the Luxembourg source that records the CSSF’s broader Article 2(1)(a) to (t) formulation and gives effect to the Commission stance for the TCB categories within the CSSF’s remit.

The CSSF gives effect to that reading through Circular 26/915. The treatment turns on the type of Luxembourg branch and the status of its head-office undertaking under the scope conditions in Circular 26/915. Establishing a Luxembourg branch as a third-country credit institution requires authorisation from the CSSF under the Law of 5 April 1993 on the financial sector. The CSSF then treats the branch as a financial entity subject to DORA across the amended circulars.

The significance here is interpretive. The CSSF uses the Commission response as the basis for treating the TCB categories within its remit as financial entities subject to DORA and for routing them to the relevant Luxembourg circulars.

Which Luxembourg establishments the circular actually reaches

The scope chapter of 26/915 lists the financial entities it covers, from credit institutions and investment firms through payment and e-money institutions, crypto-asset service providers and issuers of asset-referenced tokens, central securities depositories, central counterparties, management companies and AIFMs, IORPs, benchmark administrators and crowdfunding service providers. Sitting alongside them is the branch category: third-country branches of those undertakings whose head office is in a third country and that would qualify under Article 2(1) of DORA.

The phrase third-country branch is easy to misread. For this Luxembourg framework, a third-country branch should not be defined merely by saying that its head office is outside the EU. Circular 22/806 separately treats Luxembourg branches whose head office is in another EEA Member State as ‘EEA branches’; US, UK and Swiss head offices are examples outside that EEA branch category. A Luxembourg bank’s overseas operation runs in the opposite direction and belongs to a different regulatory conversation. The concept sits next to the prudential authorisation regime for such establishments, which we cover in our note on third-country branch authorisation under CRD6.

Branches of entities headquartered elsewhere in the EEA are treated differently and are not swept into this re-mapping. Circular 22/806 expressly describes Luxembourg branches whose head office is in another EEA Member State as ‘EEA branches’. Circular 25/892 uses narrower wording: it expressly excludes Luxembourg branches whose head office is in another EU Member State and states that those EU branches are expected to report their DORA estimations to the competent authority of the home Member State upon request. The line the CSSF draws is between a head office inside the EEA, where home-state supervision governs, and a head office in a genuine third country, where the Luxembourg branch now carries DORA obligations locally.

The circular map: from 20/750 to the DORA circulars

The core of 26/915 is a set of moves between circulars. Read as a table, the changes are these.

Third-country branches are removed from Circular CSSF 20/750 on ICT and security risk management in full. That circular now speaks to entities the CSSF supervises but that are not DORA financial entities, so a DORA-scope branch no longer looks to 20/750 for its ICT rules. To keep the framework internally consistent, 26/915 also adjusts Circular CSSF 25/881, the 2025 circular that had amended 20/750, so that the branch removal flows through cleanly.

Third-country branches are added to Circular CSSF 25/882 on the use of ICT third-party services for financial entities subject to DORA. This is the circular that recalls DORA’s requirements on ICT services provided by third parties and connects them to Luxembourg law, and it is where a branch’s third-party risk management, contractual arrangements and register work now live. For the mechanics of that register, see our explainer on the DORA register of information.

Third-country branches are added to Circular CSSF 25/892, which applies the Joint ESA Guidelines on estimating the aggregated annual costs and losses caused by major ICT-related incidents referred to in Article 11(11) of DORA. The Joint ESA Guidelines carry the formal reference JC/GL/2024/34. Circular 25/892 excludes microenterprises as defined in DORA Article 3(60). DORA Article 3(60) defines a microenterprise as a financial entity, other than a trading venue, a central counterparty, a trade repository or a central securities depository, that employs fewer than 10 persons and has annual turnover and/or an annual balance sheet total not exceeding EUR 2 million; Circular 25/892 does not prescribe a separate TCB-specific calculation method.

Third-country branches are added to Circular CSSF 25/893 on the reporting of major ICT-related incidents and significant cyber threats. That circular rests on Articles 18 and 19 of DORA and on the incident-reporting standards beneath them, and it is the one channel where 26/915 does more than move scope, as the next section sets out.

Outsourcing: what stays under 22/806 and what leaves it

Outsourcing is the part of the change most likely to be misread. Circular CSSF 22/806 splits in two for DORA-scope branches. Part I of 22/806 governs outsourcing other than ICT outsourcing; Part II governs ICT outsourcing. For a DORA-scope entity, including a third-country branch, Part II no longer applies, because DORA and Circular 25/882 now govern ICT third-party arrangements. Part I continues to apply to the branch for its non-ICT outsourcing.

So, where an arrangement meets Circular CSSF 22/806’s definition of outsourcing and is not ICT outsourcing, Part I continues to apply to the branch; ICT outsourcing and other ICT third-party-service arrangements fall under DORA and Circular CSSF 25/882 as applicable. Assuming that all of 22/806 fell away for DORA entities is the trap; the outsourcing circular keeps a live role for the non-ICT arrangements a branch runs.

One older requirement did go. Circular 25/883 removed from Circular 22/806 the cloud-specific requirements concerning EEA governing law and resilience of cloud services within the EEA, in order to align the requirements for entities remaining under Circular 22/806 with those applicable to DORA entities. The repeal was therefore not limited to DORA-scope entities. The alignment change was carried by Circular CSSF 25/883, the amending circular for 22/806, and 26/915 tidies the branch treatment to match. A branch reviewing cloud contracts should follow DORA’s contractual requirements and 25/882; the clause that 22/806 previously imposed on cloud providers was removed from Circular 22/806 by Circular 25/883.

The one substantive tweak: a fallback channel in 25/893

Everything above is scope. The exception is a change to point 9 of Circular CSSF 25/893. Alongside adding third-country branches, 26/915 introduces an alternative communication channel for cases where a technical impossibility prevents a financial entity from notifying the CSSF of a major ICT-related incident or a significant cyber threat through the indicated primary channel.

DORA’s classification and notification obligations under Articles 18 and 19, and the initial, intermediate and final report structure set out in the delegated and implementing standards, stay exactly as they were; the amendment addresses a narrow operational failure mode, not the timelines themselves. The scenario is straightforward: the reporting window is running and the usual submission route is down. The fallback channel gives an entity a defined route to the CSSF at that moment, providing certainty where the prior text left room for improvisation. Because this addition sits in the body of 25/893, it applies to every financial entity in that circular’s scope, not only to the branches that 26/915 brings in.

For a branch standing up its incident-reporting runbook for the first time, the fallback channel is worth writing into the procedure now, next to the primary submission path, so that a channel outage during a live incident does not turn into a missed notification.

Re-mapping the framework before the next ICT filing

The practical work is a controlled reclassification, and it is small if a branch already runs DORA processes at group level. The sequence is straightforward.

First, confirm the status of each Luxembourg establishment. For this Circular 26/915 re-mapping, the TCB category is limited to Luxembourg branches of the undertakings listed in points (a) to (j) of Chapter 1, with a head office in a third country that satisfies the DORA qualification condition stated in point (l). An establishment whose parent is in another EEA state does not go through this re-mapping, and neither does an entity that the CSSF supervises but that falls outside DORA altogether.

Second, retire the pre-DORA references. Remove 20/750 as the source for the branch’s ICT and security risk management, and stop treating the ICT-outsourcing Part II of 22/806 as live. Point the branch’s ICT risk documentation at DORA and at 25/882, 25/892 and 25/893 instead. Our DORA compliance checklist for Luxembourg firms is a useful cross-check for the DORA obligations a branch now inherits directly.

Third, review the third-party and register position under 25/882, covering ICT third-party arrangements and the register of information. Then confirm the incident-reporting setup under 25/893, including the new fallback channel, and check whether the branch clears or misses the microenterprise threshold that governs the 25/892 cost-estimation duty. For the proportionality logic that decides how heavy each control has to be, our note on DORA resilience testing for smaller firms sets out how size and complexity scale the requirements.

The CSSF annexed the corresponding amended pages of the seven circulars to 26/915 in track-changes form, so the relevant edits can be read directly against the prior text. That annex is the reference to keep open while the reclassification is documented.

Frequently Asked Questions

Does Circular 26/915 create new reporting obligations for third-country branches?

The circular is a scope instrument that confirms third-country branches are DORA financial entities and routes them to the correct Luxembourg circulars, with no new template or return introduced. The obligations brought into the branch mapping already existed for DORA entities: ICT third-party management under 25/882, cost estimation under 25/892 where the branch is not a microenterprise as defined in DORA Article 3(60), and incident reporting under 25/893. The only substantive addition is the fallback communication channel in 25/893.

Is the Luxembourg branch of a Swiss or US bank a third-country branch for this purpose?

Yes, provided the head-office undertaking in that third country would qualify as an entity listed under Article 2(1)(a) to (t) of DORA. Switzerland, the United Kingdom and the United States are third countries for DORA purposes, so a Luxembourg branch of a bank headquartered there is squarely the establishment the circular addresses.

What about a Luxembourg branch of a German or Irish bank?

That is an EEA branch, and it is not caught by this re-mapping. An EEA branch is supervised by its home Member State authority. For the 25/892 incident cost estimation, the CSSF expects such a branch to report its DORA estimations to its home authority on request, which places it outside the scope of the circular.

Does the DORA microenterprise carve-out help a small branch?

It helps for one specific obligation. Circular 25/892 excludes microenterprises as defined in DORA Article 3(60) from its scope. DORA Article 3(60) defines the threshold directly. The microenterprise exclusion from 25/892 does not by itself remove an in-scope TCB from Circulars 25/882 or 25/893.

We already report ICT incidents at group level. Does the branch report separately?

The branch is treated as a financial entity in scope of 25/893 in its own right, so its reporting position follows that circular and the DORA standards beneath it on its own account. A group may support the reporting process, and DORA allows a financial entity to outsource the reporting obligation to a third-party service provider, but the branch itself remains fully responsible for the fulfilment of its major-incident notifications within the applicable timelines; notification of significant cyber threats under DORA Article 19(2) is voluntary and is not subject to those major-incident reporting deadlines.

What happens to our existing cloud-outsourcing contracts under 22/806?

The specific contractual clause that 22/806 imposed on cloud providers, EEA-governing law and EEA resilience, was repealed from Circular 22/806 by Circular 25/883 to align with DORA’s own contractual regime. Cloud and other ICT service contracts should therefore be assessed against DORA’s contractual requirements and 25/882, while any non-ICT outsourcing continues under Part I of 22/806.

Is there a transition period before 26/915 bites?

No. Chapter 3 states the circular applies with immediate effect from its 27 August 2026 publication. There is no phase-in, so a branch that meets the definition should treat the DORA circulars as its governing framework from that date.

The DORA incident reporting framework behind Circulars 25/892 and 25/893 is covered in detail in our guide to DORA ICT Incident Reporting, which walks through classification and the initial, intermediate and final notification structure. The contractual register that 25/882 requires is detailed in the DORA Register of Information explainer. For context on how incident obligations have played out since DORA applied, the ESAs DORA ICT Incident Annual Report 2025 covers the first year of data. The CSSF AI Communiqué and DORA ICT Risk Management note addresses how the CSSF frames emerging ICT risks within the DORA framework, and the DORA Threat-Led Penetration Testing note covers the advanced testing regime for the largest in-scope entities.

Key Takeaways

Circular CSSF 26/915 applies with immediate effect from 27 August 2026 and amends seven circulars in a single instrument: 20/750, 22/806, 25/881, 25/882, 25/883, 25/892 and 25/893. Third-country branches leave Circular 20/750 in full and exit the ICT-outsourcing Part II of Circular 22/806, moving into the DORA-native circulars: 25/882 for ICT third-party services, 25/892 for incident cost estimation, and 25/893 for incident and cyber-threat reporting. For this Luxembourg re-mapping, a third-country branch is a Luxembourg branch of an undertaking whose head office is in a third country outside the EEA and that satisfies the scope test in Circular CSSF 26/915 by reference to DORA Article 2(1); Luxembourg branches of EEA-headquartered undertakings are treated separately. Point 9 of Circular 25/893 now includes a fallback communication channel for incident notification when the primary channel is technically unavailable, extending to all entities in the circular’s scope. Part I of Circular 22/806 continues to govern a branch’s non-ICT outsourcing, and the old EEA-law cloud contractual clause has been repealed from Circular 22/806 by Circular 25/883. Branches meeting DORA’s Article 3(60) microenterprise threshold fall outside the 25/892 cost-estimation duty, though they remain fully in scope of 25/882 and 25/893.

Sources and References

What TCB compliance teams do next

The action is a documented reclassification, due now with no future go-live to plan for. Confirm which Luxembourg establishments fall within the third-country-branch scope set by Circular CSSF 26/915, applying its head-office qualification test by reference to DORA Article 2(1), swap their ICT rulebook from 20/750 and the ICT half of 22/806 to 25/882, 25/892 and 25/893, and write the new fallback notification channel into the 25/893 incident procedure. Keep the track-changes annex to 26/915 open while that mapping is recorded, because it shows the exact edit to each circular.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • CSSF AIF and ELTIF Marketing Notification: What Luxembourg AIFMs Must File

    Updated July 2026In this guideThe current AIF and ELTIF marketing notification templateThe legal basis: AIFMD Article 31, Article 32, and ELTIF Article 31What belongs in a complete notification fileThe twenty working day clock and when marketing can startThe ELTIF dimension changes the investor baseMaterial changes, pre-marketing, and de-notification are different formsFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources…

  • APRA’s BEAR Case Against Bendigo: An $8m Cyber Accountability Test

    Bendigo and Adelaide Bank has admitted it breached its accountability obligations under the Banking Executive Accountability Regime (BEAR), and on 10 August 2026 the Australian Prudential Regulation Authority (APRA) filed civil penalty proceedings against it in the Federal Court. The parties have jointly proposed that the bank pay an $8 million pecuniary penalty, subject to…

  • CSSF AML/CFT Sanction: Enforcement Lessons From the March 2026 Fine

    Updated July 2026In this guideWhat the CSSF AML/CFT sanction actually coveredLate and incomplete suspicious activity reportsThe client-portfolio takeover trapName screening, sanctions and PEP alert backlogsOutsourced screening and the four-eyes gapDatabase completeness is an AML control, not IT housekeepingHow supervisors surface these gaps before an inspectionFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the sanction as a…

  • CSSF Remuneration Reporting: Who the Guide Really Covers

    Updated July 2026In this guideWhat the CSSF updated on 3 June 2026The legal basis: CRD Article 75 and IFD Article 34Who actually files CSSF remuneration reporting, and who does notThe high earners collection and the EUR 1 million thresholdWhere UCITS managers and AIFMs report remuneration insteadWhat to check before this cycle’s submissionFrequently Asked QuestionsRelated ArticlesKey…