The classic trap
The trap in Amendment 3 is not textual, it is about classification. CSSF penalises entities that apply the wrong regime to their outsourcing arrangements because they misclassified themselves among the four cases. An entity that believes it is outside DORA keeps applying Part II of 22/806 to its ICT services when DORA actually governs them, and conversely an Article 125-1 management company that assumes DORA applies wrongly drops Part II. The result is an inconsistent ICT outsourcing register, obsolete cloud contractual clauses (the removed EEA clauses) kept out of habit, and outsourcing notifications made under the wrong regime when a CSSF inspection occurs.
The classification test: which case are you in?
The first compliance question is no longer "what must I do", but "who am I within the meaning of Article 2 of DORA". A wrong routing contaminates the entire downstream framework.
- Case a: DORA financial entity supervised by CSSF, formerly fully under 22/806. Part I kept for non-ICT, Part II replaced by DORA and CSSF 25/882 for ICT.
- Case b: 22/806 entity but outside DORA. 22/806 remains fully applicable, Parts I and II, for all outsourcing including ICT.
- Case c: DORA entity to which 22/806 applied only for ICT. Full exit from 22/806, DORA exclusive.
- Case d: management company authorised solely under Article 125-1, Chapter 16 of the UCI Law, excluded from DORA. 22/806 continues to apply fully to ICT.
- Cross-cutting trap: the specific cloud contractual clauses (applicable EEA law, EEA resilience) are removed from 22/806 for DORA cases, as they are now covered by DORA and 25/882. Leaving them in your contracts creates unmanageable contractual duality.
How Luxgap automates this risk
Our Luxgap Outsourcing Regime Classifier makes misclassification impossible: it automatically determines which of the four cases of CSSF 25/883 each entity in your group falls into, then applies the correct corpus (22/806 Part I, Part II, DORA, 25/882) to each outsourcing arrangement. The LLM agent reads your CSSF authorisation, your status under Article 2 of DORA and Article 125-1 of the UCI Law, cross-references your outsourcing register in Odoo or ServiceNow and your supplier contracts, and reassigns each line to the exact regime, with no form to fill in.
- Classifies each supervised entity into one of the four cases a, b, c, d of 25/883 based on its authorisation and DORA status, and alerts on any change of scope.
- Detects ICT outsourcing arrangements still mapped to Part II of 22/806 when DORA applies, and vice versa, by scanning your connected outsourcing register.
- Identifies obsolete cloud contractual clauses (applicable EEA law, EEA resilience) removed from 22/806 and flags contracts to realign on DORA and CSSF 25/882.
- Generates a unified outsourcing register where each relationship carries its applicable regime and the exact legal basis (DORA article or 22/806 point).
- Produces a timestamped PDF report enforceable before CSSF demonstrating that the four-case classification has been performed and documented.
Available as a complement to a Luxgap CISO or DPO mandate or as a dedicated SaaS module depending on your scope. Request a personalised quote and our teams will prepare a demonstration on your real outsourcing register, with a free blind audit within 48h to measure your exposure before any commitment.