COFREP Validation Rules: The CSSF List Banks Must Recheck
On 21 July 2026, the CSSF updated its COFREP guidance workbook to add the EBA small validation rules package dated 10 June 2026. The workbook states that this package applies to credit institution reports submitted to the CSSF from 15 July 2026. It identifies the applicable EBA package and links to the EBA source material; it does not list individual validation-rule IDs or, by itself, establish that a triggered validation may be disregarded.
COFREP is the CSSF label for the COREP and FINREP prudential returns that credit institutions file in XBRL under the EBA implementing technical standards. The EBA validation-rules material records the current status and severity of individual rules. The CSSF workbook records which EBA validation-rule package applies to reports submitted to the CSSF and links to the relevant EBA material; it is not an individual-rule register.
Related reading: EBA Validation Rules for Supervisory Reporting
The dates that govern your next submission
Four dates carry the operational weight of this update.
- 10 June 2026: the EBA published its latest quarterly small validation rules package (the micro taxonomy package plus the DPM validation rule update scripts).
- 15 July 2026: the date from which the CSSF applies that package to reports submitted to it, for credit institution reports only.
- 21 July 2026: the modification date recorded in the English and French COFREP workbooks.
- 20 January 2026: the applicability date of the final entry in the legacy deactivated-rules sheet, after which newer deactivations moved to a separate sheet.
The EBA released the package on 10 June 2026, while the CSSF workbook states that it applies to reports submitted to the CSSF from 15 July 2026. Use the CSSF submission-applicability date when determining which validation-rule package governs a filing; do not treat it as a reporting-reference-date condition.
What the CSSF changed in the COFREP validation rules list
The page carries two spreadsheets, one English and one French, each about 14 kilobytes and holding the same two sheets. The first, “Deactivated EBA rules”, is a running log back to 19 May 2014 recording every EBA validation-rule revision the CSSF has recognised, alongside the date the CSSF applies it. The second, “Micro taxonomy packages”, tracks the EBA small validation rules packages and is marked as applying to credit institution reports only.
The substantive change on 21 July was a single new row in that second sheet: the 10 June 2026 EBA package, applicable to CSSF reports as from 15 July 2026. The sheet previously held one entry, the 10 March 2022 package applied from 18 March 2022. The footprint is narrow, but this is the package governing the checks that run against reports filed right now.
Why a deactivated rule is safe to ignore
An EBA validation rule is an automated test that compares reported data and flags a potential inconsistency. When the applicable EBA material shows that a rule is deactivated, that rule alone should not be treated as evidence that the reported value is wrong. Deactivation does not confirm that the underlying data are correct: the institution must still test the data against the applicable reporting instructions, active validation rules and its other data-quality controls.
The deactivation leaves the reporting obligation untouched. The current supervisory-reporting ITS is Commission Implementing Regulation (EU) 2024/3117, as amended by Commission Implementing Regulation (EU) 2025/2475, adopted under Articles 415 and 430 CRR. Limited market-risk provisions of Implementing Regulation (EU) 2021/451 continue to apply until 31 December 2026. Withdrawing a validation rule changes the automated check, not the obligation to report the underlying data under the applicable templates and instructions. Our guide to common COREP reporting errors covers the difference between a real data fault and a false flag.
The two sheets, and the one that now matters most
The design of the file has shifted, which is the trap for anyone who bookmarked the old view. The “Deactivated EBA rules” sheet was historically the single place to look: each time the EBA issued a revised list of validation rules, the CSSF added a row. That log now stops at the EBA revision of 13 January 2026, applied from 20 January 2026, with a note directing readers to the “Micro taxonomy packages” sheet for later deactivations.
From early 2026, the newest deactivations live in that small-packages sheet, keyed to the EBA small validation rules packages page rather than the general reporting-frameworks page. A reporting officer who checks only the first sheet sees nothing after January and wrongly concludes that no rules have been deactivated since. Both sheets are current; the second is where fresh entries land. Read the file as two lists together.
What an EBA small validation rules package contains
The EBA revises validation rules through two channels. An updated validation rules package appears roughly two months before the first reference date of a new framework release. A small validation rules package appears every quarter, around 10 March, 10 June, 10 September and 10 December, about 20 days before the end-of-quarter reference date. A small package can deactivate rules, reactivate rules previously switched off, or change a rule’s severity status, for example between a blocking error and a warning. The EBA publishes separate validation-rules files for framework releases from 4.0 onward and for releases up to 3.5; each file reflects the latest published state for its release range.
Two boundaries are worth holding. Small packages apply to the framework releases covered by the EBA’s two-file split: releases from 4.0 onward and releases up to and including 3.5, so older archived frameworks fall outside them. From release 4.0 onward, the EBA publishes these packages so the deactivation applies consistently in both the XBRL taxonomy and the data point model. The current EBA framework for these returns is 4.2, with DPM 4.2.1 uploaded on 27 February 2026. For defects that sit alongside these checks, see our explainer on the EBA DPM known issues list.
Where this bites in the CSSF filing workflow
Luxembourg credit institutions submit COREP and FINREP through the dedicated eDesk Bank Prudential Reporting procedure or by automated S3 transfer. For framework 4.2 reports using a .json entry point, the CSSF requires an XBRL-CSV report package in accordance with the EBA filing rules and the CSSF XBRL User Guide. A ZIP containing one .xbrl instance file applies to XBRL-XML reports using a .xsd entry point. Since 1 April 2025 the CSSF no longer accepts these returns through the older external channels. Validation runs when the report is processed. The CSSF applicability date identifies the EBA package used for the submission; it does not itself determine whether the report is accepted. Acceptance depends on the validation results and their severity, together with any required correction or warning explanation.
When a validation fails, first use the CSSF workbook to identify the EBA package applicable to the submission date, then open the linked EBA validation-rules material and check the individual rule’s status and severity there. The CSSF workbook itself contains package dates and links, not individual rule IDs. Under EBA validation practice, an ERROR flag indicates a validation failure that requires analysis before deciding whether the reported data require correction and resubmission; a WARNING indicates a lower-severity finding that may require resolution or explanation. The CSSF reporting calendar for Q3 2026 sets the remittance dates that make this triage time-sensitive around quarter-end.
Where teams get this wrong
One misstep is to treat the deactivation list as broader than it is. It covers credit institution COFREP returns submitted to the CSSF, and the small-packages sheet says so explicitly, so reusing it to justify ignoring a flag in a different collection over-reads it. The opposite error assumes a rule stays active because it fired: severity status changes, and a check that blocked last quarter may have been downgraded to a warning, or switched off, in the 10 June package. Re-pull the current CSSF list each quarter rather than working from a cached copy, because the point of the small-package channel is that the state moves between releases. Our overview of how COREP reporting works sets out where these checks sit in the wider return.
Frequently Asked Questions
Does the deactivation of a validation rule remove my obligation to report the underlying figure?
No. The current reporting requirements are principally set by Commission Implementing Regulation (EU) 2024/3117, as amended by Implementing Regulation (EU) 2025/2475, under Articles 415 and 430 CRR. Limited market-risk provisions of Implementing Regulation (EU) 2021/451 remain applicable until 31 December 2026. Deactivating a validation rule changes the automated check, not the obligation to submit complete and accurate data under the applicable requirements.
Which date decides whether a deactivation applies to my Luxembourg submission?
Use the date in the CSSF column headed “Applicability for reports submitted to the CSSF”, rather than the EBA publication date. For the EBA package dated 10 June 2026, the workbook gives 15 July 2026. This is a submission-applicability date, not a reporting-reference-date condition.
Who does the COFREP deactivation list cover?
The small-packages sheet is marked as applying to credit institution reports only. It is the reference for Luxembourg credit institutions filing COREP and FINREP to the CSSF, and should not be assumed to apply to other entity types or reporting collections.
Why does the deactivated-rules spreadsheet appear to stop in January 2026?
The “Deactivated EBA rules” sheet ends at the EBA revision of 13 January 2026, applied from 20 January 2026, and points readers to the “Micro taxonomy packages” sheet for later deactivations. Both sheets are current; the newest deactivations sit in the second one.
What can a small validation rules package change?
It can deactivate a validation rule, reactivate one previously switched off, or change a rule’s severity status, such as moving it between a blocking error and a warning. The EBA issues these packages quarterly, around 10 March, 10 June, 10 September and 10 December, roughly 20 days before the end-of-quarter reference date.
Related Articles
- EBA Validation Rules for Supervisory Reporting – how the EBA validation-rule framework is built and revised across releases.
- COREP Reporting Explained – the structure, templates and reference dates of the COREP return.
- FINREP Reporting Explained – the financial reporting return that files alongside COREP under the same ITS.
- Common COREP Reporting Errors – distinguishing genuine data faults from false validation flags.
- EBA DPM Known Issues List – the companion track for acknowledged framework defects awaiting correction.
Key Takeaways
- The CSSF’s English and French COFREP workbooks were modified on 21 July 2026 to add the EBA small validation rules package of 10 June 2026.
- That package applies to reports submitted to the CSSF as from 15 July 2026, for credit institution reports only.
- A deactivated rule should not be used alone as evidence that the reported value is wrong, but deactivation does not confirm that the underlying data are correct; test the data against the applicable instructions and active controls before deciding whether an amendment is required.
- The CSSF submission-applicability date, not the EBA publication date, determines which EBA validation-rule package applies to a report submitted to the CSSF.
- The newest deactivations sit in the “Micro taxonomy packages” sheet; the older “Deactivated EBA rules” sheet stops at 20 January 2026 and points readers onward.
Sources and References
- CSSF, Deactivated validation rules and EBA small validation packages COFREP (page published 19 May 2014; linked workbooks modified 21 July 2026).
- CSSF, Deactivated validation rules and EBA small validation packages COFREP (XLSX).
- EBA, Reporting frameworks (updated and small validation rules packages).
- EBA, Small validation rules packages.
- CSSF, Prudential reporting for credit institutions.
- CSSF, New transmission method for EBA ITS reports.
- Commission Implementing Regulation (EU) 2024/3117, as amended by Commission Implementing Regulation (EU) 2025/2475, current consolidated ITS on supervisory reporting of institutions (EUR-Lex).
Reading the flag before you edit the file
The value of this small update is the sequence it enforces. When a COFREP submission fails, use the CSSF workbook to identify the package applicable on the submission date, then consult the linked EBA material for the individual rule’s status and severity before deciding whether the reported data require correction. Correcting data solely because a deactivated rule fired can create unnecessary rework, while dismissing an active rule without checking its severity and the underlying reporting instructions can leave the report not accepted. Recheck the applicable package each quarter because a rule’s activation or severity can change between packages.
Last updated: July 2026
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.