Prior notification in case of IT hardware subcontracting
CSSF Circular 21/785
- Replacement of the prior authorisation requirement with a prior notification requirement in the case of hardware IT subcontracting.
- Effective date: 15 October 2021
- Amendments to CSSF circulars 12/552, 17/654, 17/656 & 20/758
- PSF
- Payment institutions
- Electronic money institutions
- Credit institutions
- Investment fund managers subject to CSSF Circular 18/698
Objective
The CSSF's objective is to Simplify the prior communication procedure to IT hardware subcontracting in order to prevent the analysis of requests from hindering the smooth running of the projects of the supervised entities.
Definition of hardware IT subcontracting
Hardware IT outsourcing involves critical or important functions as defined by the EBA's guidelines on outsourcing.
That is to say, functions whose failure would undermine :
- The strength and to the Continuity services and activities of the entity; ;
- The regulatory compliance to which the entity is subject.
Cumulative conditions
For it to be valid, the Notification pre-requis in case of hardware IT subcontracting must fulfil the two cumulative conditions following
- The notification must be communicated at least 3 months before that subcontracting planned will be Effective. The timeframe is 1 month if a PSF is used for support.
- The notification must be made in using the forms available on the website of the CSSF.
In the absence of a reaction from the CSSF, the establishment may implement subcontracting upon expiry of the above-mentioned deadlines (1 or 3 months). However, the CSSF may decide to suspend these deadlines.
Binding measures & sanctions
The CSSF reserves the right to apply binding measures and/or administrative sanctions within the scope of ongoing ex-post supervision if it appears that outsourcing projects do not comply with the applicable legal and regulatory framework.
Cloud computing at group level
From the 15 October 2021, the Stretches The following are applicable when a contract signed with a group-wide cloud computing provider and a Luxembourg entity benefits from cloud computing services:
- The contract may be subject to the law of the country of the signing entity of the group, even if that country is located outside the European Union; ;
- The resilience of cloud computing services in the European Union is no longer a mandatory requirement, but it must be taken into account in the risk analysis of the Luxembourgish entity.
Transitional measures
The procedures and deadlines in place before 15 October 2021 remain applicable to entities that submitted their subcontracting authorisation applications up to and including 31 August 2021.
Entities that submitted their subcontracting authorisation requests between 1 September and 14 October 2021 inclusive may implement the planned subcontracting if the CSSF has not reacted by 15 January 2022.
Useful links
Discover our other publications:

Roadmap: building your GRC framework step by step
An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.

GRC reporting: giving the board an overview
A useful GRC reporting consolidates the work of control functions into a readable view allowing the board to identify developments, areas of concern and decisions to be made.

Data, evidence and traceability: the foundation of a credible system
A credible monitoring system relies on reliable data, structured evidence and an audit trail making it possible to reconstruct decisions and actions throughout the activity.