• About
  • Privacy Poilicy
  • Disclaimer
  • Contact
CoinInsight
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining
No Result
View All Result
CoinInsight
No Result
View All Result
Home Regulation

Luxembourg: CSSF aligns with DORA – Key updates on ICT and outsourcing rules

Coininsight by Coininsight
May 8, 2025
in Regulation
0
Luxembourg: CSSF aligns with DORA – Key updates on ICT and outsourcing rules
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

What the Knowledge Says and What Compliance Officers Have to Do About It

What the Knowledge Says and What Compliance Officers Have to Do About It

May 3, 2026
Main Overhaul or Finetuning Regulatory Options?: Evaluating the Influence of Regulatory Reductions Underneath Trump 2.0

Main Overhaul or Finetuning Regulatory Options?: Evaluating the Influence of Regulatory Reductions Underneath Trump 2.0

May 3, 2026


In short

On 9 April 2025, the Fee de Surveillance du Secteur Financier (CSSF) issued a number of new circulars associated to data and communication applied sciences (ICT) danger administration and the usage of ICT third events, aiming to align current circulars and practices with the Digital Operational Resilience Act (DORA). 

Key adjustments embrace amendments to Round CSSF 20/750 on ICT and safety danger administration and Round CSSF 22/806 on outsourcing preparations, together with the introduction of New Round CSSF 25/882 and Round CSSF 25/880.

These updates intention to scale back regulatory overlap, improve readability, and guarantee compliance with DORA, impacting ICT danger administration and outsourcing follow for each DORA and non-DORA entities supervised by the CSSF.


DORA entered into drive on 17 January 2025 and since then has been immediately relevant beneath Luxembourg legislation.

DORA enhances the monetary sector’s digital operational resilience by imposing new obligations on monetary entities and ICT service suppliers. It requires sturdy measures to handle and mitigate ICT dangers, structured round 5 key pillars: ICT danger administration and governance, ICT incident administration and reporting, digital operational resilience testing, technique for ICT third-party danger, and knowledge and intelligence sharing. 

On 2 July 2024, the Luxembourg legislation (“Regulation“) implementing DORA was printed within the Official Journal of the Grand Duchy of Luxembourg, designating the CSSF and the Commissariat aux Assurances (CAA) because the competent Luxembourgish authorities liable for its utility by the in-scope entities beneath their supervision.

ICT and safety danger administration

  • New Round CSSF 25/880: This round is addressed to all fee service suppliers (PSPs), each DORA and non-DORA entities. It adopts the brand new EBA Tips on ICT and safety danger administration, which intention to harmonize and supply the necessities for PSPs’ ICT evaluation. It additionally implements the reporting requirement on operational and safety dangers outlined within the Regulation of 10 November 2009 on fee companies.
  • Round CSSF 20/750: The Round CSSF 20/750 on ICT and safety danger administration stays relevant to non-DORA entities, with solely minor updates being made. The time period “PSPs” has been refined to be restricted to specialised PSPs, help PSPs, POST Luxembourg and third nation branches. DORA entities are explicitly out of scope of this round.

Outsourcing

  • Round CSSF 22/806: This round gives a complete framework for outsourcing preparations, together with ICT outsourcing. DORA has launched harmonized necessities for the usage of ICT third-party companies, together with ICT outsourcing, which overlap with Round CSSF 22/806.

To take away overlaps with DORA, Round CSSF 22/806 has been amended to use to DORA entities just for enterprise course of outsourcing, whereas ICT outsourcing necessities are already ruled by DORA. The amended round stays absolutely relevant to non-DORA entities for each enterprise course of and ICT outsourcing, and to administration corporations regarding undertakings for collective funding. Moreover, particular contractual clauses for cloud computing service suppliers have been repealed to align necessities between DORA and non-DORA entities.

  • New Round CSSF 25/882: The CSSF has launched Round CSSF 25/882, detailing necessities for the usage of ICT third-party companies for DORA entities. This round outlines necessities for the usage of ICT third-party companies, together with reporting obligations and sustaining a register of data. It additionally retains some components from Round CSSF 22/806 that aren’t lined by DORA however stay essential for compliance.

To totally adjust to the CSSF updates, in-scope entities beneath its supervision should do the next:

  • Assessment and replace ICT Threat Administration procedures to make sure alignment with the brand new EBA Tips and the necessities set out in Round CSSF 25/880.
  • Adjust to the applied reporting necessities outlined in Article 105-1(2) of the Regulation of 10 November 2009 on fee companies.
  • Assessment and amend outsourcing agreements to adjust to the up to date necessities in Round CSSF 22/806 and the brand new Round CSSF 25/882, notably for ICT outsourcing.
Tags: alignsCSSFDORAICTKeyLuxembourgoutsourcingRegulationsUpdates
Share76Tweet47

Related Posts

What the Knowledge Says and What Compliance Officers Have to Do About It

What the Knowledge Says and What Compliance Officers Have to Do About It

by Coininsight
May 3, 2026
0

  I've spent a big period of time in Japan over the previous decade, assembly with compliance leaders at totally...

Main Overhaul or Finetuning Regulatory Options?: Evaluating the Influence of Regulatory Reductions Underneath Trump 2.0

Main Overhaul or Finetuning Regulatory Options?: Evaluating the Influence of Regulatory Reductions Underneath Trump 2.0

by Coininsight
May 3, 2026
0

by Catie Garcia, Christina Guerrero-Gomez, and Bhargav Tata From left to proper: Catie Garcia, Christina Guerrero-Gomez, and Bhargav Tata Earlier...

AI Act reforms stall as EU misses deal, with August deadline looming

AI Act reforms stall as EU misses deal, with August deadline looming

by Coininsight
May 2, 2026
0

After greater than 12 hours of negotiations in Brussels, EU lawmakers have walked away with out settlement on proposed modifications...

United States: New York LLC Transparency Act

United States: New York LLC Transparency Act

by Coininsight
May 1, 2026
0

Briefly The New York LLC Transparency Act (“Act“) grew to become efficient as of January 1, 2026. Though there was...

Regulatory Compliance: Navigating Office Modifications

Regulatory Compliance: Navigating Office Modifications

by Coininsight
May 1, 2026
0

New office legal guidelines emerge, present laws broaden, and steerage evolves as regulators make clear expectations.  For HR and compliance groups, the fixed...

Load More
  • Trending
  • Comments
  • Latest
MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

MetaMask Launches An NFT Reward Program – Right here’s Extra Data..

July 24, 2025
Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

Finest Bitaxe Gamma 601 Overclock Settings & Tuning Information

November 26, 2025
Easy methods to Host a Storj Node – Setup, Earnings & Experiences

Easy methods to Host a Storj Node – Setup, Earnings & Experiences

March 11, 2025
BitHub 77-Bit token airdrop information

BitHub 77-Bit token airdrop information

February 6, 2025
Kuwait bans Bitcoin mining over power issues and authorized violations

Kuwait bans Bitcoin mining over power issues and authorized violations

2
The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

The Ethereum Basis’s Imaginative and prescient | Ethereum Basis Weblog

2
Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

Unchained Launches Multi-Million Greenback Bitcoin Legacy Mission

1
Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

Earnings Preview: Microsoft anticipated to report larger Q3 income, revenue

1
SUI Holds Close to $0.92 as CME Futures Launch Tomorrow, Charts Sign Warning

SUI Holds Close to $0.92 as CME Futures Launch Tomorrow, Charts Sign Warning

May 3, 2026
Prediction: these FTSE 100 and FTSE 250 trusts can beat the market in 5 years

Am I loopy to contemplate this dangerous FTSE 100 financial institution inventory over Rolls-Royce shares?

May 3, 2026
Technique (MSTR) Pops 9% As Bitcoin Value Will get Again To $78k

Technique (MSTR) Pops 9% As Bitcoin Value Will get Again To $78k

May 3, 2026
AAVE Value Prediction: $80 Breakdown Imminent Earlier than December Restoration to $120

AAVE Value Prediction: $80 Breakdown Imminent Earlier than December Restoration to $120

May 3, 2026

CoinInight

Welcome to CoinInsight.co.uk – your trusted source for all things cryptocurrency! We are passionate about educating and informing our audience on the rapidly evolving world of digital assets, blockchain technology, and the future of finance.

Categories

  • Bitcoin
  • Blockchain
  • Crypto Mining
  • Ethereum
  • Future of Crypto
  • Market
  • Regulation
  • Ripple

Recent News

SUI Holds Close to $0.92 as CME Futures Launch Tomorrow, Charts Sign Warning

SUI Holds Close to $0.92 as CME Futures Launch Tomorrow, Charts Sign Warning

May 3, 2026
Prediction: these FTSE 100 and FTSE 250 trusts can beat the market in 5 years

Am I loopy to contemplate this dangerous FTSE 100 financial institution inventory over Rolls-Royce shares?

May 3, 2026
  • About
  • Privacy Poilicy
  • Disclaimer
  • Contact

© 2025- https://coininsight.co.uk/ - All Rights Reserved

No Result
View All Result
  • Home
  • Bitcoin
  • Ethereum
  • Regulation
  • Market
  • Blockchain
  • Ripple
  • Future of Crypto
  • Crypto Mining

© 2025- https://coininsight.co.uk/ - All Rights Reserved

Social Media Auto Publish Powered By : XYZScripts.com
Verified by MonsterInsights