{"id":"circulars/cssf-25-893","title":"Circular CSSF 25/893","type":"circular","date":"2025-05-27","kind":"circular","html":"<p>Circular CSSF 25/893 is a CSSF circular on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA), published 27 May 2025 and updated 28 May 2025.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: AIFMs, AISPs, Central Securities Depositories (CSDs), Credit institutions, Crowdfunding service providers, Crypto-Assets Service Providers (CASPs), Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Investment fund managers, Issuers of ARTs, Issuers of E-Money Tokens (EMTs), Issuers of Tokens, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Payment institutions/electronic money institutions/AISPs, Pension funds.</p>\n<p>Keywords: Cybersecurity, Information and communications technology (ICT), Information security.</p>\n<p>Amended by <a href=\"/lhoft?page=circulars%2Fcssf-26-915\" class=\"wikiLink\" data-target=\"circulars/cssf-26-915\">Circular CSSF 26/915</a>. Repeals <a href=\"/lhoft?page=circulars%2Fcssf-21-787\" class=\"wikiLink\" data-target=\"circulars/cssf-21-787\">Circular CSSF 21/787</a>.</p>\n<h2>Text</h2>\n<p>on reporting of major ICTrelated incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)</p>\n<p>on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) To all financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s), and within the meaning of Article 2(2) of Regulation (EU) 2022/2554 1 on digital operational resilience for the financial sector (hereafter “DORA”) and to all Payment Service Providers as referred to in Article 1(37) of the Law of 10 November 2009 on payment services (LPS). To all third-country branches of financial entities defined in Article 2(1)(a) to (i), (k) to (m), (p), (r) and (s), and within the meaning of Article 2(2) of Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (hereafter “DORA”), if in the third country where their head office is established, they would qualify as entities listed under Article 2(1) of Regulation (EU) 2022/2554 (DORA).</p>\n<p>Luxembourg, 27 May 2025 Ladies and Gentlemen, As defined in Articles 18(1), 18(2), 19(1) and 19(2) of DORA, financial entities subject to DORA are required to comply with the obligations for classifying and reporting major ICT-related incidents and, if applicable, significant cyber threats. The specifics regarding classification and reporting are detailed in the following Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS): •</p>\n<p>RTS on classification of ICT-related incidents and cyber threats 2 (hereafter “RTS on classification”), and</p>\n<p>RTS and ITS on incident and voluntary cyber threats reporting (hereafter “RTS on incident reporting” 3 and “ITS on incident reporting” 4)</p>\n<p>Furthermore, with this circular the CSSF requires Payment Service Providers (PSPs) that are not in the scope of DORA to follow the ICT-related incident and cyber threat classification and reporting procedures under DORA in order to fulfil the reporting requirements stipulated under Article 105-2</p>\n<p>1 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011</p>\n<p>2 Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents</p>\n<p>3 Commission Delegated Regulation (EU) 2025/301 of 23 October 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats 4 Commission Implementing Regulation (EU) 2025/302 of 23 October 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat</p>\n<p>of the LPS. As a simplification, these PSPs shall follow the DORA requirements for all ICT-related incidents (i.e. including ICT-related incident not related to payment services), so as to avoid a dual reporting scheme.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-25-893/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf25_893eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}