CSSF Circular 21/777
- Outsourcing to cloud service providers
- Implementation of the European Securities and Markets Authority (ESMA) guidelines on outsourcing to CLOUD service providers, by amending the scope of CSSF Circular 17/654 as amended
Objective of CSSF Circular 21/777
The objective of CSSF Circular 21/777 is to se to comply with ESMA guidelines relating to outsourcing to service providers in Cloud (ESMA reference 50-164-4285) and apply them.
The CSSF has already implemented some orientations equivalent to those of the ESMA via CSSF Circular 17/654 as amended.
Therefore, only the scope of CSSF Circular 17/654 as amended has been broadened in order to include all entities targeted by the ESMA guidelines.
New scope of CSSF Circular 17/654 as amended
- Support PFS
- Specialised PFS
- Investment fund managers
- Investment companies
- Payment institutions
- Credit institutions
- Electronic money institutions
- Central Securities Depositories (CSDs)
- Undertakings for Collective Investment in Transferable Securities (UCITS)
- Data communication providers (DCPS)
In practice
Nothing changes regarding outsourcing to cloud service providers for entities that were already subject to CSSF Circular 17/654 as amended.
The new entities targeted by CSSF Circular 17/654 as amended must:
- For the 31 July 2021 : Apply CSSF Circular 17/654 as amended to all cloud service subcontracts concluded, renewed or amended from this date onwards.
- For the 31 December 2022 : Amend and modify existing agreements outsourcing of CLOUD services in order to ensure that Circular CSSF 17/654, as amended, is taken into account.
Entities that have not completed the review of their Cloud service subcontracting agreements for important or critical functions by 31 December 2022 must inform their competent authority, indicating the measures planned to conclude the review or their withdrawal strategy.
ESMA's guidelines
The ESMA guidelines on outsourcing to CLOUD service providers aims to help businesses and competent authorities to identifier, treat and monitor the risks and challenges arising from CLOUD service subcontracting agreements, from the decision to outsource to the implementation of withdrawal strategies, including the selection of a cloud service provider and the monitoring of outsourced activities.
L'ESMA describe les orientations following
- 1. Governance, supervision and documentation;
- Pre-contractual analysis and due diligence procedure;
- 3. Key contractual elements;
- 4. Information Security;
- 5. Withdrawal strategies;
- 6. Access and audit rights;
- 7. Sub-subcontracting;
- 8. Written notification to the competent authorities;
- 9. Monitoring of cloud service subcontracting agreements.
Useful links
Discover our other publications:

Uncategorised
Roadmap: building your GRC framework step by step
An effective GRC framework is built progressively, from the diagnosis of the existing state to consolidation, by adapting each step to the maturity, size and priorities of the organisation.
19 August 2026

Uncategorised
GRC reporting: giving the board an overview
A useful GRC reporting consolidates the work of control functions into a readable view allowing the board to identify developments, areas of concern and decisions to be made.
19 August 2026

Uncategorised
Data, evidence and traceability: the foundation of a credible system
A credible monitoring system relies on reliable data, structured evidence and an audit trail making it possible to reconstruct decisions and actions throughout the activity.
19 August 2026