CSSF Circular 21/777
- Outsourcing to cloud service providers
- Implementation of the European Securities and Markets Authority (ESMA) guidelines on outsourcing to CLOUD service providers, by amending the scope of CSSF Circular 17/654 as amended
Objective of CSSF Circular 21/777
The objective of CSSF Circular 21/777 is to se to comply with ESMA guidelines relating to outsourcing to service providers in Cloud (ESMA reference 50-164-4285) and apply them.
The CSSF has already implemented some orientations equivalent to those of the ESMA via CSSF Circular 17/654 as amended.
Therefore, only the scope of CSSF Circular 17/654 as amended has been broadened in order to include all entities targeted by the ESMA guidelines.
New scope of CSSF Circular 17/654 as amended
- Support PFS
- Specialised PFS
- Investment fund managers
- Investment companies
- Payment institutions
- Credit institutions
- Electronic money institutions
- Central Securities Depositories (CSDs)
- Undertakings for Collective Investment in Transferable Securities (UCITS)
- Data communication providers (DCPS)
In practice
Nothing changes regarding outsourcing to cloud service providers for entities that were already subject to CSSF Circular 17/654 as amended.
The new entities targeted by CSSF Circular 17/654 as amended must:
- For the 31 July 2021 : Apply CSSF Circular 17/654 as amended to all cloud service subcontracts concluded, renewed or amended from this date onwards.
- For the 31 December 2022 : Amend and modify existing agreements outsourcing of CLOUD services in order to ensure that Circular CSSF 17/654, as amended, is taken into account.
Entities that have not completed the review of their Cloud service subcontracting agreements for important or critical functions by 31 December 2022 must inform their competent authority, indicating the measures planned to conclude the review or their withdrawal strategy.
ESMA's guidelines
The ESMA guidelines on outsourcing to CLOUD service providers aims to help businesses and competent authorities to identifier, treat and monitor the risks and challenges arising from CLOUD service subcontracting agreements, from the decision to outsource to the implementation of withdrawal strategies, including the selection of a cloud service provider and the monitoring of outsourced activities.
L'ESMA describe les orientations following
- 1. Governance, supervision and documentation;
- Pre-contractual analysis and due diligence procedure;
- 3. Key contractual elements;
- 4. Information Security;
- 5. Withdrawal strategies;
- 6. Access and audit rights;
- 7. Sub-subcontracting;
- 8. Written notification to the competent authorities;
- 9. Monitoring of cloud service subcontracting agreements.
Useful links
Discover our other publications:

Uncategorised
AMLA: the new European authority at the heart of AML/CFT supervision
Scope, governance, KYC due diligence, beneficial ownership, suspicious activity reports, and cash payments: the key contributions of the AMLR.
15 July 2026

Uncategorised
AMLR: The European regulation to be directly applicable from 10 July 2027
Scope, governance, KYC due diligence, beneficial ownership, suspicious activity reports, and cash payments: the key contributions of the AMLR.
15 July 2026

Uncategorised
AMLD6: How Directive (EU) 2024/1640 is reorganising the European AML/CFT framework
Discover the role of AMLD6, its transposition timeline, and its consequences for the FIUs, registries, supervisors and obliged entities.
15 July 2026