DORA is directly applicable EU law, but a Luxembourg-regulated entity still has to reconcile it with a specific set of CSSF circulars that weren’t simply repealed when DORA arrived — some were amended, some narrowed in scope, and one new circular was created purely to handle DORA-entity notifications. Building the resilience programme means getting that reconciliation right.
DORA has applied since 17 January 2025. In April 2025, the CSSF published a package of updates addressing exactly how DORA interacts with its existing national circulars — amending Circular 22/806 on outsourcing, creating a new Circular 25/882 specifically for DORA entities’ ICT third-party notifications, and adopting new EBA guidelines on ICT and security risk management for payment service providers specifically. This is what a genuinely complete resilience programme needs to account for, beyond DORA’s own text.
Who this is for
- The CTO or head of ICT risk at a Luxembourg-regulated financial entity building or updating a DORA resilience programme.
- The compliance officer trying to determine which CSSF circulars still apply directly, and which have been superseded by DORA.
- The board member who assumed “we’re DORA compliant” closed every open CSSF-specific question.
What DORA replaced, and what it didn’t
Two CSSF circulars overlapped substantially with DORA: Circular 20/750 on ICT and security risk management, and Circular 22/806 on outsourcing arrangements. Rather than leaving both in force alongside DORA in full, the CSSF narrowed their application specifically to remove the overlap. Circular 22/806 as amended now applies to DORA entities only for business process outsourcing — its ICT outsourcing provisions have been repealed for those entities, replaced by DORA’s own third-party risk provisions and the new Circular 25/882. For non-DORA entities, 22/806 remains fully applicable for both business process and ICT outsourcing, unchanged in substance. A resilience programme needs to state, explicitly, which of these positions applies to the entity in question — this shouldn’t be an assumption carried forward from before the CSSF’s April 2025 clarification.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
The notification mechanics that changed
Circular 25/882 introduced a new notification form specifically for DORA entities, used to inform the CSSF of any planned contractual arrangement for ICT services supporting a critical or important function, and when an existing function becomes critical or important. Previously notified ICT outsourcing arrangements under the old 22/806 regime don’t need to be re-submitted, and arrangements already assessed as non-critical don’t need notifying — but any new critical arrangement, or reclassification of an existing one, needs the new form. Non-DORA entities continue using a separate, only lightly updated version of the previous form. A programme that hasn’t confirmed which form applies risks submitting the wrong one, or missing a notification obligation because it assumed an old exemption still held.
The Register of Information deadline discipline
The Register of Information for a given year must generally be submitted between 28 February and 31 March of the following year — though the CSSF has been explicit it reserves the right to request the register outside that window at any time. Treating this as a fixed annual deadline, without building in the capability to produce the register on demand year-round, misreads what the CSSF has actually said about its own expectations. The underlying data — every ICT third-party arrangement, mapped to the criteria DORA and the CSSF require — needs to be maintained as a living dataset, not assembled once a year in the run-up to the submission window.
Where GDPR sits in the same programme
Circular 22/806, even in its amended, narrowed form, still requires in-scope entities to comply with GDPR and with the requirements of Luxembourg’s data protection authority, the CNPD, for their third-party and outsourcing arrangements specifically. A DORA resilience programme built purely against DORA’s own text, without an explicit line connecting ICT third-party risk management to the entity’s GDPR and CNPD obligations, has a structural gap the circular itself flags directly.
What a complete programme actually contains
- A documented determination of DORA scope and the corresponding CSSF circular position — 22/806 as amended, 25/882, or both for different functions.
- ICT risk management, incident reporting, and third-party risk built to DORA’s Articles 6 through 30, with the CSSF-specific notification mechanics layered on top rather than treated as a separate process.
- A Register of Information maintained continuously as a live dataset, capable of being produced on request, not just assembled for the annual submission window.
- Explicit linkage between ICT third-party risk management and GDPR/CNPD obligations for the same arrangements.
- A clear, current answer to which notification form applies to which arrangement, reviewed against the April 2025 CSSF updates rather than an earlier version of the process.
Not every entity needs the full framework — but confirming that isn’t optional
DORA itself provides for a Simplified ICT Risk Management Framework for smaller, less complex entities, and threat-led penetration testing under Article 26 applies only to a subset of significant entities the CSSF and ESAs designate, not the whole regulated population. A Luxembourg fund administrator or management company shouldn’t assume the full DORA framework, including TLPT, applies by default — but equally shouldn’t assume it doesn’t without confirming its own designation status directly. This determination should be documented and revisited whenever the entity’s scale, complexity, or systemic significance changes, rather than assumed once and left unreviewed as the business grows.
Where the Simplified Framework does apply, it doesn’t remove the CSSF-specific obligations layered on top — the Register of Information submission, the 25/882 notification mechanics, and the GDPR/CNPD linkage all still apply regardless of which version of the ICT risk management framework itself the entity is building.
How we engage with this
We read DORA resilience programmes against both DORA’s own requirements and the CSSF’s specific reconciliation of them — including the April 2025 circular updates — as a Technology Control Review. The output is a written assessment identifying which regulatory position genuinely applies, and where the programme has gaps relative to it.
We don’t build the Register of Information submission. We don’t submit CSSF notifications on a client’s behalf. We don’t sell GRC software. We read what’s there, identify what’s missing, and write it down for the people who have to decide what to do about it.
Pricing is published at /pricing/. If your resilience programme hasn’t been reviewed against the CSSF’s April 2025 circular updates, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming