Luxembourg Financial Regulatory Advisory, Tools, Templates:
The Circular CSSF 26/915 establishes that the Digital Operational Resilience Act (DORA) officially applies to third-country branches (TCBs) operating within Luxembourg. This regulatory update follows a European Commission clarification confirming that these branches must meet the same ICT risk management and operational resilience standards as other financial entities. To ensure consistency, the CSSF has modified several existing circulars to remove TCBs from outdated frameworks and integrate them into new DORA-compliant requirements regarding third-party services and incident reporting. Additionally, the new guidance introduces a backup communication channel for reporting major technical disruptions if primary systems are unavailable. These changes aim to harmonize the security and outsourcing oversight of all relevant financial players regardless of their head office location. These administrative adjustments become effective immediately to align Luxembourg’s financial supervision with broader EU digital resilience laws.
Summary of Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
The Commission de Surveillance du Secteur Financier (CSSF) has issued Circular CSSF 26/915, which formalizes the application of the Digital Operational Resilience Act (DORA) to third-country branches (TCBs) operating in Luxembourg. This regulatory shift follows a December 2025 confirmation from the European Commission that TCBs fall within the scope of DORA if their head offices qualify as financial entities under the Act.
The primary objective of Circular CSSF 26/915 is to align the Luxembourgish regulatory framework with this interpretation by:
- Integrating TCBs into the scope of DORA-specific circulars.
- Removing TCBs from the scope of “pre-DORA” information and communication technology (ICT) and outsourcing circulars to avoid regulatory overlap.
- Establishing alternative notification channels for incident reporting during exceptional events where primary channels are technically unavailable.
This circular applies with immediate effect as of its publication date, August 27, 2026.
Regulatory Context and Scope of Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

The DORA Interpretation
While DORA provisions generally became applicable to financial entities on January 17, 2025, the specific status of TCBs was clarified later. Through an official DORA Q&A (ID: DORA102 – 3097), the European Commission confirmed that TCBs in an EU country are subject to DORA if their head office is established in a third country and would qualify as a financial entity under Article 2(1)(a) to (t) of the Regulation.
TCBs Considered Financial Entities
Under Circular CSSF 26/915, TCBs are considered financial entities subject to DORA if their head offices qualify under the following DORA classifications:
- Article 2(1)(a) to (i)
- Article 2(1)(k) to (m)
- Article 2(1)(p)
- Article 2(1)(r) and (s)
- Article 2(2)
Analysis of Circular Modifications under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
To ensure consistency and prevent conflicting requirements, the CSSF has modified several existing circulars. These changes are categorized into three primary actions: removal from legacy requirements, inclusion in DORA requirements, and alignment of amending circulars.
1. Removal from Pre-DORA Circulars
TCBs have been removed from the scope of older circulars to ensure they are governed exclusively by DORA-compliant frameworks for ICT and outsourcing.
| Circular Reference | Subject | Nature of Change |
| CSSF 20/750 | ICT and security risk management | Full removal of TCBs from scope. |
| CSSF 22/806 | Outsourcing arrangements | Removal of Part II (ICT outsourcing); Part I (non-ICT outsourcing) remains applicable. |
2. Inclusion in DORA-Related Circulars
TCBs are now explicitly included in the scope of circulars designed to implement DORA requirements in Luxembourg.
| Circular Reference | Subject | Key Requirements |
| CSSF 25/882 | ICT third-party services | Use of ICT third-party services for DORA entities. |
| CSSF 25/892 | Aggregated costs and losses | Estimation of annual costs/losses from major ICT incidents. |
| CSSF 25/893 | Incident reporting | Reporting of major ICT incidents and significant cyber threats. |
3. Alignment of Amending Circulars
The CSSF updated the circulars that originally modified legacy rules when DORA was first implemented. This ensures that the instructions for “pre-DORA” entities do not inadvertently apply to TCBs.
- Circular CSSF 25/881: Updated to remove TCBs from the amendments made to Circular CSSF 20/750.
- Circular CSSF 25/883: Updated to align the modifications of Circular CSSF 22/806, ensuring TCBs are only subject to non-ICT outsourcing rules under that specific circular.
Incident Reporting and Alternative Channels under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
A significant clarification provided in Circular CSSF 26/915 concerns the reporting of major ICT-related incidents and cyber threats.
Exceptional Notification Channel
The CSSF has modified Circular CSSF 25/893 (Point 9) to introduce an alternative communication channel. This channel is intended for use only in the event of technical impossibility. If a financial entity is unable to notify the CSSF through the prescribed primary channel due to an exceptional event, they must use this alternative method to ensure timely compliance with DORA’s reporting obligations.
Administrative Information under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
The CSSF provides dedicated contact points for entities seeking further clarification on these changes:
- General ICT Risk Supervision: ictrisksupervision@cssf.lu
- Third-Country Branches of Credit Institutions: banking_ict_risk@cssf.lu
- PSP ICT Assessment Inquiries: pspictassessment@cssf.lu
Circular CSSF 26/915 and its associated updates were finalized and released on August 27, 2026, with immediate applicability for affected entities.
This news related to Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg can be considered beneficial under CSSF-Circulars, Central Securities Depositories (CSDs) News, Credit Institutions News, Crowdfunding service providers (CSPs) News, Crypto-Assets Service Providers (CASPs) and Virtual Asset Service Providers (VASPs) News, Data Reporting Service Providers (DRSPs) News, EU Regulations, Explanation, IFMs (AIFMs, ManCos) News, Investment Firms News, Issuers of Tokens (EMTs, ARTs) News, Multimedia, Must Read, Opinion, Payment Institutions (PIs) / Electronic Money Institutions (EMIs) /AISPs News, Pension funds News, PFS/PSF News, Undertakings for collective investment (UCIs).
At https://Ratiofy.Lu/, we defend your hard-earned money with our free daily news platform and expert-vetted templates. Need more help? Request access to our hands-on expert Advisory, Training and Coaching Services (very limited availability) related to CSSF Circulars and EU Regulations.
The pre-filled example templates for many CSSF Circulars are available at https://ratiofy.lu/templates/ from the summer of 2026.
Beyond Borders: 4 Essential Takeaways from Luxembourg’s Strategic DORA Expansion under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg

The landscape of global financial regulation is notoriously complex, often leaving international firms to wonder how European Union mandates apply to their local outposts. While the Digital Operational Resilience Act (DORA) became applicable across the Union on 17 January 2025, the specifics for international entities remained a point of high-level discussion.
With the release of Circular CSSF 26/915 on 27 August 2026, the Commission de Surveillance du Secteur Financier (CSSF) has provided a definitive roadmap. This circular brings “Third-Country Branches” (TCBs)—branches of financial institutions headquartered outside the EU—firmly into the DORA fold. This update represents a fundamental shift in how international firms must manage digital risk in the Grand Duchy, moving beyond local metrics to a more holistic, global assessment of resilience.
1. The “Mirror Test”: Why Your HQ Now Defines Your Compliance under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
The most significant change introduced by Circular CSSF 26/915 is the adoption of a “qualitative” approach to determining compliance. Rather than looking at the size or specific activity of a Luxembourg branch in isolation, the regulator now examines the nature of the parent organization.
Following a crucial European Commission Q&A, the CSSF has established a “mirror test.” If a branch’s head office is established in a third country but would qualify as a financial entity under specific DORA categories if it were based in the EU, the Luxembourg branch is now subject to full DORA standards.
“On 17 December 2025, the European Commission confirmed, via an official DORA Q&A, that DORA is also applicable to third-country branches (“TCBs”) in an EU country, if in the third country where their head office is established, they would qualify as entities listed under Article 2(1)(a) to (t) of DORA.”
To be precise, the Luxembourg implementation targets TCBs whose head offices qualify under Article 2(1)(a) to (i), (k) to (m), (p), (r), and (s). By focusing on the nature of the head office, the CSSF ensures that non-EU firms cannot use local branches as “weak points” or regulatory havens within the European digital ecosystem.
2. The Great Regulatory Migration: Consolidating the Framework Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
To accommodate this expansion, the CSSF is performing a significant “regulatory cleanup” to avoid duplication and conflicting requirements. TCBs are being systematically removed from “pre-DORA” circulars, most notably Circular CSSF 20/750.
However, strategists should note a critical nuance: while TCBs are removed from the general scope of 20/750, those classified as Payment Service Providers (PSPs) must still attend to the “PSP ICT Assessment” form. For these specific requirements, firms should direct inquiries to pspictassessment@cssf.lu. Ideally, Circular CSSF 25/880 should apply for PSP ICT Assessment.
In place of the older framework, TCBs must now align with a new consolidated suite of DORA-related circulars:
- Circular CSSF 25/882: Requirements regarding the use of ICT third-party services.
- Circular CSSF 25/892: Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents.
- Circular CSSF 25/893: Procedures for reporting major ICT-related incidents and significant cyber threats.
3. Communication Resilience: The New Sanctioned Backup for Incident Reporting under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
A practical update found in the modification of Circular CSSF 25/893 concerns the reality of digital crises. The CSSF has introduced a specific “Plan B” for emergency communications by establishing an “alternative notification channel” to be used in cases of “technical impossibility.”
This provides a sanctioned backup for financial entities to notify the regulator if their primary prescribed communication channels are compromised. There is a pragmatic necessity in having a designated alternative for reporting a digital crisis; it is the ultimate mark of operational resilience to have a functional reporting path even when primary digital infrastructures fail.
4. BPO vs. ITO: Navigating the New Outsourcing Divide under Circular CSSF 26/915 on the applicability of the Digital Operational Resilience Act (DORA) to third-country branches in Luxembourg
For firms managing a complex web of vendors, Circular CSSF 26/915 introduces a critical distinction in how outsourcing is governed. The CSSF has modified Circular CSSF 22/806 to create a clear split between Information Technology Outsourcing (ITO) and Business Process Outsourcing (BPO):
- ITO (Information Technology Outsourcing): This moves almost entirely under the DORA umbrella. TCBs have been removed from “Part II” of the old outsourcing circular to ensure they follow DORA-aligned requirements for third-party ICT services.
- BPO (Business Process Outsourcing): These non-ICT arrangements (covered under “Part I”) remain subject to the existing rules in Circular CSSF 22/806.
This distinction is vital for Vendor Management Offices (VMOs). To prevent compliance gaps, firms must carefully categorize their third-party arrangements to ensure that ITO contracts meet DORA’s rigorous standards while BPO service contracts continue to satisfy the original requirements of the Grand Duchy’s outsourcing framework.
Conclusion: A Final Thought for the Global Resilience Era
Circular CSSF 26/915, which applies with immediate effect as of its August 2026 update, marks a milestone in the harmonization of EU financial standards. By integrating Third-Country Branches into the DORA framework, Luxembourg is ensuring that the “digital walls” protecting the financial sector are consistent, regardless of where an institution’s headquarters are located.
For firms requiring further technical clarification, the CSSF has provided direct lines of communication via ictrisksupervision@cssf.lu or banking_ict_risk@cssf.lu for TCBs of credit institutions.
As international firms begin the work of aligning their Luxembourg branches with these expectations, one question remains: Will the Luxembourgish approach of high-fidelity alignment with European Commission Q&As become the definitive blueprint for other EU regulators looking to secure their borders?




