← Luxembourg

Reminder regarding ICT-related incident reporting requirements

Obsah (5)Article 2Article 27Article 4Article 25Article 20

Published on 25 July 2025 Email this Share this on LinkedIn Share this on Facebook Communiqué Reminder regarding ICT-related incident reporting requirements In response to recent events that have rece

the obligation to submit ICT-related incident notifications in line with the relevant provisions outlined in Circular CSSF 25/893 and/or Circular CSSF 24/847. Supervised entities are strongly encouraged to thoroughly review the applicable provisions to ensure a clear and comprehensive understanding

the reporting obligations. This includes knowing which types

ICT-related incidents trigger mandatory notification, the specific thresholds that apply, the required timelines for submission and the proper procedures for reporting through the designated channels. While certain incidents may be publicly known or reported by the press, the CSSF emphasises that such public knowledge does not exempt supervised entities from their obligation to report these incidents. Supervised entities are expected to act in accordance with the established requirements without delay. 5 January 2024 Circular CSSF 24/847 on ICT-related incident reporting framework Communiqué

5 January 2024 CSSF circular PDF (300.89Kb) PDF (213.33Kb) 28 May 2025 Circular CSSF 25/893 on reporting

major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) CSSF circular PDF (207.99Kb) PDF (148.31Kb) Relevant for Central Securities Depositories (CSDs) Credit institutions Crowdfunding service providers Crypto-Assets Service Providers (CASPs) Data Reporting Service Providers (DRSPs) Investment firms Investment fund managers Payment institutions/electronic money institutions/AISPs Pension fund Specialised PFS Support PFS Circulaire CSSF 24/847 sur le cadre de notification des incidents liés aux TIC CIRCULAIRE CSSF 24/847 En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 24/847 sur le cadre de notification des incidents liés aux TIC À toutes les Entités Surveillées au sens des lois modifiées et des règlements suivants, tels que précisés au point 2 : - la loi du 5 avril 1993 sur le secteur financier - la loi du 15 décembre 2000 sur les services financiers postaux - la loi du 10 novembre 2009 relative aux services de paiement - la loi du 17 décembre 2010 concernant les organismes de placement collectif - la loi du 12 juillet 2013 relative aux gestionnaires de fonds d’investissement alternatifs - la loi du 15 mars 2016 relative aux produits dérivés de gré à gré, aux contreparties centrales et aux référentiels centraux - la loi du 17 avril 2018 relative aux indices de référence - la loi du 6 juin 2018 relative aux dépositaires centraux de titres - la loi du 28 mai 2019 relative aux réseaux et aux systèmes d’information - la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers Luxembourg, le 5 janvier 2024 Mesdames, Messieurs, La présente circulaire vise à introduire un nouveau cadre de notification des incidents liés aux TIC en vue d’obtenir une meilleure vue d’ensemble plus structurée de la nature, de la fréquence, de l’importance et des conséquences des incidents liés aux TIC, en prenant également en compte le risque croissant lié aux TIC et à la sécurité dans le contexte d’un système financier mondial fortement interconnecté. Les dispositions de la présente circulaire se fondent sur l’article 53, paragraphe 1, de la loi modifiée du 5 avril 1993 relative au secteur financier (ci-après la « LSF »), l’article 31, paragraphe 4, de la loi modifiée du 10 novembre 2009 relative aux services de paiement (ci-après la « LSP »), l’article 2 de la loi modifiée du 15 décembre 2000 sur les services financiers postaux, l’article 147 de la loi modifiée du 17 décembre 2010 concernant les organismes de placement collectif (ci-après la « Loi OPCVM »), l’article 50 de la loi modifiée du 12 juillet 2013 relative aux gestionnaires de fonds d'investissement alternatifs (ci-après la « Loi GFIA »), l’article 2, paragraphe 1, de la loi modifiée du 15 mars 2016 relative aux produits dérivés de gré à gré, aux contreparties centrales et aux référentiels centraux (ci-après la « Loi EMIR »), l’article 2, paragraphe 1, de la loi du 17 avril 2018 relative aux indices de référence (ci-après la « Loi relative aux indices de référence »), l’article 2 de la loi du 6 juin 2018 relative aux dépositaires centraux de titres (ci-après la « Loi DCT »), et l’article 20-16 de la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers. Conformément à l’article 3 de la loi du 28 mai 2019 relative aux réseaux et aux systèmes d’information (ci-après la « Loi SRI »), la CSSF est également l’autorité compétente en termes de sécurité des réseaux et de l’information pour les établissements de crédit et les infrastructures des marchés financiers qui ont été identifiés en tant qu’opérateurs de services essentiels (ci-après les CIRCULAIRE CSSF 24/847 « OSE »), ainsi que pour les fournisseurs de services numériques (ci-après les « FSN ») qui sont déjà soumis à la surveillance de la CSSF (ci-après l’« autorité SRI »). L’objectif de la présente circulaire est de fixer les détails et modalités pratiques en matière d’obligations de notification prévues à l’article 8, paragraphes 4 et 5, à l’article 9, paragraphe 1, à l’article 11, paragraphes 3 et 4, et à l’article 12 de la Loi SRI et au règlement CSSF N° 24-01 relatif à la notification des incidents selon la loi du 28 mai 2019 1 (ci-après le « Règlement CSSF N° 24-01 ») notamment en ce qui concerne l’article 8, paragraphe 5, et l’article 11, paragraphe 3, de la Loi SRI. La présente circulaire apporte les modifications suivantes au mécanisme actuel de notification des incidents : • élargissement de la couverture des incidents qui est actuellement limitée à la fraude et aux incidents dus à des attaques informatiques externes conformément à la circulaire CSSF 11/504, en couvrant plus largement les incidents opérationnels et de sécurité liés aux TIC tout en évitant la double notification pour les incidents à notifier en vertu d’autres cadres de notification des incidents ; • introduction de notifications reposant sur la classification. Les Entités Surveillées seront tenues de classifier les incidents liés aux TIC sur base des critères énoncés dans la présente circulaire et de notifier à la CSSF les cas d’incidents liés aux TIC qui sont classifiés en tant qu’incidents majeurs ou significatifs ; • introduction d’un nouveau formulaire de notification d’incidents. Afin d’obtenir les données de manière structurée, les Entités Surveillées seront tenues de compléter et de soumettre un formulaire de notification d’incidents liés aux TIC au cas où l’incident lié aux TIC est classifié en tant qu’incident majeur ou significatif ; • introduction d’un chapitre spécifique pour couvrir dans la même circulaire les exigences en matière de notification d’incidents (précédemment communiqué de manière bilatérale aux Entités Surveillées qui tombent sous le champ d’application de la Loi SRI) en vue d’appliquer le nouveau formulaire de notification d’incidents et les exigences pratiques aux notifications d’incidents évalués comme significatifs en vertu de la Loi SRI. La présente circulaire est divisée en quatre chapitres : • Le chapitre 1 (Définitions et champ d’application) fixe les définitions applicables aux fins de la présente circulaire et établit le champ d’application ; • Le chapitre 2 (Exigences générales) établit les exigences pour la classification et les notifications d’incidents liés aux TIC ; • Le chapitre 3 (Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01) est dédié aux exigences spécifiques pour les Entités Surveillées qui sont soumises à la Loi SRI et au Règlement CSSF N° 24-01 et qui sont définies comme OSE ou FSN ; • Le chapitre 4 (Date d’application) prévoit l’entrée en vigueur de la présente circulaire. Règlement CSSF N° 24-01 du 5 janvier 2024 relatif à la notification des incidents selon la loi du 28 mai 2019 portant transposition de la directive (UE) 2016/1148 du Parlement européen et du Conseil du 6 juillet 2016 concernant des mesures destinées à assurer un niveau élevé commun de sécurité des réseaux et des systèmes d’information dans l’Union européenne. 1 CIRCULAIRE CSSF 24/847 TABLE DES MATIÈRES Chapitre 1 : Définitions et champ d’application ....................................................................... 5 Section 1.1 : Définitions .................................................................................................... 5 Section 1.2 : Champ d’application ...................................................................................... 7 Chapitre 2 : Exigences générales .......................................................................................... 8 Section 2.1 : Incidents à notifier ........................................................................................ 8 Section 2.2 : Classification des incidents liés aux TIC ............................................................ 9 Section 2.3 : Notification d’incidents majeurs liés aux TIC ..................................................... 9 Chapitre 3 : Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01 ......... 11 Section 3.1 : Notifications d’incidents par les Entités Surveillées qui sont également des OSE .. 11 Section 3.2 : Notifications d’incidents par les Entités Surveillées qui sont également des FSN .. 11 Chapitre 4 : Date d’application ........................................................................................... 12 CIRCULAIRE CSSF 24/847 Chapitre 1 : Définitions et champ d’application Section 1.1 : Définitions 1. Aux fins de la présente circulaire, on entend par 2: a) « Réseaux et systèmes d’information » : i. un réseau de communications électroniques au sens de l’article 2, point 1°, de la loi du 17 décembre 2021 sur les réseaux et les services de communications électroniques 3 ; ii. tout dispositif ou tout ensemble de dispositifs interconnectés ou apparentés, dont un ou plusieurs éléments assurent, en exécution d’un programme, un traitement automatisé de données numériques ; ou iii. les données numériques stockées, traitées, récupérées ou transmises par les éléments visés aux points i. et ii. ci-dessus en vue de leur fonctionnement, utilisation, protection et maintenance. b) « Sécurité des réseaux et des systèmes d’information » : la capacité des réseaux et des systèmes d’information de résister, à un niveau de confiance donné, à des actions qui compromettent la disponibilité, l’authenticité, l’intégrité ou la confidentialité des données stockées ou transmises ou faisant l’objet d’un traitement, ou des services que ces réseaux et systèmes d’information

frent ou rendent accessibles.

  1. c)« Incident lié aux TIC » : un événement unique ou une série d’événements liés entre eux que l’Entité Surveillée n’a pas prévu, qui compromet la sécurité des réseaux et des systèmes d’information, et a une incidence négative sur la disponibilité, l’authenticité, l’intégrité ou la confidentialité des données ou sur les services fournis par l’Entité Surveillée.
  2. d)« Incident majeur lié aux TIC » : un incident lié aux TIC qui a une incidence négative élevée sur les réseaux et les systèmes d’information qui soutiennent les fonctions critiques ou importantes de l’Entité Surveillée.
  3. e)« Fonction critique ou importante » : une fonction dont la perturbation est susceptible de nuire sérieusement à la performance financière d’une Entité Surveillée, ou à la solidité ou à la continuité de ses services et activités, ou une interruption, une anomalie ou une défaillance de l’exécution de cette fonction qui est susceptible de nuire sérieusement à la capacité d’une Entité Surveillée de respecter en permanence les conditions et obligations de son agrément, ou ses autres obligations découlant des dispositions applicables des lois relatives aux services financiers. 2 Les définitions aux points 1.
  4. f)à 1.
  5. i)sont spécifiques aux Entités Surveillées soumises aux exigences de la Loi SRI et du Règlement CSSF N° 24-01. 3 Un « réseau de communications électroniques » : les systèmes de transmission, qu’ils soient ou non fondés sur une infrastructure permanente ou une capacité d’administration centralisée et, le cas échéant, les équipements de commutation ou de routage et les autres ressources, y compris les éléments de réseau qui ne sont pas actifs, qui permettent l’acheminement de signaux par câble, par la voie hertzienne, par moyen optique ou par d’autres moyens électromagnétiques, comprenant les réseaux satellitaires, les réseaux fixes (avec commutation de circuits ou de paquets, y compris l’internet) et mobiles, les systèmes utilisant le réseau électrique, pour autant qu’ils servent à la transmission de signaux, les réseaux utilisés pour la radiodiffusion sonore et télévisuelle et les réseaux câblés de télévision, quel que soit le type d’information transmise. CIRCULAIRE CSSF 24/847
  6. f)« Opérateur de services essentiels » (« OSE ») : conformément à l’article 2, point 3°, de la Loi SRI, une entité publique ou privée dont le type figure à l'annexe de la Loi SRI et 4 qui répond aux critères énoncés à l'article 7, paragraphe 2, de la Loi SRI .
  7. g)« Fournisseur de service numérique » (« FSN ») : conformément à l’article 2, point 5°, de la Loi SRI, une entité privée qui fournit un service numérique, tel que défini à l’article 5 2, point 4°, de la Loi SRI .
  8. h)« Service essentiel » : un service qui est essentiel au maintien d'activités sociétales et/ou économiques critiques et qui est listé en tant que service essentiel à l’article 2 du 6 règlement CSSF N° 20-04 du 15 juillet 2020 .
  9. i)« Incident significatif » : un incident qui a un impact significatif sur la continuité des services essentiels fournis par un OSE ou sur la prestation d’un service numérique par un FSN 7 au sein de l’Union européenne. Aux fins de la présente circulaire, un incident significatif est considéré par défaut comme « incident majeur lié aux TIC ». 2. Les entités suivantes sont à considérer comme Entités Surveillées dans le cadre de la présente circulaire :
  10. a)les établissements de crédit et les professionnels du secteur financier au sens de la LSF ;
  11. b)les dispositifs de publication agréés (« APA ») avec une dérogation et les mécanismes de déclaration agréés (« ARM ») avec une dérogation au sens de la LSF ;
  12. c)les établissements de paiement et les établissements de monnaie électronique au sens de la LSP ;
  13. d)POST Luxembourg régi par la loi du 15 décembre 2000 sur les services financiers 8 postaux ;
  14. e)les sociétés de gestion de droit luxembourgeois soumises au chapitre 15 de la Loi OPCVM ;
  15. f)les sociétés de gestion de droit luxembourgeois soumises aux articles 125-1 ou 125-2 du chapitre 16 de la Loi OPCVM ;
  16. g)les succursales luxembourgeoises de gestionnaires de fonds d'investissement soumis au chapitre 17 de la Loi OPCVM ;
  17. h)les sociétés d’investissement qui n’ont pas désigné une société de gestion au sens de l’article 27 de la Loi OPCVM ; 4 En sa qualité d’autorité SRI, la CSSF a déjà notifié les Entités Surveillées concernées de leur identification en tant qu’OSE lorsque la Loi SRI est entrée en vigueur. La CSSF confirmera à nouveau le statut d’OSE aux Entités Surveillées concernées au plus tard le 1er mars 2024. Les Entités Surveillées qui n’ont pas reçu cette notification à la date prévue ne sont donc pas désignées comme OSE sans préjudice d’une possible désignation ultérieure. 5 En sa qualité d’autorité SRI, la CSSF a déjà informé les Entités Surveillées concernées qu’elles sont considérées comme FSN lorsque la Loi SRI est entrée en vigueur. La CSSF confirmera à nouveau le statut de FSN aux Entités Surveillées concernées au plus tard le 1er mars 2024. Les Entités Surveillées qui n’ont pas reçu cette information à la date prévue ne sont donc pas considérées comme FSN sans préjudice d’une possible information ultérieure. 6 Règlement CSSF N° 20-04 du 15 juillet 2020 relatif à la définition des services essentiels selon la loi du 28 mai 2019 portant transposition de la directive (UE) 2016/1148 du Parlement européen et du Conseil du 6 juillet 2016 concernant des mesures destinées à assurer un niveau élevé commun de sécurité des réseaux et des systèmes d’information dans l’Union européenne. 7 Définition en ligne avec la Loi SRI. Par souci de clarté, le terme « services financiers postaux » a la même signification qu’à l’article 1 de la loi modifiée du 15 décembre 2000. 8 CIRCULAIRE CSSF 24/847
  18. i)les gestionnaires de fonds d’investissement alternatifs agréés au titre du chapitre 2 de la Loi GFIA ;
  19. j)les fonds d’investissement alternatifs à gestion interne au sens de l’article 4, paragraphe 1, point b), de la Loi GFIA ;
  20. k)les contreparties centrales (« CCP ») au sens de l’article 2, paragraphe 1, du Règlement 9 EMIR , y compris les contreparties centrales de pays tiers de catégorie 2 au sens de l’article 25, paragraphe 2bis, du Règlement EMIR, qui respectent les exigences applicables du Règlement EMIR conformément à l’article 25, paragraphe 2ter, point a), du Règlement EMIR ;
  21. l)les dépositaires centraux de titres au sens de la Loi DCT ;
  22. m)les administrateurs d’indices de référence d’importance critique au sens de l’article 20, paragraphe 1, point b), du Règlement sur les indices de référence 10 ;
  23. n)les prestataires de services de financement participatif au sens de la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers ;
  24. o)les établissements de crédit et les infrastructures des marchés financiers pour lesquels la CSSF est l’autorité compétente, en vertu de l’article 3 de la Loi SRI, en termes de sécurité des réseaux et de l’information et qui ont été identifiés en tant qu’OSE ;
  25. p)les PSF de support agréés conformément à l’article 29-3 de la LSF pour lesquels la CSSF est l’autorité compétente, en vertu de l’article 3 de la Loi SRI, en termes de sécurité des réseaux et de l’information et qui ont été informés par la CSSF qu’ils sont considérés comme FSN conformément à la Loi SRI. Section 1.2 : Champ d’application 3. La présente circulaire définit les attentes prudentielles à respecter dans le cas d’un incident lié aux TIC. 4. Les dispositions du chapitre 2 (Exigences générales) de la présente circulaire s’appliquent à toutes les Entités Surveillées, telles que définies au point 2.
  26. a)à
  27. n)ci-dessus, ci-après dénommées collectivement « Entités Surveillées » ou individuellement « Entité Surveillée », y compris leurs succursales telles que précisées dans les lois respectives. Les succursales au Luxembourg d’entités ayant leur siège social dans un pays tiers sont réputées être incluses dans la notion d’Entité Surveillée. 5. Les succursales au Luxembourg d’entités qui font partie d’une entité juridique dont le siège social est situé dans un État membre de l’Espace économique européen (EEE) différent (succursales EEE) sont soumises à la surveillance de l’autorité compétente de cet État membre (État membre d’origine). Cependant, la CSSF étant compétente pour veiller à ce que les succursales EEE respectent les exigences spécifiques prévues dans les cadres légaux 9 Règlement (UE) n° 648/2012 du Parlement européen et du Conseil du 4 juillet 2012 sur les produits dérivés de gré à gré, les contreparties centrales et les référentiels centraux. 10 Règlement (UE) 2016/1011 du Parlement européen et du Conseil du 8 juin 2016 concernant les indices utilisés comme indices de référence dans le cadre d’instruments et de contrats financiers ou pour mesurer la performance de fonds d’investissement et modifiant les directives 2008/48/CE et 2014/17/UE et le règlement (UE) n° 596/2014. CIRCULAIRE CSSF 24/847 et réglementaires sectoriels 11, la présente circulaire s’applique si un incident lié aux TIC a une incidence sur les domaines pour lesquels la CSSF conserve une responsabilité de contrôle. 6. Les dispositions du chapitre 3 (Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01) de la présente circulaire sont applicables uniquement aux Entités Surveillées qui sont également des OSE4 ou des FSN5. 7. Afin d’éviter la double notification, les Entités Surveillées tombant dans le champ d’application de la présente circulaire ne sont pas tenues de notifier, en vertu de la présente circulaire, les incidents qu’elles notifient conformément à :
  28. a)la circulaire CSSF 21/787 concernant l’application des Orientations de l’EBA (EBA/GL/2021/03) sur la notification des incidents majeurs en vertu de la directive DSP2 ; et/ou
  29. b)le cadre de notification des cyberincidents pour les Entités Surveillées définies en tant qu’établissements d’importance significative tombant sous la supervision directe de la BCE ; et/ou
  30. c)l’article 45, paragraphe 6, du règlement (UE) n° 909/2014 relatif à la notification d’incidents résultant de risques que les participants clés, les prestataires de services et les fournisseurs de services de réseau, les autres dépositaires centraux de titres (« DCT ») ou les autres infrastructures de marché sont susceptibles de représenter pour les activités de DCT ; et/ou
  31. d)l’article 71, paragraphe 4, point b), du règlement délégué (UE) 2017/392 de la Commission du 11 novembre 2016 complétant le règlement (UE) n° 909/2014 relatif à la notification d’incidents opérationnels importants à l’autorité compétente. 8. Par dérogation au point 7 ci-dessus, les Entités Surveillées tombant sous le point 7.
  32. b)et qui sont également des OSE sont tenues, conformément à la présente circulaire, de notifier à la CSSF les incidents qui ont un impact sur la continuité des services essentiels qu’elles fournissent, en sus de leurs autres obligations en matière de notification d’incidents. Chapitre 2 : Exigences générales Section 2.1 : Incidents à notifier 9. Les Entités Surveillées doivent notifier les incidents suivants conformément à la procédure définie à la section 2.3 :
  33. a)tout accès malveillant non autorisé réussi aux réseaux et systèmes d’information. Aux fins de la présente circulaire, ces accès malveillants non autorisés réussis sont à considérer comme incidents majeurs liés aux TIC ;
  34. b)tout incident autre que ceux visés au point
  35. a)ci-dessus, classifié conformément à la section 2.2 en tant qu’incident majeur lié aux TIC. 11 Notamment dans le cadre de services d’investissement conformément à la loi modifiée du 30 mai 2018 relative aux marchés d’instruments financiers (ci-après la « Loi MiFID »), la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme (ci-après la « Loi LBC/FT »), la fourniture de services de gestion de portefeuille et l’exercice de tâches de dépositaire pour les organismes de placement collectif établis au Luxembourg. CIRCULAIRE CSSF 24/847 Section 2.2 : Classification des incidents liés aux TIC 10. Les Entités Surveillées doivent classifier les incidents liés aux TIC et évaluer leur incidence sur base des critères suivants :
  36. a)le nombre et/ou la pertinence des clients 12 ou des contreparties financières affectés et, le cas échéant, le montant ou le nombre de transactions affectées par l’incident lié aux TIC et si cet incident a porté atteinte à la réputation ;
  37. b)la durée de l’incident lié aux TIC, y compris les interruptions de service ;
  38. c)la répartition géographique en ce qui concerne les zones touchées par l’incident lié aux TIC, en particulier si celui-ci touche plus de deux États membres ;
  39. d)les pertes de données occasionnées par l’incident lié aux TIC en ce qui concerne la disponibilité, l’authenticité, l’intégrité ou la confidentialité ;
  40. e)la criticité des services touchés, y compris les transactions et les opérations de l’Entité Surveillée ;
  41. f)les conséquences économiques, en particulier les coûts et pertes directs et indirects, en termes absolus et relatifs, de l’incident lié aux TIC. 11. Lorsque l’évaluation interne de l’Entité Surveillée fondée sur les critères énoncés au point 10 conduit l’Entité Surveillée à classifier un incident lié aux TIC en tant qu’incident majeur, l’incident lié aux TIC doit être considéré comme majeur en vertu de la présente circulaire. 12. Lorsque l’évaluation visée au point 11 ne permet pas de conclure clairement si un incident lié aux TIC est à classifier comme majeur, les Entités Surveillées doivent notifier l’incident lié aux TIC à la CSSF. 13. Les Entités Surveillées doivent classifier l’incident lié aux TIC rapidement après la détection de l’incident lié aux TIC et sans délai indu suivant la disponibilité de l’information requise pour la classification de l’incident lié aux TIC aux Entités Surveillées, mais pas plus tard que 24 heures suivant la détection de cet incident lié aux TIC. Si un délai plus long est nécessaire pour classifier l’incident lié aux TIC, les Entités Surveillées doivent en expliquer les raisons dans la notification initiale soumise à l’autorité compétente. Lorsque le délai pour la classification tombe un jour de fin de semaine ou un jour férié, les Entités Surveillées peuvent classifier l’incident le jour ouvrable suivant. Section 2.3 : Notification d’incidents majeurs liés aux TIC 14. Les Entités Surveillées doivent soumettre à la CSSF, endéans les délais fixés à l’annexe I, les notifications suivantes relatives aux incidents majeurs liés aux TIC :
  42. a)Une notification initiale avec des « Informations initiales » lorsque l’incident lié aux TIC a été classifié comme majeur.
  43. b)Une notification intermédiaire avec « Causes, classification et incidence de l’incident » après la notification initiale visée au point 14.a), suivi, le cas échéant, de notifications actualisées chaque fois qu’une mise à jour pertinente est disponible, ainsi que sur demande spécifique de la CSSF. 12 Les Entités Surveillées qui sont également des OSE doivent prendre en considération le nombre d’utilisateurs touchés par la perturbation du service essentiel. Les Entités Surveillées qui sont également des FSN doivent prendre en considération le nombre d'utilisateurs touchés par l'incident, en particulier ceux qui recourent au service numérique pour la fourniture de leurs propres services. CIRCULAIRE CSSF 24/847
  44. c)Une notification finale, lorsque l’analyse des causes originelles est terminée, que des mesures d’atténuation aient été mises en œuvre pleinement ou non, et lorsque les chiffres relatifs aux incidences réelles sont disponibles en lieu et place des estimations. Dans cette notification, les Entités Surveillées peuvent ajouter tout suivi ou informations complémentaires qu’elles jugent utiles pour l’incident lié aux TIC. 15. Lorsque l’incident lié aux TIC s’avère avoir ou pourrait avoir une grave incidence (par exemple, l’indisponibilité totale des systèmes), l’Entité Surveillée doit notifier la CSSF dès que possible endéans le délai fixé et, le cas échéant, avant la soumission formelle du formulaire de notification. 16. Les notifications concernant les incidents liés aux TIC visées au point 14 doivent être soumises à l’aide du formulaire correspondant disponible via la solution numérique de la CSSF, telle que précisée sur le site Internet de la CSSF. 17. Les Entités Surveillées doivent compléter la section pertinente du formulaire de notification, en fonction de la phase dans laquelle elles se trouvent (c.-à-d. la section « Informations initiales » (Initial Information) pour les notifications initiales, la section « Causes, classification et incidence de l’incident » (Incident cause, classification and impact) pour les notifications intermédiaires et la section « Causes originelles - suivi et informations complémentaires » (Root cause – Follow-up and additional information) pour les notifications finales). Le formulaire de notification contient des champs de données prévus à l’annexe II (uniquement disponible en anglais). 18. Les sections du formulaire de notification doivent être soumises dans l’ordre indiqué sous le point 14. Si l’Entité Surveillée dispose de toutes les informations requises au moment de la notification initiale, une seule soumission (contenant toutes les sections du formulaire de notification) doit être faite. 19. Les Entités Surveillées doivent également notifier à l’autorité compétente lorsque, en raison de l’évaluation continue de l’incident lié aux TIC, il a été déterminé qu’un incident lié aux TIC déjà notifié ne remplit plus les critères pour être considéré comme majeur et il est présumé que l’incident lié aux TIC ne les remplit pas avant sa résolution. Dans ce cas, les Entités Surveillées doivent reclassifier l’incident lié aux TIC dès que cette circonstance est identifiée et fournir une explication des raisons justifiant cette reclassification à la section « Informations initiales » du formulaire de notification. 20. Les Entités Surveillées peuvent externaliser les obligations de déclaration prévues par le présent chapitre à un prestataire tiers. Dans le cas d’une telle externalisation, l’Entité Surveillée reste pleinement responsable du respect des exigences en matière de déclaration des incidents liés aux TIC endéans les délais applicables et pour le contenu complet des déclarations des incidents. CIRCULAIRE CSSF 24/847 Chapitre 3 : Exigences spécifiques en vertu de la Loi SRI et du Règlement CSSF N° 24-01 Section 3.1 : Notifications d’incidents par les Entités Surveillées qui sont également des OSE 21. Conformément à l’article 8, paragraphe 4, de la Loi SRI, les Entités Surveillées qui sont également des OSE doivent notifier à la CSSF, sans retard injustifié, les incidents qui ont un impact significatif sur la continuité des services essentiels qu’elles fournissent. On considère que la notion de « sans retard injustifié » est considérée comme respectée lorsque les Entités Surveillées soumettent leur notification d’incident conformément aux délais indiqués à la section 2.3 (Notification d’incidents majeurs liés aux TIC) et à l’annexe I. 22. À cet égard, conformément à l’article 8, paragraphe 5, de la Loi SRI et au Règlement CSSF N° 24-01, les Entités Surveillées qui sont également des OSE doivent évaluer si l’incident est à classifier en tant qu’incident significatif en appliquant mutatis mutandis les exigences énoncées à la section 2.2 (Classification des incidents liés aux TIC) et doivent notifier les incidents significatifs conformément aux exigences énoncées à la section 2.3 (Notification d’incidents majeurs liés aux TIC). 23. Les accès malveillants non autorisés réussis doivent être considérés par défaut comme des incidents significatifs et doivent être notifiés conformément aux exigences énoncées à la section 2.3 (Notification d’incidents majeurs liés aux TIC). 24. Lorsqu’un incident est classifié en tant qu’incident significatif et en tant qu’incident majeur lié aux TIC (par exemple, l’incident impacte aussi bien les services essentiels en vertu de la Loi SRI que les autres fonctions critiques ou importantes), les Entités Surveillées qui sont également des OSE doivent notifier l’incident une seule fois et indiquer dans leur notification que l’incident est également notifié en vertu de la Loi SRI. Section 3.2 : Notifications d’incidents par les Entités Surveillées qui sont également des FSN 25. L’article 11, paragraphe 3, de la Loi SRI et le Règlement CSSF N° 24-01 indiquent que les FSN doivent notifier à l’autorité compétente, sans retard injustifié, les incidents ayant un impact significatif sur la fourniture d’un service numérique qu’ils

frent dans l’Union européenne. On considère que la notion de « sans retard injustifié » est considérée comme respectée lorsque les Entités Surveillées soumettent leur notification d’incident conformément aux délais indiqués à la section 2.3 (Notification d’incidents majeurs liés aux TIC) et à l’annexe I. 26. Les Entités Surveillées qui sont également des FSN doivent :

  1. a)évaluer si un incident (y compris des accès malveillants non autorisés réussis, tels que définis au point 9.
  2. a)de la section 2.1) est à classifier en tant qu’incident significatif conformément aux articles 3 et 4 du règlement d’exécution (UE) 2018/151 de la CIRCULAIRE CSSF 24/847 Commission du 30 janvier 2018 13 portant précision de l’article 11, paragraphe 4, de la Loi SRI ;
  3. b)appliquer mutatis mutandis les points 12 et 13 de la section 2.2 (Classification des incidents liés aux TIC) ;
  4. c)notifier les incidents significatifs conformément aux exigences énoncées à la section 2.3 (Notification d’incidents majeurs liés aux TIC). 27. Lorsqu’un incident est classifié en tant qu’incident significatif et en tant qu’incident majeur lié aux TIC, les Entités Surveillées qui sont également des FSN doivent notifier l’incident une seule fois et indiquer dans leur notification que l’incident est également notifié en vertu de la Loi SRI. Chapitre 4 : Date d’application 28. La présente circulaire entre en vigueur le 1er avril 2024 pour les Entités Surveillées telles que définies au point 2.
  5. a)à
  6. d)et
  7. k)à
  8. p)de la section 1.1, et le 1er juin 2024 pour les Entités Surveillées telles que définies au point 2.
  9. e)à
  10. j)de la section 1.1. La présente circulaire abrogera et remplacera la circulaire CSSF 11/504 concernant les fraudes et incidents dus à des attaques informatiques externes le 1er avril 2024 pour les Entités Surveillées telles que définies au point 2.
  11. a)à
  12. d)et
  13. k)à
  14. p)de la section 1.1, et le 1er juin 2024 pour les Entités Surveillées telles que définies au point 2.
  15. e)à
  16. j)de la section 1.1. Claude WAMPACH Directeur Françoise KAUTHEN Directeur Annexes Marco ZWICK Directeur Jean-Pierre FABER Directeur Claude MARX Directeur général I. Délais et explications concernant la soumission de notifications II. Champs de données (uniquement en anglais) 13 Règlement d’exécution (UE) 2018/151 de la Commission du 30 janvier 2018 portant modalités d'application de la directive (UE) 2016/1148 du Parlement européen et du Conseil précisant les éléments à prendre en considération par les fournisseurs de service numérique pour gérer les risques qui menacent la sécurité des réseaux et des systèmes d'information ainsi que les paramètres permettant de déterminer si un incident a un impact significatif. CIRCULAIRE CSSF 24/847 Annexe I : Délais et explications concernant la soumission de notifications Section pertinente à remplir et à Délais Notes explicatives Classification de l’incident en tant que majeur Classification de l’incident en tant que majeur Endéans les 24 heures après la détection de l’incident lié aux TIC Rappel du point 15 : Lorsque l’incident lié aux TIC s’avère avoir ou soumettre N/A Lorsque le délai pour la classification tombe un jour de fin de semaine ou un jour férié, les Entités Surveillées peuvent classifier l’incident le jour ouvrable suivant. INFORMATIONS INITIALES pourrait avoir une grave incidence (par exemple, l’indisponibilité totale des systèmes), l’Entité Surveillée doit notifier la CSSF dès que possible endéans le délai fixé et, le cas échéant, avant la soumission formelle du formulaire de notification. Endéans les 4 heures après la classification de l’incident en tant que majeur La Lorsque le délai pour la notification tombe un jour l’incident qui doivent être incluses dans la de fin de semaine ou un jour férié, les Entités section « INFORMATIONS INITIALES » comprend les informations générales concernant notification lors de la première soumission. Surveillées peuvent notifier l’incident le jour ouvrable suivant. CAUSES, CLASSIFICATION ET INCIDENCE DE Endéans L’INCIDENT soumission des INFORMATIONS INITIALES à la les 3 jours ouvrables après la La INCIDENCE section « CAUSES, CSSF description plus détaillée de l’incident, de ses DE CLASSIFICATION L’INCIDENT » fournit ET une conséquences et des mesures correctives prises pour la résolution. Si l’Entité Surveillée peut mettre à jour des rapports antérieurs (concernant le même incident), une version actualisée de la section du formulaire peut être soumise. CIRCULAIRE CSSF 24/847 13/24 CAUSES ORIGINELLES - SUIVI INFORMATIONS COMPLÉMENTAIRES ET Endéans les la La section « CAUSES ORIGINELLES - SUIVI ET CAUSES, INFORMATIONS COMPLÉMENTAIRES » fournit les CLASSIFICATION ET INCIDENCE DE L’INCIDENT informations concernant l’analyse des causes soumission 20 jours à la ouvrables CSSF des après originelles, les enseignements tirés et toute autre information pertinente. Lors de la soumission de ces informations, l’Entité Surveillée doit examiner les autres sections du formulaire et les mettre à jour, le cas échéant. CIRCULAIRE CSSF 24/847 14/24 Annexe II : Champs de données (uniquement en anglais) Section – Initial Information Data Field description / Question Field type Proposed options Alphanumeric 1. Contact person within the supervised entity for updates: Name and surname 1. Contact person within the supervised entity for updates: Email Alphanumeric (email format) 1. Contact person within the supervised entity for updates: Phone Number (telephone format) 2. Second contact person within the supervised entity for updates: Name and surname Alphanumeric 2. Second contact person within the supervised entity for updates: Email Alphanumeric (email format) 2. Second contact person within the supervised entity for updates: Phone Number (telephone format) Choice (multiple) - Select all 3. Country(ies) affected by the incident that apply 4. Date and time

detection

the incident yyyy-mm-dd hh:mm 5. Date and time

classification

the incident as major List

world countries yyyy-mm-dd hh:mm Choice (multiple) - Select all that apply • • • • • • 6. Criteria triggering the major ICT-related incident report • • CIRCULAIRE CSSF 24/847 Clients or financial counterparts affected Transactions affected Reputational impact Service downtime Geographical spread Data losses entailed in relation to availability, authenticity, integrity or confidentiality Criticality

the services affected Economic impact 15/24 Data Field description / Question Field type Proposed options Choice (multiple) – Select • • • • • • • • one option 7. The incident was detected by 7.1. If "Other", specify Alphanumeric 8. General description

the incident Alphanumeric IT security Staff member Internal audit Consumer / payment service user External auditor Third party provider Attacker / warning Other Provide a general description

the incident, its immediate impact and including the measures that have been taken so far 9. Short description

impact in other EU member states Alphanumeric

  1. Has the incident been reported to other authorities? Boolean (Checkbox) 10.
  2. If checkbox was ticked, specify Alphanumeric
  3. If the incident caused a service interruption, is the service restored (even Alphanumeric in degraded mode) at the time

this notification?

  1. Is the incident notified under NIS (Network Information System) Boolean (Checkbox) framework? CIRCULAIRE CSSF 24/847 16/24 Section – Incident cause, classification and impact Data Field description / Question Field type
  2. Detailed description

the incident, Alphanumeric Proposed options Provide a detailed description

the incident, including (if known and/or applicable): - How the incident started - Background and incident detection, who was involved, what happened, how did it evolve? - Cause

the incident

  1. What are the main areas/systems/channels that were affected as the incident Alphanumeric evolved? Boolean
  2. Was it related to a previous incident(s)? (Checkbox) 3.
  3. If checkbox was ticked, specify Alphanumeric yyyy-mm-dd
  4. Date and time

beginning

the incident - if known hh:mm Choice (multiple) – Select one option 5. Who is leading the investigation

the incident?

  1. Cause and type 6.
  2. Details regarding incident cause and type (Select all that apply). Select at least one

the main options. Then, as applicable, select the subcategories CIRCULAIRE CSSF 24/847 Choice (multiple) Select all that apply • • • • • Group Supervised entity Service provider Security company Other • • • • • Under investigation Malware Social engineering Insider/Third Party Provider Threat Intrusion/Unauthorised access 17/24 Data Field description / Question 6.1.1. If "Other", specify Field type • • • • Denial

service System/Process failure Human error Other • Malware o Ransomware o Trojan horse o Virus/Worm/Spyware o Other (Malware) Social engineering o Phishing/*ishing o Other (Social engineering) Insider/Third Party Provider Threat o Accidental data leakage/corruption o Intentional misuse

access rights by insider o Intentional misuse

access rights by service provider o Other (Insider/Third Party Provider Threat) Intrusion/Unauthorised access o Brute force attack o Malicious script injection and/or OS commanding o Unauthorized use

resources, copyright o Account/application compromise o Other exploited vulnerability o Other (Intrusion/Unauthorised access) Denial

service System/Process failure o Hardware failure o Software/application failure o Network failure o Database/Storage failure o Physical damage o Other (System/Process failure) Alphanumeric Choice (multiple) - 6.

  1. As applicable, select the subcategories Proposed options Select all that apply • • • • • CIRCULAIRE CSSF 24/847 18/24 Data Field description / Question
  2. If this incident is related to a cyber-attack, provide information regarding the attacker(s) (select all that apply) 7.
  3. If "Other", specify Field type Choice (multiple) Select all that apply Alphanumeric Proposed options • • Human error Other • • • • • • Terrorists Hacktivists Foreign agencies Inside job/Unaware employee Unknown Other • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available
  4. Users impacted 8.
  5. Number

internal users impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.1.

  1. As a % total internal users (values allowed from 0 to 100, rounded, no Numeric decimals, percentage sign not allowed) Choice (multiple) – Actual or estimated Select one option 8.
  2. Number

customers impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.2.

  1. As a % total customers (values allowed from 0 to 100, rounded, no decimals, Numeric percentage sign not allowed) Choice (multiple) – Actual or estimated CIRCULAIRE CSSF 24/847 Select one option 19/24 Data Field description / Question Field type Proposed options Boolean
  2. Service downtime? (Checkbox) Alphanumeric 9.
  3. If checkbox was ticked, provide the total service downtime (DD:HH:MM) (DD:HH:MM) Choice (multiple) – Actual or estimated Select one option • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available
  4. Economic impact 10.
  5. Direct financial loss in EUR Numeric Choice (multiple) – Actual or estimated Select one option 10.
  6. Indirect financial loss in EUR Numeric Choice (multiple) – Actual or estimated Select one option
  7. Were crisis management (or equivalent) procedures activated or is it likely to Boolean be activated? (Checkbox) 11.
  8. If checkbox was ticked, specify the actions taken Alphanumeric Boolean
  9. Were any legal or regulatory requirements breached? (Checkbox) 12.
  10. If checkbox was ticked, specify Alphanumeric Boolean
  11. Was there any media coverage? (Checkbox) 13.
  12. If checkbox was ticked, specify the media/newspapers/blogs that covered Alphanumeric the topic CIRCULAIRE CSSF 24/847 20/24 Data Field description / Question Field type Proposed options
  13. Overall impact (select all that apply) Choice (multiple) - • • • • • • Select all that apply Choice (multiple) –
  14. Was the incident affecting you directly, or indirectly through a service provider? Select one option 15.
  15. If "Indirectly", specify the service provider's name Alphanumeric
  16. Other impacts Alphanumeric
  17. Corrective actions/measures that have been taken so far or are planned to Alphanumeric Integrity Availability Confidentiality Reputational Directly Indirectly recover from the incident Boolean
  18. Was a business continuity plan activated? If yes, when and how? (Checkbox) yyyy-mm-dd 18.
  19. Date and time hh:mm 18.
  20. Describe Alphanumeric Boolean
  21. Was a disaster recovery plan activated? If yes, when and how? (Checkbox) yyyy-mm-dd 19.
  22. Date and time hh:mm 19.
  23. Describe Alphanumeric
  24. Is the incident in any way related to remote access (e.g., teleworking, remote Boolean connectivity, etc.)? (Checkbox) 20.
  25. If checkbox was ticked, specify Alphanumeric CIRCULAIRE CSSF 24/847 21/24 Section - Root cause, follow-up and additional information Data Field description / Question Field type
  26. Additional information Alphanumeric Proposed options Provide details regarding the following: Lessons learned (including main actions/measures taken/planned to prevent the incident from happening again in the future)
  27. Root cause and/or (select all that apply) Vulnerabilities/weaknesses identified Choice (multiple) Select all that apply – • • • • • • • • • • • • • • • • • • • • • • • CIRCULAIRE CSSF 24/847 Inadequate Change Management Migration failure Inadequacy

internal procedures and documentation Improper operations Latency issues Recovery issues Lack

staff awareness and/or compliance Unauthorised software/wrong version Inadequate privileged account management Inadequate email/web browser protection Inadequate malware defences Inadequate identity access management Inadequate security configurations for secure hardware and software on devices, laptops, workstations, servers Inadequate boundary defences Inadequate control

network ports, protocols and services Inadequate resilience and/or back-up

systems or files Unsecured network devices (firewalls, routers, switches) Inadequate maintenance and monitoring

logs Inadequate DDoS defences Inadequate penetration and security testing Inadequate patch management Inadequate application software security controls (webbased and other applications) Other 22/24 Data Field description / Question Field type 2.

  1. If "Other", specify Alphanumeric
  2. Other relevant information on the root cause (e.g., What Alphanumeric Proposed options went wrong with the change, New technical vulnerability exploited, etc.)
  3. If this incident is related to a cyber-attack, what was the entry vector

the incident? (select all that apply) Choice (multiple) – • • • • • • • • • • • Website Instant messaging Phone Insider attack (privileged user) E-mail Third party network Unauthorised devices Insider attack (regular / business users) Lost / stolen devices Chat rooms / social media Other – • • • • • Group Supervised entity Service provider Security company Other – • • • Police Other None Select all that apply 4.

  1. If "Other", specify Alphanumeric
  2. Who is leading the remediation actions? Choice (multiple) Select one option 5.
  3. If "Other", specify
  4. Are Police/other Alphanumeric security agencies involved in the Choice (multiple) investigation? Select one option 6.
  5. If "Other", specify Alphanumeric
  6. If the incident is related to ICT security, was the incident Boolean (Checkbox) reported to the national CERT (e.g., CIRCL, GOVCERT)?
  7. Has any legal action been taken (e.g., complaint with Boolean (Checkbox) prosecutor against provider or perpetrator)? CIRCULAIRE CSSF 24/847 23/24 Data Field description / Question Field type 8.
  8. If checkbox was ticked, specify Alphanumeric
  9. Assessment

the effectiveness

the action taken Choice 9.

  1. Details Alphanumeric
  2. What is the current status

the incident? Choice 10.1. Provide the date and time when then incident was closed yyyy-mm-dd hh:mm (multiple) Proposed options – • • • • Highly effective Moderately effective Not effective Not yet available – • • • • Resolved Contained Ongoing Unknown Select one option (multiple) Select one option or is expected to be closed if known CIRCULAIRE CSSF 24/847 24/24 Circular CSSF 24/847 ICT-related incident reporting framework CIRCULAR CSSF 24/847 Circular CSSF 24/847 ICT-related incident reporting framework To all Supervised Entities within the meaning

the following laws, as amended, and regulations as further specified in point 2: - Law

5 April 1993 on the financial sector - Law

15 December 2000 on postal financial services - Law

10 November 2009 on payment services - Law

17 December 2010 relating to undertakings for collective investment - Law

12 July 2013 on alternative investment fund managers - Law

15 March 2016 on OTC derivatives, central counterparties and trade repositories - Law

17 April 2018 on benchmarks - Law

6 June 2018 on Central Securities Depositories - Law

28 May 2019 on Network and Information Systems - Law

16 July 2019 on the operationalisation

European regulations in the area

financial services Luxembourg, 5 January 2024 Ladies and Gentlemen, The purpose

this Circular is to introduce a new ICT-related incident reporting framework in order to acquire a better and more structured overview

the nature, frequency, significance and impact

ICT-related incidents, also considering the growing ICT and security risk in the context

a highly interconnected global financial system. The provisions

this Circular are based on Article 53

(1)

the Law

5 April 1993 on the financial sector, as amended (hereafter “LFS”), Article 31

(4)

the Law

10 November 2009 on payment services, as amended (hereafter “LPS”), Article 2

the Law

15 December 2000 on postal financial services, as amended, Article 147

the Law

17 December 2010 relating to undertakings for collective investment, as amended (hereafter “UCITS Law”), Article 50

the Law

12 July 2013 on alternative investment fund managers, as amended (hereafter “AIFM Law”), Article 2

(1)

the Law

15 March 2016 on OTC derivatives, central counterparties and trade repositories, as amended (hereafter “EMIR Law”), Article 2

(1)

the Law

17 April 2018 on benchmarks (hereafter “Benchmark Law”), Article 2

the Law

6 June 2018 on Central Securities Depositories (hereafter “CSD Law”), and Article 20-16

the Law

16 July 2019 on the operationalisation

European regulations in the area

financial services. According to Article 3

the Law

28 May 2019 on Network and Information Systems (hereafter “NIS Law”), the CSSF is also the competent authority in terms

network and information security for the credit institutions and the financial market infrastructures that have been identified as Operators

Essential Services (hereafter “OES”), as well as for Digital Service Providers (hereafter “DSP”) which are already under the supervision

the CSSF (“NIS authority”). The objective

this circular is to lay down the practical details and modalities for the reporting obligations set forth in Articles 8

(4), 8
(5), 9
(1), 11
(3)and 11
(4)and 12

the NIS Law and in CSSF Regulation No 24-01 CIRCULAR CSSF 24/847 2/24 relating to the notification

incidents according to the Law

28 May 2019 1 (hereafter “CSSF Regulation No 24-01”) regarding specifically Articles 8

(5)and 11
(3)

the NIS Law. This Circular brings the following changes to the current incident reporting mechanism: • Increases the incident coverage, currently limited to fraud and incidents due to external computer attacks as per Circular CSSF 11/504, by covering more broadly ICT operational and security incidents while avoiding double reporting for incidents to be notified under other incident notification frameworks. • Introduces reporting based on classification. Supervised Entities will be required to classify ICTrelated incidents based on the criteria indicated in this Circular and to notify to the CSSF the cases where ICT-related incidents are classified as major or significant incidents. • Introduces a new incident reporting notification form. To obtain data in a structured form, Supervised Entities will be required to complete and submit an ICT-related incident notification form in case the ICT-related incident is classified as a major or significant incident. • Introduces a specific chapter to cover in the same Circular the incident notification requirements (previously communicated via bilateral communications to Supervised Entities that are under the scope

the NIS Law) in order to apply the new incident reporting notification forms and practical requirements to the notifications

incidents assessed as significant under the NIS Law. This Circular is divided in four chapters: • Chapter 1 (Definitions and scope

application) sets out the definitions applicable for the purpose

this Circular and defines the scope

application; • Chapter 2 (General requirements) sets out the requirements for the classification and reporting

the ICT-related incidents; • Chapter 3 (Specific requirements under the NIS Law and CSSF Regulation No 24-01) is dedicated to specific requirements for those Supervised Entities that are subject to the NIS Law and CSSF Regulation No 24-01 and that are defined as OES or DSP; • Chapter 4 (Date

application) provides for the entry into force

this Circular. 1 CSSF Regulation No 24-01

5 January 2024 relating to the notification

incidents according to the Law

28 May 2019 transposing Directive (EU) 2016/1148

the European Parliament and

the Council

6 July 2016 concerning measures for a high common level

security

network and information systems across the European Union. CIRCULAR CSSF 24/847 3/24 TABLE

CONTENTS Chapter 1: Definitions and scope

application ................................................................. 5 Section 1.1: Definitions ............................................................................................... 5 Section 1.2: Scope

application .................................................................................. 7 Chapter 2: General requirements .................................................................................... 9 Section 2.1: Incidents to be notified .............................................................................. 9 Section 2.2: ICT-related incident classification................................................................ 9 Section 2.3: Major ICT-related incident notification ....................................................... 10 Chapter 3: Specific requirements under NIS Law and CSSF Regulation No 24-01 ................ 11 Section 3.1: Incident notification by Supervised Entities who are also OES ....................... 11 Section 3.2: Incident notification by Supervised Entities who are also DSP ....................... 11 Chapter 4: Date

application ...................................................................................... 12 CIRCULAR CSSF 24/847 4/24 Chapter 1: Definitions and scope

application Section 1.1: Definitions 1. For the purpose

this Circular, the following definitions apply 2: a) “Network and information system” means: i. an electronic communications network within the meaning

Article 2

, paragraph 1,

the Law

17 December 2021 on electronic communications networks and services 3; ii. any device or group

interconnected or related devices, one or more

which, iii. digital data stored, processed, retrieved or transmitted by elements covered under pursuant to a program, perform automatic processing

digital data; or points i. and ii. above for the purposes

their operation, use, protection and maintenance. b) “Security

network and information systems” means the ability

network and information systems to resist, at a given level

confidence, any action that compromises the availability, authenticity, integrity or confidentiality

stored or transmitted or processed data or the related services

fered by, or accessible via, those network and information systems. c) “ICT-related incident” means a single event or a series

linked events unplanned by the Supervised Entity that compromises the security

the network and information systems, and has an adverse impact on the availability, authenticity, integrity or confidentiality

data, or on the services provided by the Supervised Entity. d) “Major ICT-related incident” means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions

the Supervised Entity. e) “Critical or important function” means a function, the disruption

which would materially impair the financial performance

a Supervised Entity, or the soundness or continuity

its services and activities, or the discontinued, defective or failed performance

that function would materially impair the continuing compliance

a Supervised Entity with the conditions and obligations

its authorisation, or with its other obligations under applicable financial services laws. f) “Operator

Essential Services” (“OES”) means, in accordance with point

(3)

Article 2

the NIS Law, a public or private entity

a type referred to in the annex to the NIS Law, and which meets the criteria laid down in Article 7

(2)

the NIS law 4. Definitions in points 1.

  1. f)to 1.
  2. i)are specific to Supervised Entities subject to the requirements

the NIS Law and CSSF Regulation No 24-01. 2 3 ‘Electronic communications network’ means transmission systems, whether or not based on a permanent infrastructure or centralised administration capacity, and, where applicable, switching or routing equipment and other resources, including network elements which are not active, which permit the conveyance

signals by wire, radio, optical or other electromagnetic means, including satellite networks, fixed (circuit- and packetswitched, including internet) and mobile networks, electricity cable systems, to the extent that they are used for the purpose

transmitting signals, networks used for radio and television broadcasting, and cable television networks, irrespective

the type

information conveyed. 4 In its competence as NIS authority, the CSSF already notified the relevant Supervised Entities

their identification as OES when the NIS Law entered into force. The CSSF will reconfirm the relevant Supervised Entities

their status as OES at the latest by 1 March 2024. The Supervised Entities which will not receive this notification at that date are therefore not designated as OES, without prejudice to potential future designation. CIRCULAR CSSF 24/847 5/24 g) “Digital Service Provider” (“DSP”) means, in accordance with point

(5)

Article 2

the NIS Law, a private entity that provides a digital service as defined in point

(4)

Article 2

the NIS Law 5. h) “Essential service” means a service which is essential for the maintenance

critical societal and/or economic activities and which is listed as essential service in Article 2

6 CSSF Regulation No 20-04

15 July 2020 . i) “Significant incident” means an incident having a significant impact on the continuity

the essential services provided by an OES or on the provision

a digital service provided 7 by a DSP within the European Union. For the purpose

this Circular, a significant incident is by default considered as a “Major ICT-related incident”. 2. The following entities are to be considered as Supervised Entities in the frame

this Circular: a) credit institutions and professionals

the financial sector within the meaning

the LFS; b) approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation within the meaning

the LFS; c) payment institutions and electronic money institutions within the meaning

the LPS; d) POST Luxembourg governed by the Law

15 December 2000 on postal financial services 8; e) management companies incorporated under Luxembourg law and subject to Chapter 15

the UCITS Law; f) management companies incorporated under Luxembourg law and subject to Articles 1251 or 125-2

Chapter 16

the UCITS 2010 Law; g) Luxembourg branches

IFMs subject to Chapter 17

the UCITS Law; h) investment companies which did not designate a management company within the meaning

Article 27

the UCITS Law; i) alternative investment fund managers authorised under Chapter 2

the AIFM Law; j) internally managed alternative investment funds within the meaning

point (b)

Article 4

(1)

the AIFM Law; k) central counterparties (CCPs) within the meaning

Article 2

(1)

EMIR 9, including Tier 2 third-country CCPs within the meaning

Article 25

(2a)

EMIR, complying with the relevant requirements

EMIR in accordance with point (a)

Article 25

(2b)

EMIR; l) central securities depositories within the meaning

the CSD Law; 5 In its competence as NIS authority, the CSSF already informed relevant Supervised Entities

their consideration as DSP when the NIS Law entered into force. The CSSF will reconfirm the relevant Supervised Entities

their status as DSP at the latest by 1 March 2024. The Supervised Entities which will not receive this information at that date are therefore not considered as DSP, without prejudice to potential future information. 6 CSSF Regulation No 20-04

15 July 2020 on the definition

essential services under the Law

28 May 2019 transposing Directive (EU) 2016/1148

the European Parliament and

the Council

6 July 2016 on measures to ensure a common high level

network and information system security in the European Union. 7 Definition in alignment with the NIS Law. For the sake

clarity, the wording “postal financial services” has the meaning provided for in Article 1

the Law

15 December 2000, as amended. 8 9 Regulation (EU) No 648/2012

the European Parliament and

the Council

4 July 2012 on OTC derivatives, central counterparties and trade repositories. CIRCULAR CSSF 24/847 6/24 m) administrators

critical benchmarks within the meaning

point (b)

Article 20

(1)

the Benchmark Regulation 10; n) crowdfunding Service Providers within the meaning

the Law

16 July 2019 on the operationalisation

European regulations in the area

financial services; o) credit institutions and the financial market infrastructures for which according to Article 3

the NIS Law the CSSF is the competent authority in terms

network and information security and that have been identified as OES, p) support PSF authorised in accordance with Article 29-3

the LFS for which according to Article 3

the NIS Law the CSSF is the competent authority in terms

network and information security and that have been informed by the CSSF

their consideration as DSP under the NIS Law. Section 1.2: Scope

application 3. This Circular defines the supervisory expectations that must be complied with in the event

an ICT-related incident. 4. The provisions

Chapter 2

(General requirements)

this Circular are applicable to all Supervised Entities as defined in point 2

  1. a)to
  2. n)above, hereinafter collectively referred to as “Supervised Entities” or individually as “Supervised Entity”, including their branches as specified in the respective laws. Branches in Luxembourg

Entities incorporated in a third country shall be deemed to be included in the notion

Supervised Entity. 5. Branches in Luxembourg

the Entities that are part

a legal entity whose head

fice is located in a different Member State

the European Economic Area (EEA) (EEA branches) are subject to the supervision

the competent authority

that Member State (home Member State). However, as the CSSF is competent for ensuring that EEA branches comply with the specific requirements laid down in the sectoral legal and regulatory frameworks 11, this Circular applies if an ICT-related incident impacts areas for which the CSSF retains an oversight responsibility. 6. The provisions

Chapter 3

(Specific requirements under the NIS Law and CSSF Regulation No 24-01)

this Circular are only applicable to those Supervised Entities that are also OES4 or DSP5. 7. With the aim

preventing double reporting, Supervised Entities in scope

this Circular are not required to notify under this Circular the incidents they notify in compliance with: a) Circular CSSF 21/787 on the “Application

the EBA Guidelines (EBA/GL/2021/03) on Major Incident Reporting under PSD2”, and/or; b) Cyber Incident Reporting for Supervised Entities defined as significant institutions falling under the direct supervision

the ECB, and/or; c) Article 45

(6)

Regulation (EU) No 909/2014 on notification

incidents resulting from the risks that key participants, service and utility providers, other central securities 10 Regulation (EU) 2016/1011

the European Parliament and

the Council

8 June 2016 on indices used as benchmarks in financial instruments and financial contracts or to measure the performance

investment funds and amending Directives 2008/48/EC and 2014/17/EU and Regulation (EU) No 596/2014. Notably in the context

investment services in accordance with the MiFID Law, the AML/CFT Law, the provision

asset management services and depositary tasks for Undertakings for Collective Investments established in Luxembourg. 11 CIRCULAR CSSF 24/847 7/24 depositories (CSDs) or other market infrastructures might pose to the CSD’s operations, and/or; d) Article 71

(4)(b)

Commission Delegated Regulation (EU) 2017/392

11 November 2016 supplementing Regulation (EU) No 909/2014 on reporting

material operational incidents to the competent authority. 8. By way

exception from point 7 above, Supervised Entities falling under by point 7.b) and who are also OES, are required to report to the CSSF as per this Circular those incidents that impact the continuity

the essential services they provide, in addition to their other incident reporting obligations. CIRCULAR CSSF 24/847 8/24 Chapter 2: General requirements Section 2.1: Incidents to be notified 9. Supervised Entities shall notify the following incidents in accordance with the procedure defined in section 2.3: a) Any successful malicious unauthorised access to the network and information systems. For the purpose

this circular these successful malicious unauthorised accesses are to be considered as major ICT-related incidents.

  1. b)Any incident other than those referred to in point
  2. a)above, classified in line with section 2.2 as major ICT-related incident. Section 2.2: ICT-related incident classification 10. Supervised Entities shall classify ICT-related incidents and assess their impact on the basis

the following criteria: a) the number and/or relevance

clients 12 or financial counterparts affected and, where applicable, the amount or number

transactions affected by the ICT-related incident, and whether the ICT-related incident has caused reputational impact; b) the duration

the ICT-related incident, including the service downtime;

  1. c)the geographical spread with regard to the areas affected by the ICT-related incident, particularly if it affects more than two Member States;
  2. d)the data losses that the ICT-related incident entails, in relation to availability, authenticity, integrity or confidentiality;
  3. e)the criticality

the services affected, including the Supervised Entity’s transactions and operations; f) the economic impact, in particular direct and indirect costs and losses,

the ICT-related incident in both absolute and relative terms.

  1. When the Supervised Entity's internal assessment based on the criteria listed under point 10 leads the Supervised Entity to classify an ICT-related incident as major, the ICT-related incident shall be considered as major under this circular.
  2. In the case the assessment referred under point 11 does not lead to a clear outcome on whether the ICT-related incident has to be classified as major, Supervised Entities shall report the ICT-related incident to the CSSF.
  3. Supervised Entities shall classify the ICT-related incident in a timely manner after the ICTrelated incident has been detected, and without undue delay after the information required for the classification

the ICT-related incident is available to the Supervised Entities, but no later than 24 hours after the detection

that ICT-related incident. If longer time is needed to classify the ICT-related incident, Supervised Entities shall explain in the initial notification submitted to the competent authority the reasons thereof. Where the deadline Supervised Entities who are also OES shall consider the number

users affected by the disruption to the essential service. Supervised Entities who are also DSP shall consider the number

users affected by the incident, in particular those who use the digital service to provide their own services. 12 CIRCULAR CSSF 24/847 9/24 for classification falls on a weekend day or a bank holiday, Supervised Entities may classify the incident on the next working day. Section 2.3: Major ICT-related incident notification 14. Supervised Entities shall, within the time limits laid down in Annex I, submit the following notifications

major ICT-related incidents to the CSSF:

  1. a)An initial notification with "Initial Information" when the ICT-related incident has been classified as major.
  2. b)An intermediate notification with “Incident cause, classification and impact” after the initial notification referred to in point 14.a), followed by, as appropriate, updated notifications each time a relevant update is available, as well as upon specific request by the CSSF.
  3. c)A final notification, when the root cause analysis has been completed, regardless

whether mitigation measures have been fully implemented, and when the actual impact figures are available to replace estimates. In this notification Supervised Entities can add any follow-up and additional information that is deemed relevant for the ICT-related incident. 15. When the ICT-related incident proves to have or will potentially have a very serious impact (e.g., complete unavailability

the systems), the Supervised Entity shall notify the CSSF as soon as possible within the given timeframe, and if necessary, before the formal submission

the notification form.

  1. ICT-related incident notifications referred to in point 14 shall be submitted via the corresponding form available using the CSSF digital solution as further specified on the CSSF website.
  2. Supervised Entities shall complete the relevant section

the notification form, depending on the phase they are in (i.e., section “Initial information” for initial notification, section “Incident cause, classification and impact” for intermediate notification and section “Root cause – Follow-up and additional information” for final notification). The notification form contains the data fields laid down in Annex II. 18. The sections

the notification form must be submitted in the order indicated in point 14. Should the Supervised Entity have all the information required available at the time

the initial notification, a single submission (containing all the sections

the notification form) shall be made. 19. Supervised Entities shall also notify the competent authority when, as a result

the continuous assessment

the ICT-related incident, it is identified that an already reported ICT-related incident no longer fulfils the criteria to be considered major and is not expected to fulfil them before the ICT-related incident is resolved. In this case, Supervised Entities shall reclassify the ICT-related incident as soon as this circumstance is detected and provide an explanation

the reasons justifying this reclassification in the section “Initial information”

the notification form. 20. Supervised Entities may outsource the reporting obligations under this chapter to a thirdparty provider. In case

such outsourcing, the Supervised Entity remains fully responsible for the fulfilment

the ICT-related incident reporting requirements within the applicable timeline and for the whole content

the incident reporting. CIRCULAR CSSF 24/847 10/24 Chapter 3: Specific requirements under NIS Law and CSSF Regulation No 24-01 Section 3.1: Incident notification by Supervised Entities who are also OES 21. In compliance with Article 8

(4)

the NIS Law, Supervised Entities who are also OES shall notify, without undue delay, the CSSF

incidents having a significant impact on the continuity

the essential services they provide. The notion

“without undue delay” is considered complied with when Supervised Entities submit their incident notification in line with the time limits indicated in section 2.3 (Major ICT-related incident notification) and in Annex I. 22. In this respect, in compliance with Article 8

(5)

the NIS Law and CSSF Regulation No 2401, Supervised Entities who are also OES shall assess whether an incident is to be classified as a significant incident by applying mutatis mutandis the requirements stated in section 2.2 (ICT-related incident classification) and shall notify the significant incidents in compliance with the requirements stated in section 2.3 (Major ICT-related incident notification).

  1. Successful malicious unauthorised accesses have to be considered by default as significant incidents and shall be notified in compliance with the requirements stated in section 2.3 (Major ICT-related incident notification).
  2. When an incident is classified both as a significant incident and as a major ICT-related incident (e.g., the incident impacts both essential services under NIS and other critical or important functions), Supervised Entities who are also OES shall notify only once the incident and indicate in their notification that the incident is also notified under the NIS Law. Section 3.2: Incident notification by Supervised Entities who are also DSP
  3. Article 11

(3)

the NIS Law and CSSF Regulation No 24-01 mentions that DSPs shall notify, without undue delay, the competent authority

incidents having a significant impact on the provision

a digital service they provide within the European Union. The notion

“without undue delay” is considered complied with when Supervised Entities submit their incident notification in line with the time limits indicated in section 2.3 (Major ICT-related incident notification) and in Annex I. 26. Supervised Entities who are also DSP shall: a) assess whether an incident (including successful malicious unauthorised accesses, as defined under point 9.a)

section 2.1) is to be classified as a significant incident in line with Articles 3 and 4

Commission Implementing Regulation (EU) 2018/151

30 January 2018 13 providing details on Article 11

(4)

the NIS Law; 13 Commission Implementing Regulation (EU) 2018/151

30 January 2018 laying down rules for application

Directive (EU) 2016/1148

the European Parliament and

the Council as regards further specification

the elements to be taken into account by digital service providers for managing the risks posed to the security

network and information systems and

the parameters for determining whether an incident has a substantial impact. CIRCULAR CSSF 24/847 11/24 b) apply mutatis mutandis points 12 and 13

section 2.2 (ICT-related incident classification); c) notify the significant incidents in compliance with the requirements stated in section 2.3 (Major ICT-related incident notification). 27. When an incident is classified both as a significant incident and as a major ICT-related incident, Supervised Entities who are also DSP shall notify only once the incident and indicate in their notification that the incident is also notified under the NIS Law. Chapter 4: Date

application 28. This Circular shall enter into force on 1 April 2024 for the Supervised Entities as defined in point 2

  1. a)to
  2. d)and
  3. k)to
  4. p)in Section 1.1., and on 1 June 2024 for the Supervised Entities as defined in point 2
  5. e)to
  6. j)in Section 1.1. The Circular will repeal and replace Circular CSSF 11/504 on “Frauds and incidents due to external computer attacks” on 1 April 2024 for the Supervised Entities as defined in point 2
  7. a)to
  8. d)and
  9. k)to
  10. p)in Section 1.1. and on 1 June 2024 for the Supervised Entities as defined in point 2
  11. e)to
  12. j)in Section 1.1. Marco ZWICK Director Claude WAMPACH Director Françoise KAUTHEN Director Annexes CIRCULAR CSSF 24/847 Jean-Pierre FABER Director Claude MARX Director General I. Deadlines and explanations for submission

notifications II. Data fields 12/24 Annex I: Deadlines and explanations for submission

notifications Relevant section to be filled in and Deadlines Explanatory notes Classification

the incident as major Classification

the incident as major Within 24 hours after the detection

the ICTrelated incident Reminder

point 15: When the ICT-related incident proves to have or submitted N/A Where the deadline for classification falls on a weekend day or a bank holiday, Supervised Entities may classify the incident on the next working day. will potentially have a very serious impact (e.g., complete unavailability

the systems), the Supervised Entity shall notify the CSSF as soon as possible within the given timeframe, and if necessary, before the formal submission

the notification form. INITIAL INFORMATION Within 4 hours after the classification

the incident as major The “INITIAL INFORMATION” section contains the Where the deadline for notification falls on a be included in the notification the first time it is weekend day or a bank holiday, Supervised general information about the incident that shall submitted. Entities may notify the incident on the next working day. INCIDENT CAUSE, CLASSIFICATION IMPACT AND Within 3 working days after the submission to the The section “INCIDENT CAUSE, CLASSIFICATION CSSF

the INITIAL INFORMATION AND IMPACT” provides a more detailed description

the incident, its consequences and the corrective measures that were taken to CIRCULAR CSSF 24/847 13/24 recover. If the Supervised Entity has updates to previous reports (

the same incident), an updated version

the section

the form may be submitted. ROOT CAUSE – FOLLOW-UP AND ADDITIONAL Within 20 working days after the submission to The section “ROOT CAUSE – FOLLOW-UP AND INFORMATION the ADDITIONAL CSSF

the INCIDENT CLASSIFICATION AND IMPACT CAUSE, INFORMATION” provides information regarding the root cause analysis, lessons learned and any other relevant information. When submitting this information, the Supervised Entity shall review the other sections

the form and update these, where appropriate. CIRCULAR CSSF 24/847 14/24 Annex II: Data fields Section – Initial Information Data Field description / Question Field type Proposed options Alphanumeric

  1. Contact person within the supervised entity for updates: Name and surname
  2. Contact person within the supervised entity for updates: Email Alphanumeric (email format)
  3. Contact person within the supervised entity for updates: Phone Number (telephone format)
  4. Second contact person within the supervised entity for updates: Name and surname Alphanumeric
  5. Second contact person within the supervised entity for updates: Email Alphanumeric (email format)
  6. Second contact person within the supervised entity for updates: Phone Number (telephone format) Choice (multiple) - Select all
  7. Country(ies) affected by the incident that apply
  8. Date and time

detection

the incident yyyy-mm-dd hh:mm 5. Date and time

classification

the incident as major List

world countries yyyy-mm-dd hh:mm Choice (multiple) - Select all that apply • • • • • • 6. Criteria triggering the major ICT-related incident report • • CIRCULAR CSSF 24/847 Clients or financial counterparts affected Transactions affected Reputational impact Service downtime Geographical spread Data losses entailed in relation to availability, authenticity, integrity or confidentiality Criticality

the services affected Economic impact 15/24 Data Field description / Question Field type Proposed options Choice (multiple) – Select • • • • • • • • one option 7. The incident was detected by 7.1. If "Other", specify Alphanumeric 8. General description

the incident Alphanumeric IT security Staff member Internal audit Consumer / payment service user External auditor Third party provider Attacker / warning Other Provide a general description

the incident, its immediate impact and including the measures that have been taken so far 9. Short description

impact in other EU member states Alphanumeric

  1. Has the incident been reported to other authorities? Boolean (Checkbox) 10.
  2. If checkbox was ticked, specify Alphanumeric
  3. If the incident caused a service interruption, is the service restored (even Alphanumeric in degraded mode) at the time

this notification?

  1. Is the incident notified under NIS (Network Information System) Boolean (Checkbox) framework? CIRCULAR CSSF 24/847 16/24 Section – Incident cause, classification and impact Data Field description / Question Field type
  2. Detailed description

the incident, Alphanumeric Proposed options Provide a detailed description

the incident, including (if known and/or applicable): - How the incident started - Background and incident detection, who was involved, what happened, how did it evolve? - Cause

the incident

  1. What are the main areas/systems/channels that were affected as the incident Alphanumeric evolved? Boolean
  2. Was it related to a previous incident(s)? (Checkbox) 3.
  3. If checkbox was ticked, specify Alphanumeric yyyy-mm-dd
  4. Date and time

beginning

the incident - if known hh:mm Choice (multiple) – Select one option 5. Who is leading the investigation

the incident?

  1. Cause and type 6.
  2. Details regarding incident cause and type (Select all that apply). Select at least one

the main options. Then, as applicable, select the subcategories CIRCULAR CSSF 24/847 Choice (multiple) Select all that apply • • • • • Group Supervised entity Service provider Security company Other • • • • • Under investigation Malware Social engineering Insider/Third Party Provider Threat Intrusion/Unauthorised access 17/24 Data Field description / Question 6.1.1. If "Other", specify Field type • • • • Denial

service System/Process failure Human error Other • Malware o Ransomware o Trojan horse o Virus/Worm/Spyware o Other (Malware) Social engineering o Phishing/*ishing o Other (Social engineering) Insider/Third Party Provider Threat o Accidental data leakage/corruption o Intentional misuse

access rights by insider o Intentional misuse

access rights by service provider o Other (Insider/Third Party Provider Threat) Intrusion/Unauthorised access o Brute force attack o Malicious script injection and/or OS commanding o Unauthorized use

resources, copyright o Account/application compromise o Other exploited vulnerability o Other (Intrusion/Unauthorised access) Denial

service System/Process failure o Hardware failure o Software/application failure o Network failure o Database/Storage failure o Physical damage o Other (System/Process failure) Alphanumeric Choice (multiple) - 6.

  1. As applicable, select the subcategories Proposed options Select all that apply • • • • • CIRCULAR CSSF 24/847 18/24 Data Field description / Question
  2. If this incident is related to a cyber-attack, provide information regarding the attacker(s) (select all that apply) 7.
  3. If "Other", specify Field type Choice (multiple) Select all that apply Alphanumeric Proposed options • • Human error Other • • • • • • Terrorists Hacktivists Foreign agencies Inside job/Unaware employee Unknown Other • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available
  4. Users impacted 8.
  5. Number

internal users impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.1.

  1. As a % total internal users (values allowed from 0 to 100, rounded, no Numeric decimals, percentage sign not allowed) Choice (multiple) – Actual or estimated Select one option 8.
  2. Number

customers impacted Numeric Choice (multiple) – Actual or estimated Select one option 8.2.

  1. As a % total customers (values allowed from 0 to 100, rounded, no decimals, Numeric percentage sign not allowed) Choice (multiple) – Actual or estimated CIRCULAR CSSF 24/847 Select one option 19/24 Data Field description / Question Field type Proposed options Boolean
  2. Service downtime? (Checkbox) Alphanumeric 9.
  3. If checkbox was ticked, provide the total service downtime (DD:HH:MM) (DD:HH:MM) Choice (multiple) – Actual or estimated Select one option • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available • • • Actual figure Estimation Not yet available
  4. Economic impact 10.
  5. Direct financial loss in EUR Numeric Choice (multiple) – Actual or estimated Select one option 10.
  6. Indirect financial loss in EUR Numeric Choice (multiple) – Actual or estimated Select one option
  7. Were crisis management (or equivalent) procedures activated or is it likely to Boolean be activated? (Checkbox) 11.
  8. If checkbox was ticked, specify the actions taken Alphanumeric Boolean
  9. Were any legal or regulatory requirements breached? (Checkbox) 12.
  10. If checkbox was ticked, specify Alphanumeric Boolean
  11. Was there any media coverage? (Checkbox) 13.
  12. If checkbox was ticked, specify the media/newspapers/blogs that covered Alphanumeric the topic CIRCULAR CSSF 24/847 20/24 Data Field description / Question Field type Proposed options
  13. Overall impact (select all that apply) Choice (multiple) - • • • • • • Select all that apply Choice (multiple) –
  14. Was the incident affecting you directly, or indirectly through a service provider? Select one option 15.
  15. If "Indirectly", specify the service provider's name Alphanumeric
  16. Other impacts Alphanumeric
  17. Corrective actions/measures that have been taken so far or are planned to Alphanumeric Integrity Availability Confidentiality Reputational Directly Indirectly recover from the incident Boolean
  18. Was a business continuity plan activated? If yes, when and how? (Checkbox) yyyy-mm-dd 18.
  19. Date and time hh:mm 18.
  20. Describe Alphanumeric Boolean
  21. Was a disaster recovery plan activated? If yes, when and how? (Checkbox) yyyy-mm-dd 19.
  22. Date and time hh:mm 19.
  23. Describe Alphanumeric
  24. Is the incident in any way related to remote access (e.g., teleworking, remote Boolean connectivity, etc.)? (Checkbox) 20.
  25. If checkbox was ticked, specify Alphanumeric CIRCULAR CSSF 24/847 21/24 Section - Root cause, follow-up and additional information Data Field description / Question Field type
  26. Additional information Alphanumeric Proposed options Provide details regarding the following: Lessons learned (including main actions/measures taken/planned to prevent the incident from happening again in the future)
  27. Root cause and/or Vulnerabilities/weaknesses (select all that apply) identified Choice (multiple) Select all that apply – • • • • • • • • • • • • • • • • • • • • • • • CIRCULAR CSSF 24/847 Inadequate Change Management Migration failure Inadequacy

internal procedures and documentation Improper operations Latency issues Recovery issues Lack

staff awareness and/or compliance Unauthorised software/wrong version Inadequate privileged account management Inadequate email/web browser protection Inadequate malware defences Inadequate identity access management Inadequate security configurations for secure hardware and software on devices, laptops, workstations, servers Inadequate boundary defences Inadequate control

network ports, protocols and services Inadequate resilience and/or back-up

systems or files Unsecured network devices (firewalls, routers, switches) Inadequate maintenance and monitoring

logs Inadequate DDoS defences Inadequate penetration and security testing Inadequate patch management Inadequate application software security controls (webbased and other applications) Other 22/24 Data Field description / Question Field type 2.

  1. If "Other", specify Alphanumeric
  2. Other relevant information on the root cause (e.g., What Alphanumeric Proposed options went wrong with the change, New technical vulnerability exploited, etc.)
  3. If this incident is related to a cyber-attack, what was the entry vector

the incident? (select all that apply) Choice (multiple) – • • • • • • • • • • • Website Instant messaging Phone Insider attack (privileged user) E-mail Third party network Unauthorised devices Insider attack (regular / business users) Lost / stolen devices Chat rooms / social media Other – • • • • • Group Supervised entity Service provider Security company Other – • • • Police Other None Select all that apply 4.

  1. If "Other", specify Alphanumeric
  2. Who is leading the remediation actions? Choice (multiple) Select one option 5.
  3. If "Other", specify
  4. Are Police/other Alphanumeric security agencies involved in the Choice (multiple) investigation? Select one option 6.
  5. If "Other", specify Alphanumeric
  6. If the incident is related to ICT security, was the incident Boolean (Checkbox) reported to the national CERT (e.g., CIRCL, GOVCERT)?
  7. Has any legal action been taken (e.g., complaint with Boolean (Checkbox) prosecutor against provider or perpetrator)? CIRCULAR CSSF 24/847 23/24 Data Field description / Question Field type 8.
  8. If checkbox was ticked, specify Alphanumeric
  9. Assessment

the effectiveness

the action taken Choice 9.

  1. Details Alphanumeric
  2. What is the current status

the incident? Choice 10.1. Provide the date and time when then incident was closed yyyy-mm-dd hh:mm (multiple) Proposed options – • • • • Highly effective Moderately effective Not effective Not yet available – • • • • Resolved Contained Ongoing Unknown Select one option (multiple) Select one option or is expected to be closed if known CIRCULAR CSSF 24/847 24/24 Circulaire CSSF 25/893 sur la notification des incidents majeurs liés aux TIC et des cybermenaces importantes en vertu du règlement sur la résilience opérationnelle numérique (DORA) En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 25/893 sur la notification des incidents majeurs liés aux TIC et des cybermenaces importantes en vertu du règlement sur la résilience opérationnelle numérique (DORA) À toutes les entités financières telles que définies à l’article 2, paragraphe 1, points

  1. a)à i),
  2. k)à m), p),
  3. r)et s), au sens de l’article 2, paragraphe 2, du règlement (UE) 2022/2554 1 sur la résilience opérationnelle numérique du secteur financier (ci-après le « règlement DORA ») et à tous les prestataires de services de paiement tels que définis à l’article 1 er, paragraphe 37, de la loi du 10 novembre 2009 relative aux services de paiement (LSP) Luxembourg, le 27 mai 2025 Mesdames, Messieurs, Tel que défini à l’article 18, paragraphes 1 et 2, et à l’article 19, paragraphes 1 et 2, du règlement DORA, les entités financières soumises au règlement DORA sont tenues de se conformer aux obligations de classification et de notification des incidents majeurs liés aux TIC et, le cas échéant, des cybermenaces importantes. Les dispositions relatives à la classification et à la notification sont détaillées dans les normes techniques de réglementation (RTS) et les normes techniques d’exécution (ITS) suivantes : • RTS sur la classification des incidents liés aux TIC et des cybermenaces2 (ci-après « RTS sur la classification »), et • RTS et ITS sur la notification des incidents et la notification volontaire des cybermenaces (ci-après « RTS sur la notification des incidents »3 et « ITS sur la notification des incidents »4) Règlement (UE) 2022/2554 du Parlement européen et du Conseil du 14 décembre 2022 sur la résilience opérationnelle numérique du secteur financier et modifiant les règlements (CE) n° 1060/2009, (UE) n° 648/2012, (UE) n° 600/2014, (UE) n° 909/2014 et (UE) 2016/1011 1 Règlement délégué (UE) 2024/1772 du 13 mars 2024 complétant le règlement (UE) 2022/2554 du Parlement européen et du Conseil par des normes techniques de réglementation précisant les critères de classification des incidents liés aux TIC et des cybermenaces, fixant des seuils d’importance significative et précisant les détails des rapports d’incidents majeurs 2 Règlement délégué (UE) 2025/301 de la Commission du 23 octobre 2024 complétant le règlement (UE) 2022/2554 du Parlement européen et du Conseil par des normes techniques de réglementation précisant le contenu et les délais pour la notification initiale des incidents majeurs liés aux TIC, et pour les rapports intermédiaire et final y afférents, et le contenu de la notification volontaire en ce qui concerne les cybermenaces importantes 3 Règlement d’exécution (UE) 2025/302 de la Commission du 23 octobre 2023 définissant des normes techniques d’exécution pour l’application du règlement (UE) 2022/2554 du Parlement européen et du Conseil en ce qui concerne les formulaires, modèles et procédures types permettant aux entités financières de notifier un incident majeur lié aux TIC et de notifier une cybermenace importante 4 En outre, par la présente circulaire, la CSSF demande aux prestataires de services de paiement (PSP) qui n’entrent pas dans le champ d’application du règlement DORA de suivre les procédures de classification et de notification des incidents liés aux TIC et des cybermenaces prévues par le règlement DORA afin de remplir les obligations de notification énoncées à l’article 105-2 de la LSP. En clair, ces PSP doivent répondre aux exigences du règlement DORA pour tous les incidents liés aux TIC (à savoir, y compris, les incidents liés aux TIC qui ne sont pas liés aux services de paiement), afin d’éviter un double mécanisme de notification. Dans ce contexte, la présente circulaire prévoit également les modalités pratiques selon lesquelles les entités financières entrant dans le champ d'application de cette circulaire sont tenues de notifier, à la CSSF, les incidents majeurs liés aux TIC ainsi que, le cas échéant, les cybermenaces importantes. La présente circulaire est divisée en quatre chapitres : • le chapitre 1 définit le champ d’application ; • le chapitre 2 énumère les exigences relatives à la classification et à la notification des incidents et des cybermenaces pour les PSP qui ne relèvent pas du règlement DORA ; • le chapitre 3 définit les modalités pratiques de notification des incidents majeurs liés aux TIC et des cybermenaces importantes ; • le chapitre 4 prévoit l’entrée en vigueur de la présente circulaire. TABLE DES MATIÈRES Chapitre 1 : Champ d’application .......................................................................................... 5 Chapitre 2 : Exigences relatives à la classification et à la notification des incidents et des cybermenaces pour les PSP qui ne relèvent pas du règlement DORA ......................................... 6 Chapitre 3 : Modalités pratiques pour la notification des incidents majeurs liés aux TIC et des cybermenaces importantes................................................................................................... 7 Chapitre 4 : Date d’application ............................................................................................. 8 Chapitre 1 : Champ d’application 1. Les entités suivantes sont à considérer comme des entités financières dans le cadre de la présente circulaire :
  4. a)établissements de crédit, entreprises d’investissement, opérateurs de marché exploitant une plate-forme de négociation et dispositifs de publication agréés (APA) avec une dérogation et mécanismes de déclaration agréés (ARM) avec une dérogation au sens de la loi du 5 avril 1993 relative au secteur financier (LSF) ;
  5. b)établissements de paiement, prestataires de services d’information sur les comptes et établissements de monnaie électronique au sens de la loi du 10 novembre 2009 relative aux services de paiement (LSP) ;
  6. c)prestataires de services sur crypto-actifs et émetteurs de jetons se référant à un ou des actifs au sens du règlement (UE) 2023/1114 ;
  7. d)dépositaires centraux de titres au sens de la loi du 6 juin 2018 relative aux dépositaires centraux de titres (Loi DCT) ;
  8. e)contreparties centrales au sens de la loi du 15 mars 2016 relative aux produits dérivés de gré à gré, aux contreparties centrales et aux référentiels centraux ;
  9. f)sociétés de gestion de droit luxembourgeois relevant du chapitre 15 ou de l’article 1252 du chapitre 16 et succursales luxembourgeoises de gestionnaires de fonds d’investissement relevant du chapitre 17, et sociétés d’investissement qui n’ont pas désigné de société de gestion au sens de l’article 27 de la loi du 17 décembre 2010 concernant les organismes de placement collectif ;
  10. g)gestionnaires de fonds d’investissement alternatifs agréés au titre du chapitre 2 et fonds d’investissement alternatifs gérés de manière interne au sens de l’article 4, paragraphe 1, point b), de la loi du 12 juillet 2013 relative aux gestionnaires de fonds d’investissement alternatifs (Loi GFIA) ;
  11. h)institutions de retraite professionnelle agréées conformément à l’article 2, paragraphe 2, de la loi du 13 juillet 2005 relative aux institutions de retraite professionnelle sous forme de sepcav et assep ;
  12. i)administrateurs d’indices de référence d’importance critique au sens de l’article 20, paragraphe 1, point b), du règlement (UE) 2016/1011 ;
  13. j)prestataires de services de financement participatif au sens de la loi du 16 juillet 2019 relative à l’opérationnalisation de règlements européens dans le domaine des services financiers ;
  14. k)prestataires de services de paiement (PSP) tels que visés à l’article 1 er, paragraphe 37, de la loi du 10 novembre 2009 relative aux services de paiement (LSP) tels que définis au point 1a) et
  15. b)ci-dessus, à savoir succursales luxembourgeoises de PSP ayant leur siège social dans un pays tiers, et POST Luxembourg. 2. Les dispositions du chapitre 2 de la présente circulaire s’appliquent uniquement aux entités entrant dans le champ d'application de la présente circulaire telles que définies au point
  16. k)ci-dessus, ci-après dénommées collectivement les « PSP qui ne relèvent pas du règlement DORA ». 3. Les dispositions du chapitre 3 de la présente circulaire s’appliquent à toutes les entités financières entrant dans le champ d’application de la présente circulaire, telles que définies au point 1a) à
  17. k)ci-dessus, ci-après dénommées collectivement « Entités financières » ou individuellement « Entité financière », y compris leurs succursales telles que précisées dans les lois respectives. 4. Les succursales luxembourgeoises des Entités financières qui font partie d'une entité juridique dont le siège social est situé dans un autre État membre de l'Union européenne (succursales de l'UE) sont censées notifier leurs incidents majeurs liés aux TIC et leurs cybermenaces importantes en vertu du règlement DORA à l'autorité compétente de cet État membre (État membre d'origine) et sont donc exclues du champ d'application de la présente circulaire. Chapitre 2 : Exigences relatives à la classification et à la notification des incidents et des cybermenaces pour les PSP qui ne relèvent pas du règlement DORA 5. Aux fins de la présente circulaire, les définitions suivantes sont reprises du règlement DORA et s'appliquent aux PSP qui ne relèvent pas du règlement DORA :
  18. a)« réseaux et systèmes d’information » :

(1)un « réseau de communications électroniques » : les systèmes de transmission, qu’ils soient ou non fondés sur une infrastructure permanente ou une capacité d’administration centralisée et, le cas échéant, les équipements de commutation ou de routage et les autres ressources, y compris les éléments de réseau qui ne sont pas actifs, qui permettent l’acheminement de signaux par câble, par la voie hertzienne, par moyen optique ou par d’autres moyens électromagnétiques, comprenant les réseaux satellitaires, les réseaux fixes (avec commutation de circuits ou de paquets, y compris l’internet) et mobiles, les systèmes utilisant le réseau électrique, pour autant qu’ils servent à la transmission de signaux, les réseaux utilisés pour la radiodiffusion sonore et télévisuelle et les réseaux câblés de télévision, quel que soit le type d’information transmise.
(2)tout dispositif ou tout ensemble de dispositifs interconnectés ou apparentés, dont un ou plusieurs éléments assurent, en exécution d’un programme, un traitement automatisé de données numériques; ou
(3)les données numériques stockées, traitées, récupérées ou transmises par les éléments visés aux points 1 et 2 ci-dessus en vue de leur fonctionnement, utilisation, protection et maintenance ; b) « sécurité des réseaux et des systèmes d’information » : la capacité des réseaux et des systèmes d’information de résister, à un niveau de confiance donné, à tout événement susceptible de compromettre la disponibilité, l’authenticité, l’intégrité ou la confidentialité de données stockées, transmises ou faisant l’objet d’un traitement, ou des services que ces réseaux et systèmes d’information

frent ou rendent accessibles ;

  1. c)« incident opérationnel ou de sécurité lié au paiement » : un événement ou une série d’événements liés entre eux que les entités financières n’ont pas prévu, lié ou non aux TIC, qui a une incidence négative sur la disponibilité, l’authenticité, l’intégrité ou la confidentialité des données liées au paiement ou sur les services liés au paiement fournis par l’entité financière ;
  2. d)« incident lié aux TIC » : un événement ou une série d’événements liés entre eux que l’entité financière n’a pas prévu qui compromet la sécurité des réseaux et des systèmes d’information, et a une incidence négative sur la disponibilité, l’authenticité, l’intégrité ou la confidentialité des données ou sur les services fournis par l’entité financière. Cela comprend les incidents opérationnels ou de sécurité liés au paiement ;
  3. e)« incident opérationnel ou de sécurité majeur lié au paiement » : un incident opérationnel ou de sécurité lié au paiement qui a une incidence négative élevée sur les services fournis liés au paiement ;
  4. f)« incident majeur lié aux TIC » : un incident lié aux TIC qui a une incidence négative élevée sur les réseaux et les systèmes d’information qui soutiennent les fonctions critiques ou importantes de l’entité financière. Cela comprend les incidents opérationnels ou de sécurité majeur lié au paiement ;
  5. g)« cybermenace » : toute circonstance, tout événement ou toute action potentiels susceptibles de nuire ou de porter autrement atteinte aux réseaux et systèmes d’information, aux utilisateurs de tels systèmes et à d’autres personnes ;
  6. h)« cybermenace importante » : une cybermenace dont les caractéristiques techniques indiquent qu’elle pourrait donner lieu à un incident majeur lié aux TIC ou à un incident opérationnel ou de sécurité majeur lié au paiement ;
  7. i)« fonction critique ou importante » : une fonction dont la perturbation est susceptible de nuire sérieusement à la performance financière d’une entité financière, ou à la solidité ou à la continuité de ses services et activités, ou une interruption, une anomalie ou une défaillance de l’exécution de cette fonction qui est susceptible de nuire sérieusement à la capacité d’une entité financière de respecter en permanence les conditions et obligations de son agrément, ou ses autres obligations découlant des dispositions applicables des lois relatives aux services financiers. 6. Les PSP ne relevant pas du règlement DORA sont tenus de classer leurs incidents liés aux TIC et leurs cybermenaces selon les critères et les seuils d’importance définis dans les chapitres I, II et III des RTS sur la classification. Les chapitres IV et V des RTS sur la classification ne leur sont pas applicables. 7. Les PSP qui ne relèvent pas du règlement DORA sont en outre tenus de notifier les incidents majeurs liés aux TIC et, le cas échéant, les cybermenaces importantes, conformément aux RTS sur la notification des incidents et aux ITS sur la notification des incidents, qui s'appliquent intégralement à eux. Chapitre 3 : Modalités pratiques pour la notification des incidents majeurs liés aux TIC et des cybermenaces importantes 8. Les notifications des incidents majeurs liés aux TIC ainsi que, le cas échéant, des cybermenaces importantes, doivent être soumises au moyen du formulaire correspondant, soit selon la procédure dédiée « DORA Major ICT-related Incident Notification » disponible sur le portail eDesk de la CSSF, soit via l'interface API (S3) fournie par la CSSF. 9. Les Entités financières doivent notifier la CSSF dans les délais prévus à l'article 5 des RTS sur la notification des incidents. 10. Les Entités financières doivent compléter la ou les sections pertinentes du formulaire de notification, en fonction de la phase dans laquelle elles se trouvent. La première section fait référence à la notification initiale conformément à l'article 2 des RTS sur la notification des incidents, la deuxième section traite du rapport intermédiaire conformément à l'article 3 des RTS sur la notification des incidents et la troisième section renvoie au rapport final conformément à l'article 4 des RTS sur la notification des incidents. Le formulaire de notification contient des champs de données prévus aux annexes II et IV des ITS sur la notification des incidents. 11. L'article 7 des ITS sur la notification des incidents indique que la déclaration agrégée n'est possible que si les autorités compétentes en ont explicitement donné l'autorisation. À cet égard, la CSSF informe les Entités financières que, après avoir soigneusement évalué toutes les conditions des points
  8. a)à
  9. d)de l'article 7, paragraphe 1, ainsi que de l'article 7, paragraphe 2, des ITS sur la notification des incidents, aucun rapport agrégé n'est autorisé lorsqu'il s'agit de notifications d'incidents majeurs liés aux TIC. 12. Les Entités financières qui ont externalisé les obligations de notification restent pleinement responsables du respect des exigences en matière de notification des incidents liés aux TIC dans les délais applicables et de l’intégralité du contenu des notifications des incidents. Comme le précise l'article 6 des ITS sur la notification des incidents, les Entités financières doivent informer la CSSF dès que possible de l'externalisation des obligations de notification et, au plus tard, avant la première notification. À cet égard, les informations suivantes doivent être fournies à la CSSF (adresse électronique : ictrisksupervision@cssf.
  10. lu):
  11. a)le nom, les coordonnées et un code d'identification du tiers qui soumettra les notifications pour le compte de l'Entité financière ;
  12. b)le nom, les coordonnées et la fonction connexe des personnes au sein du tiers à qui le rôle de notification d'incident connexe sera attribué dans la solution numérique de la CSSF. Chapitre 4 : Date d’application 13. S’agissant des entités énumérées aux point 1a) à
  13. j):
  14. a)cette circulaire s'applique avec effet immédiat et rend la circulaire CSSF 24/847 sur le cadre de notification des incidents liés aux TIC inapplicable ;
  15. b)la circulaire CSSF 21/787 concernant l’application des Orientations de l’EBA (EBA/GL/2021/03) sur la notification des incidents majeurs en vertu de la directive PSD2 ne leur est plus applicable. 14. S’agissant des entités énumérées au point 1k) :
  16. a)la présente circulaire s'applique six mois après sa date de publication ;
  17. b)pendant la période de transition, les critères de classification ainsi que les modalités de notification requises par les circulaires CSSF 24/847 sur le cadre de notification des incidents liés aux TIC et CSSF 21/787 sur l'application des Orientations de l'EBA (EBA/GL/2021/03) sur la notification des incidents majeurs en vertu de la directive PSD2 leur restent applicables. 15. Six mois après la date de publication de la présente circulaire, la circulaire CSSF 21/787 sur l'application des Orientations de l'EBA (EBA/GL/2021/03) sur la notification des incidents majeurs en vertu de la directive PSD2 sera abrogée. Claude WAMPACH Directeur Françoise KAUTHEN Directeur Marco ZWICK Directeur Jean-Pierre FABER Directeur Claude MARX Directeur général Circular CSSF 25/893 on reporting

major ICTrelated incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) Circular CSSF 25/893 on reporting

major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA) To all financial entities defined in Article 2

(1)(
  1. a)to (i), (
  2. k)to (m), (p), (
  3. r)and (s), and within the meaning

Article 2

(2)

Regulation (EU) 2022/2554 1 on digital operational resilience for the financial sector (hereafter “DORA”) and to all Payment Service Providers as referred to in Article 1

(37)

the Law

10 November 2009 on payment services (LPS). Luxembourg, 27 May 2025 Ladies and Gentlemen, As defined in Articles 18

(1), 18
(2), 19
(1)and 19
(2)

DORA, financial entities subject to DORA are required to comply with the obligations for classifying and reporting major ICT-related incidents and, if applicable, significant cyber threats. The specifics regarding classification and reporting are detailed in the following Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS): • RTS on classification

ICT-related incidents and cyber threats 2 (hereafter “RTS on classification”), and • RTS and ITS on incident and voluntary cyber threats reporting (hereafter “RTS on incident reporting” 3 and “ITS on incident reporting” 4) Furthermore, with this circular the CSSF requires Payment Service Providers (PSPs) that are not in the scope

DORA to follow the ICT-related incident and cyber threat classification and reporting procedures under DORA in order to fulfil the reporting requirements stipulated under Article 105-2

the LPS. As a simplification, these PSPs shall follow the DORA requirements for all ICT-related incidents (i.e. including ICT-related incident not related to payment services), so as to avoid a dual reporting scheme. In this context, this circular also provides the practical modalities according to which financial entities in scope

this circular are required to notify the major ICT-related incidents as well as, if applicable, significant cyber threats to the CSSF. 1 Regulation (EU) 2022/2554

the European Parliament and

the Council

14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 2 Commission Delegated Regulation (EU) 2024/1772

13 March 2024 supplementing Regulation (EU) 2022/2554

the European Parliament and

the Council with regard to regulatory technical standards specifying the criteria for the classification

ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details

reports

major incidents 3 Commission Delegated Regulation (EU) 2025/301

23 October 2024 supplementing Regulation (EU) 2022/2554

the European Parliament and

the Council with regard to regulatory technical standards specifying the content and time limits for the initial notification

, and intermediate and final report on, major ICT-related incidents, and the content

the voluntary notification for significant cyber threats 4 Commission Implementing Regulation (EU) 2025/302

23 October 2024 laying down implementing technical standards for the application

Regulation (EU) 2022/2554

the European Parliament and

the Council with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat CIRCULAR CSSF 25/893 2/8 This circular is divided into four chapters: • Chapter 1 defines the scope

application; • Chapter 2 lists the requirements on classification and reporting

incident and cyber threats for PSPs not under DORA; • Chapter 3 defines the practical modalities for the reporting

major ICT-related incidents and significant cyber threats; • Chapter 4 provides for the entry into force

this circular. CIRCULAR CSSF 25/893 3/8 TABLE

CONTENTS Chapter 1: Scope

application ...................................................................................... 5 Chapter 2: Requirements on classification and reporting

incident and cyber threats for PSPs not under DORA.................................................................................................................. 6 Chapter 3: Practical modalities for major ICT-related incident notification and significant cyber threats reporting ................................................................................................................. 7 Chapter 4: Date

application ........................................................................................ 8 CIRCULAR CSSF 25/893 4/8 Chapter 1: Scope

application 1. The following entities are to be considered as financial entities in the framework

this circular: a) credit institutions, investment firms, market operators operating a trading venue and approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation within the meaning

the Law

5 April 1993 on the financial sector (LFS); b) payment institutions, account information service providers and electronic money institutions within the meaning

the Law

10 November 2009 on payment services (LPS); c) crypto asset service providers and issuers

asset-referenced tokens within the meaning

Regulation (EU) 2023/1114; d) central securities depositories within the meaning

the Law

6 June 2018 on central securities depositories (CSD Law); e) central counterparties within the meaning

the Law

15 March 2016 on OTC derivatives, central counterparties and trade repositories; f) management companies incorporated under Luxembourg law and subject to Chapter 15 or Article 125-2

Chapter 16

, and Luxembourg branches

investment fund managers subject to Chapter 17, and investment companies which did not designate a management company within the meaning

Article 27

the Law

17 December 2010 relating to undertakings for collective investment; g) alternative investment fund managers authorised under Chapter 2 and internally managed alternative investment funds within the meaning

point (b)

Article 4

(1)

the Law

12 July 2013 on alternative investment fund managers (AIFM Law); h) institutions for occupational retirement provisions authorised in accordance with Article 2

(2)

the Law

13 July 2005 on institutions for occupational retirement provision in the form

pension savings companies with variable capital (SEPCAVs) and pension savings associations (ASSEPs); i) administrators

critical benchmarks within the meaning

point (b)

Article 20

(1)

Regulation (EU) 2016/1011; j) crowdfunding service providers within the meaning

the Law

16 July 2019 on the operationalisation

European regulations in the area

financial services; k) Payment Service Providers (PSPs) as referred to in Article 1

(37)

the Law

10 November 2009 on payment services (LPS) that are not financial entities as defined in point 1 (a) and (b) above, i.e. branches in Luxembourg

PSPs incorporated in a third country, and POST Luxembourg. 2. The provisions

Chapter 2

this circular are only applicable to entities in scope as defined in point (k) above, hereafter collectively referred to as “PSPs not under DORA”. 3. The provisions

Chapter 3

this circular are applicable to all financial entities in scope as defined in point 1 (

  1. a)to (
  2. k)above, hereafter collectively referred to as “Financial Entities” or individually as “Financial Entity”, including their branches as specified in the respective laws. CIRCULAR CSSF 25/893 5/8 4. Branches in Luxembourg

the Financial Entities that are part

a legal entity whose head

fice is located in a different Member State

the European Union (EU branches) are expected to report their major ICT-related incidents and significant cyber threats under DORA to the competent authority

that Member State (home Member State) and are therefore excluded from the scope

this circular. Chapter 2: Requirements on classification and reporting

incident and cyber threats for PSPs not under DORA 5. For the purpose

this circular, the following definitions are derived from the DORA regulation and apply for PSPs not under DORA: a) ‘network and information system’ means:

(1)an ‘electronic communications network’: transmission systems, whether or not based on a permanent infrastructure or centralised administration capacity, and, where applicable, switching or routing equipment and other resources, including network elements which are not active, which permit the conveyance

signals by wire, radio, optical or other electromagnetic means, including satellite networks, fixed (circuit- and packet-switched, including internet) and mobile networks, electricity cable systems, to the extent that they are used for the purpose

transmitting signals, networks used for radio and television broadcasting, and cable television networks, irrespective

the type

information conveyed;

(2)any device or group

interconnected or related devices, one or more

which, pursuant to a programme, carry out automatic processing

digital data; or

(3)digital data stored, processed, retrieved or transmitted by elements covered under points
(1)and
(2)for the purposes

their operation, use, protection and maintenance; b) ‘security

network and information systems’ means the ability

network and information systems to resist, at a given level

confidence, any event that may compromise the availability, authenticity, integrity or confidentiality

stored, transmitted or processed data or

the services

fered by, or accessible via, those network and information systems; c) ‘operational or security payment-related incident’ means a single event or a series

linked events unplanned by the financial entities, whether ICT-related or not, that has an adverse impact on the availability, authenticity, integrity or confidentiality

payment-related data, or on the payment-related services provided by the financial entity; d) ‘ICT-related incident’ means a single event or a series

linked events unplanned by the financial entity that compromises the security

the network and information systems, and have an adverse impact on the availability, authenticity, integrity or confidentiality

data, or on the services provided by the financial entity. This includes operational or security payment-related incidents;

  1. e)‘major operational or security payment-related incident’ means an operational or security payment-related incident that has a high adverse impact on the paymentrelated services provided; CIRCULAR CSSF 25/893 6/8
  2. f)‘major ICT-related incident’ means an ICT-related incident that has a high adverse impact on the network and information systems that support critical or important functions

the financial entity. This includes major operational or security paymentrelated incidents; g) ‘cyber threat’ means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users

such systems and other persons; h) ‘significant cyber threat’ means a cyber threat the technical characteristics

🔗 Vers la source officielle

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.