Regulation (EU) 2022/2554

  • CSSF Circular 26/915: DORA Circulars Re-Mapped for Third-Country Branches

    On 27 August 2026 the CSSF published Circular 26/915, and it applies with immediate effect. Circular CSSF 26/915 updates the Luxembourg ICT and outsourcing circular framework following the European Commission position on DORA’s applicability to third-country branches. It removes the TCB categories within the CSSF’s remit from the relevant pre-DORA circular provisions and maps them…

  • DORA for Third-Country Branches in Luxembourg: Circular CSSF 26/915

    On 27 August 2026 the CSSF issued Circular CSSF 26/915, applicable with immediate effect, to bring specified third-country branches into the CSSF circular framework for DORA. For Luxembourg purposes, the governing scope is the branch perimeter set out in Circular CSSF 26/915 and in each amended circular; the change is not a blanket head-office-only test…

  • STAR-FS and DORA TLPT: Threat-Led Testing for Firms in Both Regimes

    A UK banking group with an EU financial entity identified by its competent authority for DORA threat-led penetration testing may be subject to STAR-FS in the UK and DORA TLPT in the EU at the same time. The Bank of England, the Prudential Regulation Authority and the Financial Conduct Authority maintain STAR-FS, the Simulated Targeted…

  • CSSF AI Communique: Mapping Frontier Cyber Risk to DORA

    On 7 July 2026 the Commission de Surveillance du Secteur Financier (CSSF) published a communique, “Evolving opportunities and risks in artificial intelligence and its adoption”, addressed to the entities it supervises. The CSSF AI communique responds to a specific concern: frontier AI models have the potential to shrink drastically the gap between vulnerability disclosure and…

  • DORA ICT-Risk Reporting: Reading KNF’s 2026 Cyber-Threat Report

    On 9 July 2026, CSIRT KNF, the cyber-incident response team inside Poland’s Financial Supervision Authority, refreshed its report on the cyber threats facing the Polish financial sector for 2026. The document reads like a briefing pack rather than a rulebook: the priority attack scenarios, the techniques criminals are stacking into single campaigns, and the risks…

  • ECB AI Cybersecurity Letter: The 31 October 2026 JST Action Plan

    On 7 July 2026, the Chair of the ECB Supervisory Board, Claudia Buch, wrote to the CEO of every significant institution under a letter numbered SSM-2026-0301 and titled “Addressing AI-enabled cybersecurity threats”. The ECB AI cybersecurity letter does one operationally concrete thing behind its strategic language: it gives each directly supervised bank until 31 October…

  • DORA ICT Incident Reporting: What the ESAs First Annual Report Reveals

    If your firm filed a major incident under DORA in 2025, that report has now been counted. On 3 June 2026 the three European Supervisory Authorities published their first annual report on major ICT-related incidents, putting a hard number on what used to be guesswork: how many major incidents the EU financial sector reports, where…