{"id":"circulars/cssf-25-882","title":"Circular CSSF 25/882","type":"circular","date":"2025-04-09","kind":"circular","html":"<p>Circular CSSF 25/882 is a CSSF circular on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA), published 9 April 2025.</p>\n<p>Relevant for: AIFMs, AISPs, Central Securities Depositories (CSDs), Credit institutions, Crowdfunding service providers, Crypto-Assets Service Providers (CASPs), Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Investment fund managers, Issuers of ARTs, Issuers of E-Money Tokens (EMTs), Issuers of Tokens, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Payment institutions/electronic money institutions/AISPs, Pension funds.</p>\n<p>Main topic: DORA. Keywords: Cloud, Cybersecurity, Information and communications technology (ICT), Information security, Outsourcing.</p>\n<p>Amended by <a href=\"/lhoft?page=circulars%2Fcssf-26-915\" class=\"wikiLink\" data-target=\"circulars/cssf-26-915\">Circular CSSF 26/915</a>.</p>\n<h2>Text</h2>\n<p>on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)</p>\n<p>on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA) To all financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s), and within the meaning of Article 2(2) of Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) 1. To all third-country branches of financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s), and within the meaning of Article 2(2) of DORA, if in the third country where their head office is established, they would qualify as entities listed under Article 2(1) (a) to (t) of DORA.</p>\n<p>Luxembourg, 9 April 2025 Ladies and Gentlemen, As of 17 January 2025, the provisions of DORA are applicable to the financial entities supervised by the CSSF and in scope of DORA. The purpose of this circular is to provide them with practical instructions on the submission of certain information and reporting in relation to the use of ICT third-party providers and required under DORA. This circular also complements the DORA Regulation, notably by recalling certain general requirements regarding the use of ICT services 2 provided by third parties, considering notably the Luxembourg national laws related to financial services.</p>\n<p>1 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 2</p>\n<p>ICT services as defined in DORA Article 3(21)</p>\n<p>TABLE OF CONTENTS Chapter 1: Scope and general principles ............................................................................... 4 Sub-chapter 1.1. Scope .................................................................................................... 4 Sub-chapter 1.2. Use of a third-party for ICT operation services ............................................ 5 Sub-chapter 1.3. Backup of accounting positions ................................................................. 5 Chapter 2: DORA reporting obligations .................................................................................. 6 Sub-chapter 2.1.Notification of planned contractual arrangements regarding the use of ICT services supporting critical or important functions ................................................................ 6 Sub-chapter 2.2. Register of information ............................................................................ 7 Chapter 3: Use of ICT third-party cloud computing services ..................................................... 7 Sub-chapter 3.1. Definitions related to cloud computing ....................................................... 7 3.1.1. Specific terminology ........................................................................................... 7 3.1.2. Definition of “cloud computing” ............................................................................ 8 Sub-chapter 3.2. Cloud officer ......................................................................................... 10 Chapter 4: Date of application ........................................................................................... 11</p>\n<p>Chapter 1:</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-25-882/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf25_882eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}