08/27/2026 | Press release | Distributed by Public on 08/27/2026 03:11
As of 17 January 2025, the provisions of the Digital Operational Resilience Act1 ("DORA") are applicable to the financial entities as defined in DORA and supervised by the CSSF. On 17 December 2025, the European Commission confirmed, via an official DORA Q&A2, that DORA is also applicable to third-country branches ("TCBs") in an EU country, if in the third country where their head office is established, they would qualify as entities listed under Article 2(1)(a) to (t) of DORA.
Consequently, an update of a series of circulars published or modified in 2025 is required to include TCBs in the DORA scope.
Furthermore, the CSSF included in the frame of this update a precision regarding the reporting of major ICT-related incidents and cyber threats in case entities cannot use the prescribed communication channel.
The modifications are visualised in purple in the below graphic:
The following modifications have been made to the enumerated circulars:
For any further questions please contact [email protected] or, in case of third-country branches of credit intuitions [email protected].