{"id":"circulars/cssf-25-883","title":"Circular CSSF 25/883","type":"circular","date":"2025-04-09","kind":"circular","html":"<p>Circular CSSF 25/883 is a CSSF circular amending Circular CSSF 22/806 on outsourcing arrangements, published 9 April 2025.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F1993-04-05-n1\" class=\"wikiLink\" data-target=\"laws/1993-04-05-n1\">Law of 5 April 1993 on the financial sector</a>, <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>, <a href=\"/lhoft?page=laws%2F2010-12-17-n9\" class=\"wikiLink\" data-target=\"laws/2010-12-17-n9\">Law of 17 December 2010 on undertakings for collective investment</a>.</p>\n<p>Relevant for: AIFMs, AISPs, Central Securities Depositories (CSDs), Credit institutions, Crowdfunding service providers, Crypto-Assets Service Providers (CASPs), Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Investment fund managers, Issuers of ARTs, Issuers of E-Money Tokens (EMTs), Issuers of Tokens, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Payment institutions/electronic money institutions/AISPs, Pension funds, SICARs, Specialised PFS, Support PFS.</p>\n<p>Main topic: DORA. Keywords: Cloud, Cybersecurity, Information and communications technology (ICT), Information security, Outsourcing.</p>\n<p>Amends <a href=\"/lhoft?page=circulars%2Fcssf-22-806\" class=\"wikiLink\" data-target=\"circulars/cssf-22-806\">Circular CSSF 22/806</a>. Amended by <a href=\"/lhoft?page=circulars%2Fcssf-26-915\" class=\"wikiLink\" data-target=\"circulars/cssf-26-915\">Circular CSSF 26/915</a>.</p>\n<h2>Text</h2>\n<p>amending Circular CSSF 22/806 on outsourcing arrangements</p>\n<p>amending Circular CSSF 22/806 on outsourcing arrangements To all credit institutions and professionals of the financial sector within the meaning of the Law of 5 April 1993 on the financial sector (LFS) To all payment institutions and electronic money institutions within the meaning of the Law of 10 November 2009 on payment services (LPS) To all investment fund managers subject to Circular CSSF 18/698 To all undertakings for collective investment in transferable securities subject to Part I (UCITS) of the Law of 17 December 2010 relating to undertakings for collective investment (UCITS Law) which designate a management company within the meaning of the UCITS Law To all central counterparties (CCPs), including Tier 2 third-country CCPs, complying with the relevant requirements of EMIR To all approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation within the meaning of the LFS To all market operators operating a trading venue within the meaning of the LFS To all central securities depositories (CSDs) To all administrators of critical benchmarks</p>\n<p>Luxembourg, 9 April 2025</p>\n<p>Ladies and Gentlemen, As of 17 January 2025, the provisions of the Digital Operational Resilience Act 1 (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. DORA has introduced harmonised requirements on the use of ICT third-party services, including ICT outsourcing services which were also in the scope of Circular CSSF 22/806 on outsourcing. Consequently, to avoid duplication of requirements and to provide legal clarity to the market, the CSSF amends Circular CSSF 22/806 on outsourcing. This amendment reflects the CSSF's continued commitment to ensuring the effective management of ICT third-party risks within the financial sector while adhering to evolving European regulatory frameworks. This circular is to be read in conjunction with Circular CSSF 25/882 on requirements on the use of ICT third-party services for Financial Entities subject to DORA, which complements and provides practical instructions in relation to certain provisions of DORA. This circular amends Circular CSSF 22/806 by specifying the following: 1. the introduction has been modified to reflect the entry into application of DORA; 2. the definitions of Part I, Chapter 1 have been modified by adding a definition of DORA;</p>\n<p>Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011.</p>\n<ol start=\"3\">\n<li>the scope of application of Circular CSSF 22/806, as described in Part I, Chapter 2 has been modified to consider the entry into application of DORA: a.</li>\n</ol>\n<p>for financial entities as defined in Article 2 of DORA 2 and supervised by the CSSF, for which Circular CSSF 22/806 applied in full for all outsourcing arrangements: i. Part I of Circular CSSF 22/806 remains applicable for outsourcing arrangements other than ICT outsourcing; ii. Part II of Circular CSSF 22/806, related to ICT outsourcing arrangements, does not apply to them anymore.</p>\n<p>for entities falling under Circular CSSF 22/806 but not falling under DORA, and for which Circular CSSF 22/806 applies in full, the latter remains applicable for all outsourcing arrangements in its entirety (Part I and Part II);</p>\n<p>for financial entities as defined in Article 2 of DORA and supervised by the CSSF, for which Circular CSSF 22/806 applied in full only when performing ICT outsourcing, Circular CSSF 22/806 no longer applies. Those entities have been removed from the scope;</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-25-883/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf25_883eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}