Skip to content
Cyvalent
Back to resources

DORA Supplier Risk in Luxembourg: From Messy Supplier Lists to a Register You Can Defend

Published

DORA's ICT third-party risk rules—Articles 28–30 of Regulation (EU) 2022/2554—have applied directly since 17 January 2025 1. In Luxembourg, the Law of 1 July 2024 gives the CSSF and CAA the powers needed to supervise and sanction DORA compliance and transposes Directive (EU) 2022/2556 2. CSSF-supervised DORA entities must also follow the local requirements in Circular CSSF 25/882 5; CAA-supervised entities follow the CAA's DORA instructions 6.

The practical problem is rarely that a security manager has never heard of DORA. The problem is the gap between a supplier list and a defensible operating model. Supplier names may exist. Contract owners may be known. Risk assessments may have been performed. But when a supervisor asks for a Register of Information that ties providers, services, contractual arrangements, supported functions, and criticality together, the gap becomes visible 1 3 4.

This article explains what DORA Articles 28-30 require operationally, what the Register of Information is, and how to move from a static supplier list to a supplier-risk posture that can be maintained.

In this article, 'supplier risk' means risk arising from ICT third-party service providers. It does not cover every commercial supplier. An entity should first confirm that it falls within DORA's scope and identify which Luxembourg authority receives its reporting.

What DORA Articles 28-30 Require

DORA's third-party ICT risk framework is structured around several linked obligations. For Luxembourg entities within DORA's scope, the legal duties sit primarily with the financial entity. ICT providers are brought into the framework mainly through contractual, information, audit and cooperation requirements. CSSF-supervised entities should read these duties together with Circular CSSF 25/882, while CAA-supervised entities should follow the CAA's DORA instructions. EU oversight of designated critical ICT providers is a separate layer 1 5 6.

Article 28: general principles and governance. Financial entities remain responsible for compliance when they use ICT third-party service providers, must manage ICT third-party risk as an integral component of ICT risk, and must maintain a register of information for contractual arrangements on ICT services 1. Article 28 is also the basis for mapping ICT services to the functions they support and for assessing risks such as dependency and concentration. Before signing an ICT-service arrangement, the entity must also determine whether it supports a critical or important function, assess the relevant risks and supervisory conditions, perform provider due diligence, and identify conflicts of interest 1.

Article 29: preliminary assessment of ICT concentration risk. For an arrangement supporting a critical or important function, the financial entity must consider whether the provider is difficult to replace or whether the arrangement would add to multiple dependencies on the same—or closely connected—providers. It must weigh realistic alternatives and, where relevant, consider subcontracting chains, third-country enforcement, insolvency and urgent data recovery 1.

Article 30: key contractual provisions. DORA creates two layers. Every ICT-service arrangement must cover matters such as the services and functions provided, service and data-processing locations, data protection and recovery, service levels, incident assistance, cooperation with authorities, termination rights and relevant training. Contracts supporting critical or important functions need additional provisions, including measurable service levels, material-change notices, contingency and security requirements, TLPT cooperation, access and audit rights, and workable exit and transition arrangements 1.

These duties cut across procurement, IT, risk, legal and business ownership. They work only when those teams maintain one consistent set of data and evidence.

The Register of Information

The Register of Information is the structured record that ties the third-party ICT risk programme together. DORA Article 28(3) requires financial entities to maintain and update a register of information in relation to all contractual arrangements on ICT services provided by ICT third-party service providers 1. Commission Implementing Regulation (EU) 2024/2956 specifies the standard templates, instructions and supporting code lists in Annexes I–IV for registers maintained at entity, sub-consolidated and consolidated level 3.

For CSSF-supervised DORA entities, Circular CSSF 25/882 sets practical rules for notifying planned arrangements that support critical or important functions and for annual Register submission. Circular 25/883 removed the main overlap with Circular 22/806: for DORA entities, Circular 22/806 now principally governs business-process outsourcing, while ICT third-party services fall under DORA and Circular 25/882. Circular 22/806 continues to cover ICT outsourcing for non-DORA entities, subject to the specific exceptions stated in the circular 5.

Insurance and reinsurance entities supervised by the CAA should instead use CAA Circular Letter 25/1 and the current CAA reporting calendar for their local reporting route 6.

For the 2026 CSSF collection, relevant entities—excluding institutions under the ECB's direct supervision—had to submit through eDesk between 11 February and 31 March 2026, using 31 December 2025 as the reference date. The CAA's 2026 calendars set a 1 March 2026 deadline for insurers, reinsurers and relevant groups, with submission through SOFiE or E-File. Dates and channels are set for each reporting cycle, so readers should always check the latest notice from their competent authority 4 6.

The Register is not a filing that can be created once and forgotten. The regulatory templates capture providers, contractual arrangements, ICT services, supported functions, criticality, entity relationships and the other prescribed fields. Internally, it is useful to maintain an owner, source system, validation date and remediation status alongside that data. Those are governance controls, however—not automatically additional fields in the submitted Register 3 8.

Five Layers Between Supplier List and Defensible Register

A defensible Register of Information usually requires five layers of work.

1. Function mapping. Each ICT service should be linked to the function it supports; an entity may also map that function to its internal processes and service owners. Criticality classification depends on that connection, and DORA's third-party risk framework is built around ICT services supporting critical or important functions 1.

2. Criticality classification. Every ICT-service arrangement needs a proportionate pre-contract assessment and provider due diligence. Classification then determines which enhanced requirements apply—for example, the Article 29 concentration assessment and the additional Article 30(3) clauses for services supporting critical or important functions 1.

3. Arrangement and concentration-risk assessment. Assess each contractual arrangement, then aggregate dependencies across the same or closely connected providers. Consider substitutability, relevant subcontractors, third-country exposure and the practical cost and time needed to move the service 1 7. A financial entity with multiple critical services dependent on one hyperscaler has a different exposure from one with genuinely diversified dependencies.

4. Contractual compliance check. Review every ICT-service contract against Article 30(2), then apply the additional Article 30(3) checklist where the service supports a critical or important function. For each gap, record the affected clause, owner, remediation route and target date. This turns legacy-contract issues into a manageable plan 1.

5. Ongoing monitoring. DORA third-party risk is continuous. Where ICT services supporting critical or important functions are subcontracted, Commission Delegated Regulation (EU) 2025/532 adds specific due-diligence, contractual, notification and ongoing-assessment requirements 7. Providers change services, locations, subcontractors, ownership, risk posture, and contractual terms. The Register and the underlying risk file need to change with them 1 3.

Where Cyvalent 360 Cyber Services and Cyvalent RGX Fit

Cyvalent 360 Cyber Services / CISOaaS helps run the process: mapping ICT services to supported functions, classifying criticality, assessing arrangements and concentration risk, reviewing contract clauses, preparing Register evidence, and coordinating remediation with business owners, procurement, legal and risk.

Cyvalent RGX keeps the supplier-risk view current: obligations, evidence, contract-review status, controls and open gaps in one place. When providers, services or contracts change, teams can see what changed and what needs action.

For a Luxembourg-ready Register process, Cyvalent 360 Cyber Services can help build and maintain the evidence and operating routine. Cyvalent RGX helps teams track the supporting evidence, decisions and remediation over time.

In short

  • DORA applies directly in Luxembourg. The Law of 1 July 2024 gives the CSSF and CAA national supervisory and sanctioning powers, while the submission route depends on the entity’s competent authority. [1] [2] [5] [6]
  • Articles 28-30 are governance, risk, contract, and evidence duties — not just procurement: the financial entity stays responsible for compliance even when it relies on ICT third-party providers.
  • The Register of Information (Article 28(3), with standard templates set by Commission Implementing Regulation (EU) 2024/2956) is the maintained record that ties providers, services, contractual arrangements, supported functions, and criticality together.
  • Moving from a supplier list to a defensible register takes five layers: function mapping, criticality classification, arrangement and concentration-risk assessment, contractual-compliance check, and ongoing monitoring.

Working towards a defensible Register of Information?

If you are building a Register of Information for your Luxembourg competent authority, discuss the scope and operating model with Cyvalent — through founder-led 360 Cyber Services / CISOaaS and the Cyvalent RGX cyber GRC platform.

Frequently asked questions

What do DORA Articles 28-30 require?

Article 28 sets the governance, Register, pre-contract assessment, due-diligence and ongoing risk-management duties. Article 29 adds a concentration-risk assessment for arrangements supporting critical or important functions, including substitutability and multiple dependencies on the same or closely connected providers. Article 30 sets baseline clauses for all ICT-service arrangements and additional clauses for those supporting critical or important functions. [1]

What is the DORA Register of Information?

It is the structured record that ties the third-party ICT risk programme together. Article 28(3) requires financial entities to maintain and update a Register covering all contractual arrangements for ICT services provided by ICT third-party service providers. Commission Implementing Regulation 2024/2956 specifies the templates, instructions and supporting codes in Annexes I–IV, at entity, sub-consolidated or consolidated level. It is strongest when it reflects a living operating process rather than a one-time spreadsheet. [1] [3] [8]

Does DORA apply in Luxembourg, and who supervises it?

Yes. DORA has applied directly since 17 January 2025. Luxembourg's Law of 1 July 2024 gives the CSSF and CAA the national powers needed to supervise and sanction compliance and transposes Directive (EU) 2022/2556. Circular CSSF 25/882 applies to the CSSF-supervised DORA entities listed in its scope; CAA-supervised entities should use CAA Circular Letter 25/1 and the CAA's reporting instructions. For Register submission, current CSSF guidance separately addresses entities under the ECB's direct supervision. [1] [2] [5] [6]

When does the Register of Information have to be submitted in Luxembourg?

The deadline depends on the competent authority and reporting cycle. For the 2026 CSSF collection, the eDesk window ran from 11 February to 31 March 2026 and excluded entities under the ECB's direct supervision. The CAA's 2026 calendars set a 1 March deadline for relevant insurers, reinsurers and groups using SOFiE or E-File. Always check the latest CSSF or CAA notice rather than treating either date as permanent. [4] [6]

How do I move from a supplier list to a defensible DORA register?

Through five layers of work: (1) function mapping — link each ICT service to the business function it supports; (2) criticality classification — separate services supporting critical or important functions from the rest; (3) arrangement and concentration-risk assessment, including the Article 29 concentration-risk check; (4) contractual-compliance check against Article 30, since many contracts pre-date DORA; and (5) ongoing monitoring, because providers change services, locations, subcontractors, ownership, and terms, and the Register has to change with them.

What must DORA ICT-service contracts include?

Article 30(2) sets the baseline for all ICT-service arrangements, including the service scope, locations, data protection and recovery, service levels, incident assistance, cooperation with authorities and termination rights. Article 30(3) adds requirements for services supporting critical or important functions, including measurable service levels, contingency and security commitments, TLPT cooperation, audit and access rights, and exit arrangements. [1]

Sources & References

Last checked:

EU legislation

  1. [1] European Parliament and Council. Regulation (EU) 2022/2554 (DORA) — Article 2 (scope), Articles 28-30 (ICT third-party risk and contractual arrangements), Article 46 (competent authorities) and Article 64 (application from 17 January 2025). Source: EUR-Lex. https://eur-lex.europa.eu/legal-content/ENG/TXT/?uri=CELEX%3A32022R2554

  2. [3] European Commission. Commission Implementing Regulation (EU) 2024/2956 — standard templates, instructions and codes for the Register of Information; includes the corrigendum published on 19 September 2025. Current EUR-Lex text. https://eur-lex.europa.eu/eli/reg_impl/2024/2956/2024-12-02/eng

  3. [7] European Commission. Commission Delegated Regulation (EU) 2025/532 — risk assessment and contractual requirements when ICT services supporting critical or important functions are subcontracted. Source: EUR-Lex. https://eur-lex.europa.eu/eli/reg_del/2025/532/oj

Luxembourg authorities

  1. [2] Luxembourg. Law of 1 July 2024 implementing Regulation (EU) 2022/2554 and transposing Directive (EU) 2022/2556 (Mémorial A No 271) — national powers of the CSSF and CAA, sanctions and amendments to sectoral financial laws. Sources: Legilux and CSSF explanatory notice. https://legilux.public.lu/eli/etat/leg/loi/2024/07/01/a271/jo and https://www.cssf.lu/en/2024/07/luxembourg-dora-law-published-in-the-official-journal/

  2. [4] CSSF. DORA — Submission timeframe for Register of Information — eDesk Portal open as of 11 February 2026 — the 2026 window ran from 11 February to 31 March, with reference date 31 December 2025, and excluded entities under direct ECB supervision. https://www.cssf.lu/en/2026/02/dora-submission-timeframe-for-register-of-information-edesk-portal-open-as-of-11-february-2026/

  3. [5] CSSF. Circular CSSF 25/882 on the use of ICT third-party services by DORA entities and Circular CSSF 25/883 amending Circular 22/806. Sources: CSSF, with framework overview. https://www.cssf.lu/en/Document/circular-cssf-25-882/ and https://www.cssf.lu/en/Document/circular-cssf-25-883/ and https://www.cssf.lu/en/2025/04/updates-of-several-cssf-circulars-related-to-ict-risk-management-and-use-of-ict-third-parties-ict-outsourcing/

  4. [6] Commissariat aux Assurances. Circular Letter 25/1 concerning DORA and the current CAA Register reporting calendars (2026 solo and group). Source: CAA. https://www.caa.lu/uploads/documents/files/LC25-01_FR.pdf and https://www.caa.lu/uploads/documents/files/Calendrier_Reportings_CAA_2026_VD.pdf and https://www.caa.lu/uploads/documents/files/Calendrier_Reportings_CAA_2026_G.pdf

  5. [8] CSSF. Guide concerning the submission of the DORA Register of Information — practical guidance on its composition, content and validation. https://www.cssf.lu/en/Document/cssf-guide-concerning-the-submission-of-dora-register-of-information/

Related reading