The CSSF Circular 24/847 establishes a new ICT-related incident reporting system with the goal of obtaining a more comprehensive and organised understanding of the characteristics, occurrence rate, importance, and consequences of ICT-related incidents. This initiative also takes into account the escalating ICT and security threats within the framework of an increasingly interconnected global financial system.

Scope and Implementation Date

Universal Provisions Circular, Chapter 2 apply to all Supervised Entities listed below, including their Luxembourg branches and third-country entities with Luxembourg branches.

Specific Provisions (Chapter 3 of Circular) under NIS Law and CSSF Regulation No 24-01 apply to Supervised Entities identified as OES (Operators of Essential Services) or DSP (Digital Service Providers).

The CSSF circular is applicable (and replaces CSSF circular 11/504) from 1 April 2024 for

  • Credit institutions;
  • Financial sector professionals as defined by the LFS:
    • Investment firms;
    • Specialised PFS;
    • Support PFS.
  • Approved publication arrangements (APAs) with a derogation and authorised reporting mechanisms (ARMs) with a derogation;
  • Payment institutions and electronic money institutions as defined by the LPS;
  • POST Luxembourg ;
  • Central counterparties (CCPs);
  • Central securities depositories;
  • Administrators of critical benchmarks;
  • Crowdfunding Service Providers;
  • Credit institutions and financial market infrastructures identified as OES.;
  • Support PSFs that have been informed by the CSSF of their consideration as DSPs under the NIS Law.

 

The CSSF circular is applicable (and replaces CSSF circular 11/504) from 1 June 2024 for

  • Management companies (Chapter 15 & Chapter 16);
  • Luxembourg branches of IFMs subject to Chapter 17 of the UCITS Law;
  • Investment companies that did not appoint a management company;
  • Alternative investment fund managers authorised under Chapter 2 of the Law on Alternative Investment Fund Managers;
  • Internally managed alternative investment funds.

Significant changes to the current incident reporting system:

  1. Expansion of Incident Coverage: The existing incident reporting scope, limited to fraud and incidents resulting from external cyber attacks, as outlined in CSSF Circular 11/504, is expanded to encompass a broader range of ICT operational and security incidents.
    This expansion aims to prevent duplicate reporting for incidents that should be reported under other incident notification frameworks.

  2. Classification-Based Reporting Supervised Entities will now be required to classify ICT-related incidents based on predefined criteria set out in this Circular. Additionally, they must notify the CSSF of incidents classified as major or significant.
    This classification-based approach enhances the granularity of incident reporting.

     

  3. Introduction of a New Notification Form To streamline the collection of structured data, Supervised Entities must complete and submit an ICT-related incident notification form in instances where an ICT-related incident is classified as major or significant.
    This form helps with the reporting process and makes sure the data collected is consistent.

     

  4. Incorporation of NIS Law Requirements A specific chapter is included in this Circular to consolidate incident notification requirements that were previously communicated via bilateral communications to Supervised Entities falling under the jurisdiction of the NIS Law. This integration allows for the application of the new incident reporting notification forms and practical requirements to incidents that have been assessed as significant under the NIS Law.
    This alignment ensures a unified and comprehensive approach to incident reporting and compliance.

Incidents requiring notification

  • Any successful unauthorised access to networks and information systems;
  • Other incidents deemed major according to section 2.2 of CSSF Circular 24/847

Useful Resources

Discover our other publications: