CSSF Prudential Reporting for PIs, EMIs and CASPs: The Move to eDesk

From 1 April 2027, a Luxembourg payment institution or electronic money institution still using the current Excel-based reporting process, or a crypto-asset service provider authorised under Article 63 of MiCAR, must submit the reports covered by the new CSSF prudential reporting framework through eDesk; the previous reporting process for those reports will be discontinued. On that date, eDesk becomes the sole official channel for the reports covered by the new framework; the communiqué does not state that every other regulatory or prudential filing of those entities moves to eDesk. The regulator set out the change in a communique published on 10 September 2026, together with a preparatory data-points annex.

Three populations sit inside this change, and they start from different places. Payment institutions and electronic money institutions already file recurring prudential tables, so for them the move is a migration of familiar returns into a new tool. Crypto-asset service providers authorised under MiCAR do not file those tables today, so for them the framework introduces a recurring prudential reporting obligation that did not exist before. Everyone in scope gets a testing window running from 1 January to 31 March 2027 before the tool becomes mandatory.

The legal plumbing matters here because it tells you what is being retired. A dedicated CSSF circular, still to be published, will replace Circulars CSSF 11/511 and 11/522, the instruments that currently govern periodic reporting by payment and electronic money institutions, and will add the CASP obligations. The reporting content is being consolidated at the same time as the channel changes, making this a data-mapping exercise as much as a portal switch. For a reporting officer the live question is one of timing: whether the mapping and the eDesk access are ready before the January test window opens.

Related reading: PSD3 and Luxembourg payment and e-money institutions

The calendar that governs the switch

Deadline pressure is the reason this topic cannot sit in a backlog. The communique fixes a short sequence of dates, and each one carries a different obligation.

  • 10 September 2026: the CSSF publishes the communique and Annex 1, the overview of data points and preparatory guidance for entities.
  • 1 January to 31 March 2027: the testing phase. Submissions made through eDesk in this window are test submissions only and carry no regulatory value.
  • Until 31 March 2027: the current channel remains mandatory for reports with a submission deadline falling on or before 31 March 2027. Reports with a submission deadline falling on or after 1 April 2027 must be submitted via eDesk, even if the reporting period ended before 1 April 2027.
  • From 1 April 2027: use of the eDesk interface becomes mandatory and the previous process is discontinued.

Read those dates by submission deadline. During 1 January to 31 March 2027, eDesk submissions are tests only, while reports due on or before 31 March remain on the current channel. From 1 April 2027, eDesk is the sole official channel for reports due on or after that date, including March 2027 monthly reports due in April and reports for the first quarter of 2027.

What changes in CSSF prudential reporting, from Excel tables to eDesk forms

Today a payment institution files Table Z 1.1 and Z 1.2 monthly, and Table Z 1.4 and Z 2.1 quarterly. An electronic money institution files Table W 1.1 and W 1.2 monthly; Table W 1.3, W 1.4 and W 2.1 quarterly; and Table W 4.5 yearly. The CSSF’s current legal-reporting page requires the basic reporting templates to be transmitted in .xls or .xlsx format.

The eDesk framework replaces the spreadsheet with dynamic online forms. The forms adapt to the entity: a payment institution sees a different set from an electronic money institution, an electronic money institution issuing e-money tokens sees fields a non-issuer does not, and an entity with foreign branches sees the branch-specific data points. The same platform also absorbs the recurring information requests that the CSSF describes as previously handled through separate manual processes, covering payment volumes, human resources, shareholding, branches and distributors.

This is where the change is larger than a file format. Under the current framework, PI and EMI Excel reporting files are transmitted electronically through the CSSF’s external reporting channels, currently eFile and Sofie/Atlas; the new framework replaces those spreadsheet submissions with eDesk forms. The regulator sets out its aims in plain terms: standardise the data collection, improve accuracy, automate integrity checks and cut the administrative burden of the separate manual requests. The CSSF says the new module will perform automated integrity checks before submission and will use real-time controls to flag inconsistencies or errors during data entry. The communiqué does not characterise the current process as an after-the-fact review or prescribe when an institution must perform its internal reconciliation.

Why CASPs are the new entrants in scope

The payment and e-money population is migrating something it already does. Crypto-asset service providers are being brought into recurring prudential reporting through this framework, and that is the part of the change most likely to surprise a compliance function that has spent 2025 and 2026 focused on getting authorised. Authorisation under Article 63 of the Markets in Crypto-Assets Regulation, Regulation (EU) 2023/1114, is the entry ticket. It does not discharge an ongoing reporting duty, and the CSSF communique states that the dedicated circular will introduce specific reporting obligations for CASPs authorised under that article.

For CASPs authorised under Article 63, the forthcoming circular will introduce specific reporting obligations through the new eDesk framework. The CSSF states that forms will be dynamic and tailored to licence type and entity characteristics, so only relevant sections will apply. CASPs have no legacy Table Z or Table W return to convert; the CASP-specific data points should therefore be taken from the finalised Annex 1 and the forthcoming circular rather than assumed to mirror the PI/EMI population.

MiCAR Article 67 requires a CASP to maintain prudential safeguards at all times equal to at least the higher of the applicable Annex IV permanent minimum capital amount, EUR 50,000, EUR 125,000 or EUR 150,000 depending on the services provided, and one quarter of the preceding year’s fixed overheads, reviewed annually. For a CASP that has been in business for less than one year from the date it began providing services, Article 67(2) uses the projected fixed overheads for the first 12 months submitted with the authorisation application. The safeguards may consist of own funds, an insurance policy covering the Union territories where services are provided, a comparable guarantee, or a combination. The CSSF communiqué separately states that financial information will form part of quarterly reporting; it does not state that this reporting is specifically the mechanism used to test Article 67 compliance.

The CSSF says the forms will be dynamic and tailored to the entity’s licence type, including PI, EMI with or without e-money-token issuance, or CASP, and to characteristics such as foreign branches. The communiqué does not state that individual payment-service permissions such as account information services are themselves form-selection keys.

The data points, and how often each is due

The communique sets the reporting frequencies by data family rather than by a single periodic return, and the split is worth reading closely because it does not match the current monthly-heavy cadence.

  • Quarterly: financial information and human resources, including resources dedicated to control functions.
  • Monthly: funds segregation, and only funds segregation.
  • Annual: shareholding structure, branches, agents and distributors.

Compare that to the present state. A payment institution files the Table Z 1.1 balance sheet monthly and the Table Z 1.2 third-party funds identification monthly today; an electronic money institution files the equivalent Table W tables on the same monthly cycle. Under the new framework the monthly obligation narrows to funds segregation, while the broader financial information moves to a quarterly rhythm. Assuming every data point keeps its old frequency is the second easy error, and it runs in both directions: some fields relax to quarterly, while the segregation data stays on the tightest cycle the framework has.

Annex 1 sets out the information expected under the new framework and provides preparatory guidance for certain data points. The CSSF states that the Annex is currently for information purposes only and that minor changes to labels and guidance may still occur. It can be used for advance preparation, but the communiqué does not state that every current spreadsheet cell has a one-to-one eDesk data-point mapping.

Manual eDesk or S3: choosing the submission route

The CSSF distinguishes an optional API connection for automated quantitative-data feeding from the two available submission options. Reports may be completed and submitted manually through the eDesk interface, or submitted automatically through S3 using a JSON file containing the Annex 1 data. The API is described as a mechanism for feeding quantitative data from an entity’s internal systems, not as a third submission route.

Manual completion and submission in eDesk is one of the two submission options. The other is automated submission via S3 using a JSON file containing the Annex 1 data. Separately, the CSSF says entities may use an optional API connection to feed quantitative data automatically from internal systems. Any automation build should therefore distinguish API data feeding from S3 submission and should be exercised during the January-to-March test window.

Using the 2027 testing window without dropping the live filing

The testing phase looks generous, three months, and that generosity hides a trap. Because test submissions carry no regulatory value, the current channel still has to be used for reports due on or before 31 March 2027. Reports due on or after 1 April 2027, including March 2027 monthly reports and reports for the first quarter of 2027, must be submitted through eDesk.

Used well, the window is where the mapping proves itself. A sensible sequence is to reproduce a recent live filing inside eDesk as a test, compare the figures the platform accepts and the integrity checks it raises against what the current process produced, and resolve every discrepancy while both systems are running side by side. The CSSF strongly encourages entities to test actively, and the value of that encouragement is entirely in whether a firm treats the window as a rehearsal with real data or as a box to tick.

What to prepare before 1 January 2027

Much of the preparation, including data mapping and source identification, can begin on the strength of the communiqué and Annex 1, but final implementation should be checked against the forthcoming circular and any updated CSSF guidance or Annex 1.

Start by pulling Annex 1 and mapping each data point to its current source, whether that is a Table Z or Table W cell, an HR record for the control functions, or a shareholding register. Confirm which sections of the dynamic form apply to the entity. The communiqué expressly identifies licence type, EMI status with or without e-money-token issuance, CASP status and characteristics such as foreign branches; it does not identify agents or account-information-service permissions as form-selection triggers. Decide whether submission will be manual through eDesk or automated via S3; if the optional API data feed and/or S3 automation will be used, scope that development so it is ready for the January test window. Line up eDesk access and the internal roles that will hold it, ensuring platform access reflects how preparation and submission responsibilities are split internally. Then use the first weeks of the test window to run a real filing through the tool and clear the exceptions it raises.

For crypto-asset service providers, one extra step sits ahead of the mapping: establishing what the recurring data actually is, since there is no prior return to copy. Reading the CASP-relevant rows of Annex 1 against the firm’s own books is the first build task, and it is better done in the autumn of 2026 than discovered in the test window.

Frequently Asked Questions

Does the new eDesk framework change what we report, or only how we submit it?

Both, to a degree. The channel change is clear: from 1 April 2027, PIs and EMIs move off the current Excel-based process, while Article 63 CASPs enter the new framework; reports may be submitted manually through eDesk or automatically via S3 using JSON. The content is also being reorganised, because a dedicated circular will replace Circulars CSSF 11/511 and 11/522 and set the data points and frequencies afresh, including a shift of financial information to a quarterly cadence and the narrowing of the monthly obligation to funds segregation. The mapping work is the substance of the change, and the portal is the delivery.

We are a CASP that only completed Article 63 authorisation recently. Are we really in scope for periodic reporting?

Yes. The communique states that the new circular introduces specific reporting obligations for crypto-asset service providers authorised under Article 63 of MiCAR. The CSSF has announced that the forthcoming circular will introduce specific reporting obligations for CASPs authorised under Article 63; because those CASPs have no legacy Table Z or W return to convert, the first task is to prepare against Annex 1 pending the final circular.

Can we skip the testing window if we are confident in our data?

Nothing in the communique makes testing a formal obligation, and the CSSF frames it as a strong encouragement rather than a requirement. The practical answer is that the window is the only chance to see the platform’s integrity checks against your real figures before those figures have regulatory value. Skipping it means the first live submission in April is also the first genuine test.

During the January to March 2027 test period, which submission counts as our official filing?

It depends on the submission deadline. A report due on or before 31 March 2027 remains an official filing through the current channel; eDesk submissions made during the test window are tests only. A report due on or after 1 April 2027 must be filed through eDesk, including March 2027 monthly reports and Q1 2027 reports due in April.

If we build an API or S3 connection, do we still need eDesk user access?

Access and role requirements for the optional API connection and automated S3 submission should be confirmed from the forthcoming circular or public eDesk user guidance before implementation. The communiqué confirms that the API may feed quantitative data from internal systems and that reports are submitted either manually in eDesk or automatically via S3 using JSON.

Where do these obligations sit relative to our AML and DORA reporting?

They are separate reporting obligations. Suspicious-transaction reporting to Luxembourg’s CRF is made through goAML. The DORA register of information is also a separate obligation, but the CSSF currently collects it through a dedicated eDesk procedure. The new PI/EMI/CASP prudential forms do not replace either process.

Key Takeaways

  • From 1 April 2027, eDesk becomes the sole official channel for the reports covered by the new framework for PIs, EMIs and CASPs authorised under Article 63 of MiCAR; the previous process for those reports is discontinued.
  • The testing window runs from 1 January to 31 March 2027 and eDesk submissions during that window have no regulatory value. Reports due on or before 31 March remain on the current channel; reports due on or after 1 April must go through eDesk.
  • Frequencies are set by data family: financial information and human resources, including resources dedicated to control functions, quarterly; funds segregation monthly; and shareholding structure, branches, agents and distributors annually.
  • For PIs and EMIs this is a migration of the Table Z and Table W returns; for CASPs authorised under Article 63 MiCAR it is a new recurring obligation with no legacy return to convert.
  • Annex 1, published 10 September 2026, is currently for information purposes only and minor label changes may still occur; use it to begin preparation but take CASP-specific data points from the finalised annex and forthcoming circular.
  • Choose between the two submission options identified by the CSSF: manual completion and submission in eDesk, or automated submission via S3 using JSON. Treat the optional API connection separately as a quantitative-data feeding feature.
  • A dedicated CSSF circular, still to be published, will replace Circulars CSSF 11/511 and 11/522 and set the CASP obligations.

Sources and References

  • CSSF, “Evolution of prudential reporting for payment institutions, electronic money institutions and crypto-asset service providers” (communique, 10 September 2026): cssf.lu
  • CSSF, Annex 1, “Overview of the data points to be reported and preparatory guidance for entities” (XLSX): cssf.lu XLSX
  • CSSF, “Legal reporting for AISP / e-money institution / payment institution” (current Table Z and Table W returns): cssf.lu
  • CSSF, File transport and data protection (external reporting channels, including eFile and Sofie/Atlas): cssf.lu
  • CSSF, Circular CSSF 11/511 (payment institutions): cssf.lu
  • CSSF, Circular CSSF 11/522 (electronic money institutions): cssf.lu
  • CSSF, “DORA – Submission timeframe for register of information – eDesk Portal open as of 11 February 2026” (communique, February 2026): cssf.lu
  • CSSF eDesk platform: edesk.apps.cssf.lu
  • CSSF, Crypto-Asset Service Providers (CASPs) sector page: cssf.lu
  • Regulation (EU) 2023/1114 on markets in crypto-assets (MiCAR), including Article 63 on CASP authorisation, Article 67 on CASP prudential requirements and Annex IV capital amounts, EUR-Lex: eur-lex.europa.eu

The build starts with Annex 1

The circular that will formalise the new framework has not yet been published. The communiqué and Annex 1 provide enough information to begin preparation, but the CSSF states that Annex 1 is currently for information purposes only and that minor changes to labels and guidance may still occur. The test window opens on 1 January 2027, and eDesk becomes mandatory for reports with submission deadlines falling on or after 1 April 2027.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts