The classic trap
A definition added to a circular looks harmless, but that is precisely where the trap hides. Since the formal introduction of the DORA Regulation into CSSF 22/806, the CSSF has a precise legal anchor to distinguish what falls under the historical 22/806 regime and what shifts to DORA (EU 2022/2554). In practice, Luxembourg financial entities keep applying an outdated framework (old cloud clauses, old scope) without realising that the DORA entity qualification redefines their ICT obligations. The CSSF then sanctions a scope mismatch: you demonstrate compliance with a text that no longer applies to you.
The dual regime this definition triggers
Adding the DORA definition is not cosmetic: it activates the new four-case architecture of 22/806. You must first know which box you are in, otherwise you apply the wrong requirements.
- Entities subject to DORA: third-party ICT requirements shift under DORA and CSSF 25/882, and the old specific cloud clauses (EEA, resilience) of 22/806 are removed as they are now covered by DORA.
- Entities outside DORA scope: the historical 22/806 regime remains fully applicable, without the DORA references.
- Entities that withdrew their authorisation: a specific transitional regime to verify.
- Management companies under Article 125-1 UCITS: a dedicated treatment not to be confused with the general DORA case.
The concrete risk: reusing an ICT provider register built on the old 22/806, when DORA mandates a harmonised register of information with a precise regulatory format and mandatory fields. The applicable sanctions are not created by 25/883 itself, but the DORA regime applies on top (up to 1% of the average daily turnover for certain ICT breaches).
How Luxgap automates this risk
Our Luxgap DORA Scope Classifier makes the scope error impossible: it automatically determines which of the four cases of CSSF 25/883 your entity falls into, then generates the exact map of applicable requirements. A specialised AI agent reads your CSSF authorisation status, your regulatory references and your third-party ICT services inventory (extracted from your Odoo contracts, supplier invoices and M365 or Azure subscriptions) to qualify each obligation as falling under DORA, the historical 22/806, or both.
- Automatically classifies your entity among the four CSSF 25/883 cases (DORA entity, outside DORA, withdrawn authorisation, Article 125-1 UCITS management company) from your CSSF status.
- Detects obsolete cloud clauses (EEA, resilience) still present in your provider contracts and flags those now covered by DORA and CSSF 25/882.
- Generates the third-party ICT provider register of information in the harmonised DORA format, pre-filled from your connected contractual sources.
- Alerts in real time via Teams as soon as a new third-party ICT service appears in your systems without a criticality qualification or without a compliant DORA clause.
- Produces a timestamped PDF report, enforceable before the CSSF during an inspection, demonstrating consistency between your entity qualification and the regime applied.
Available as a complement to a Luxgap DPO or CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real scope, with a free blind audit within 48h to measure your exposure before any commitment.