Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

29 articles found · #cssf

CSSF 26/906: governance and DORA-grade immutable backups by June 30

CSSF 26/906 requires PSPs/EMIs to reassess governance and risk management by 30 June 2026. Immutable, isolated backups are the DORA-proof of ransomware resilience.

European Commission cloud attack — CSPM as a key control under CSSF 22/806

On March 27, 2026, the European Commission confirmed an intrusion and data exfiltration affecting Europa.eu’s cloud infrastructure. How CSPM meets CSSF 22/806 requirements and prevents such scenarios.

DORA — Third-country branches: ICT register due by June 30

DORA’s final stretch in Luxembourg: third‑country bank branches must submit their ICT register to the CSSF by June 30, 2026 at the latest. Here is how to get it done this week.

CSSF — Axios compromised (31/03/2026): EDR/XDR to detect and notify under DORA

The CSSF warns about the Axios supply‑chain compromise and reminds firms to notify a major ICT incident under Circular 25/893 (DORA). Here is how an EDR/XDR stack helps detect, contain, and notify on time.

GDPR Article 28: Belgian DPA fines SWDE — your DPA must be rock-solid

On 12 May 2026, the Belgian DPA fined SWDE €86,000, including €1,000 for lacking an Article 28-compliant DPA. Key takeaway: without a complete DPA, any outsourced processing leaves the controller non-compliant.

CSSF 25/880 — the 2026 PSP ICT Assessment requires continuous VM

The CSSF opened the 2026 “PSD2 – PSP ICT Assessment” campaign: every PSP must submit an up‑to‑date ICT risk assessment via eDesk. Continuous vulnerability management aligns with NIS 2 Art. 21 and DORA Arts. 25–27.

ANSSI risk analysis on encryption: actions for GDPR Art. 32 and CSSF 22/806

On 27/05/2026, ANSSI released an encryption risk analysis. This article turns the guidance into an at‑rest and in‑transit architecture aligned with GDPR Art. 32 and CSSF 22/806, including a post‑quantum roadmap.

DORA Art. 28: CSSF turns up the heat on the ICT dependencies register

As of 16 March 2026, only 40% of entities had filed their DORA Art. 28 register. CSSF warns: ESAs’ quality checks, potential rejections and tight resubmission windows, with a 30 June “best effort” for some branches.

CSSF: requirements of the review on illiquid asset valuation

On 4 June 2026, the CSSF released a feedback report on illiquid asset valuation at IFMs. It requires immediate benchmarking of practices and documented corrective measures.

CSSF — Circular 25/893: tightened ICT alerting and reporting under DORA

The CSSF tightens ICT incident classification and notification under DORA via eDesk. Here is how an EDR/XDR stack enables timely detection, qualification, and reporting with harmonized deadlines.

CSSF 25/883 amends 22/806: continuous cloud oversight

On 9 April 2025, the CSSF adjusted 22/806 via 25/883 to align ICT outsourcing with DORA. Here’s how a robust CSPM prevents cloud leaks and demonstrates compliance.

CSSF: DORA takes precedence and clarifies ICT outsourcing (Apr 2025)

CSSF confirmed DORA’s primacy from 17 January 2025 and issued Circular 25/882 to govern third‑party ICT use, the Article 28 register of information, and incident notifications via eDesk.

← Newer Page 2 / 3 Older →