Skip to content
sitraka.lu

noteLuxembourg operations · for US groups

DORA for US firms with Luxembourg operations

If you run a fund platform, a ManCo or a branch in Luxembourg for a US group, DORA is not somebody else's compliance file. It applies to your Luxembourg entity because of the licence that entity holds, not because of where your head office sits, and since 27 August 2026 the CSSF has confirmed in writing that it reaches third-country branches too.

This is a practitioner's read, written from Luxembourg, for people who have to answer a US board asking why an EU regulation is suddenly on the operations agenda. Every figure, article number and circular below was checked against its primary source on the date shown, and every source is linked at the bottom so you can verify rather than trust.

Every figure, article number and circular below was checked against its primary source on 30 August 2026. Regulatory references move: re-check the linked sources before relying on a date or a deadline.

The Grande-Duchesse Charlotte bridge and the Kirchberg financial district in Luxembourg
Cayambe · CC BY-SA 3.0

Why this lands on a US desk

Luxembourg is where American asset managers keep their European fund range, and the numbers are not marginal. In the CSSF's origin-of-initiators statistics for 30 June 2026, US-based initiators account for EUR 1,309.608 billion of net assets, 19.4 % of the EUR 6,731.325 billion held by Luxembourg undertakings for collective investment, ahead of the UK and Germany. By number of funds Germany leads; by money, the US does.

DORA's scope is drawn by the entity's own EU authorisation. Article 2(1) lists managers of alternative investment funds and management companies among the covered entities: a Luxembourg AIFM or ManCo owned by a US group is in scope on its own account, and the nationality of the parent changes nothing.

The newest development is the one most US groups have not yet priced in. Following a European Commission DORA Q&A of 17 December 2025, the CSSF published Circular 26/915 on 27 August 2026: third-country branches in Luxembourg fall under DORA where their head office would qualify as an entity listed in Article 2(1)(a) to (t). The circular applies with immediate effect, brings those branches into Circulars 25/882, 25/892 and 25/893, and pulls them out of the old ICT-outsourcing regime.

  • Scope follows the Luxembourg licence, not the parent's passport.
  • Third-country branches: in scope, confirmed and effective immediately (Circular CSSF 26/915, 27 August 2026).
  • US initiators are the largest national group behind Luxembourg funds by net assets (19.4 % at 30 June 2026).

What DORA actually is, in one screen

DORA is Regulation (EU) 2022/2554, adopted 14 December 2022. It entered into force on 16 January 2023 and has applied since 17 January 2025, so the transition period is behind us: this is live supervision, not preparation.

The five pillars people refer to are simply Chapters II to VI of the regulation: ICT risk management; ICT-related incident management, classification and reporting; digital operational resilience testing; management of ICT third-party risk; and information-sharing arrangements.

Two useful pieces of nuance that get lost in vendor decks. First, threat-led penetration testing (Article 26) is not a universal obligation: only entities identified by their competent authority must run it, then at least every three years, on live production systems. Second, information sharing (Article 45) is voluntary in substance but carries one mandatory step: you must notify the authority when you join such an arrangement, and when you leave it.

The trap: your own parent company is a third party

This is the point that surprises US groups most often. DORA defines an ICT third-party service provider in Article 3(19) as, simply, an undertaking providing ICT services. Article 3(20) then defines an ICT intra-group service provider as one inside the financial group providing ICT services to entities of that same group, expressly including parent undertakings, subsidiaries and branches.

Recital 31 removes the escape hatch: intra-group provision of ICT services should not be automatically considered less risky than provision from outside the group, and should be subject to the same regulatory framework. If your Luxembourg ManCo runs on a data centre, a service desk or an application platform operated by the US parent, that is a contractual arrangement DORA expects to see documented.

The register-of-information standard, Commission Implementing Regulation (EU) 2024/2956, is built on that assumption. Template B_02.03 exists precisely to link intra-group arrangements to arrangements with providers outside the group, and the supply-chain template B_05.02 requires you to name at least the first subcontractor outside the group, even when the service does not support a critical or important function.

And Article 28(1)(a) closes it: the financial entity remains fully responsible for compliance at all times. You cannot delegate the obligation upward to the parent that provides the service.

  • Intra-group IT is an ICT third-party arrangement, not an internal matter.
  • It must appear in the register, with the first extra-group subcontractor named.
  • Responsibility stays with the Luxembourg entity, whoever operates the platform.

Two clocks a US compliance team will find unfamiliar

The incident clock is the sharpest cultural difference. Under Article 5 of Commission Delegated Regulation (EU) 2025/301, an initial notification of a major ICT-related incident is due as early as possible and in any case within four hours of classifying it as major, and no later than 24 hours from becoming aware of it. The intermediate report follows within 72 hours of that initial notification, and the final report within one month of the intermediate one. Each stage runs from the previous filing, not from the incident.

Compare that with the US public-company rule most American groups have internalised: an Item 1.05 Form 8-K within four business days of determining an incident is material. Four hours against four business days is not a difference of degree; it changes who has to be reachable, and when.

The second clock is the register of information. The standing rule set by Circular CSSF 25/882 is that the register for year n covers all arrangements contracted to the end of that year and is submitted between 28 February and 31 March of year n+1. For the 2026 cycle the CSSF opened the eDesk window from 11 February to 31 March 2026 with a reference date of 31 December 2025, and warned that the ESA validation checks would be applied to more data fields than last year, so a register accepted one year can be rejected the next.

  • Major incident: 4 hours to notify after classification, 24 hours maximum after awareness.
  • Intermediate report at 72 hours, final report at one month, each counted from the previous filing.
  • Register of information: submitted via the CSSF eDesk portal, in the annual late-February to 31 March window.

Why the gap with US practice is widening, not closing

A US group might reasonably have assumed that domestic cyber rules would converge with DORA. They have not. On 17 June 2025 the SEC formally withdrew fourteen proposed rulemakings, stating it did not intend to issue final rules on them. The withdrawn set includes both the March 2022 cybersecurity risk-management proposal for investment advisers, registered investment companies and BDCs, and the April 2023 proposal for broker-dealers and other market entities. A search of Federal Register cybersecurity rulemakings from that date to 30 August 2026 returns no replacement.

The practical consequence for a US asset manager is a split house: the American entities work under a disclosure-centric regime aimed at materiality and investors, while the Luxembourg entity works under a resilience-centric regime aimed at supervisors, with hard operational clocks, a contractual register and testing obligations. Running one global policy and hoping it satisfies both is how firms discover, during an incident, that it does not.

The Luxembourg specifics you will be asked about

Luxembourg's DORA law of 1 July 2024 designates two national competent authorities: the CSSF for financial entities, and the Commissariat aux Assurances for insurance and reinsurance, which confirmed its own competence in Circular Letter 25/1 of 14 January 2025.

For CSSF-supervised entities, the register of information is submitted through the eDesk portal as plain CSV files inside a zip archive, following the folder structure and naming convention defined by the ESAs. Incident and significant-cyber-threat reporting runs through the eDesk procedure set out in Circular CSSF 25/893 of 27 May 2025, or through the CSSF's API.

Circular CSSF 25/883 of 9 April 2025 rewrote how the old outsourcing regime interacts with DORA: for the entities concerned, Part I of Circular 22/806 still governs non-ICT outsourcing, while the ICT outsourcing part gives way to DORA. If your Luxembourg governance documents still describe ICT outsourcing under 22/806 alone, they are out of date.

One last piece of context for a board: on 18 November 2025 the European Supervisory Authorities published the first list of designated critical ICT third-party service providers under Article 31(9). Nineteen providers were designated. If your platform depends on one of them, oversight of that provider now happens at Union level as well as through your own contract.

Where I fit

I work on observability and operational resilience for the Luxembourg financial sector, and I am the co-founder of LuxAIOps. The questions above are the ones I get asked in practice: what evidence a supervisor actually accepts, how to make an incident timeline provable rather than asserted, and how to describe an intra-group platform in a register without inventing controls you do not have. If that is your problem this quarter, get in touch.

See how I work →

FAQ

Does DORA apply to a US firm?
Not directly to the US entity, but to its EU-authorised entities. A Luxembourg AIFM, management company or investment firm owned by a US group is in scope on its own account under Article 2(1) of Regulation (EU) 2022/2554, because scope follows the licence rather than the owner's nationality. Since Circular CSSF 26/915 of 27 August 2026, third-country branches in Luxembourg are also covered where their head office would qualify as a listed entity type.
Do IT services from our US parent count under DORA?
Yes. Article 3(20) defines an ICT intra-group service provider to include provision to parent undertakings, subsidiaries and branches, and Recital 31 says intra-group services must not be automatically treated as less risky. They belong in the register of information, and the supply-chain template requires naming at least the first subcontractor outside the group.
How fast must a major ICT incident be reported in the EU?
Within four hours of classifying it as major and no later than 24 hours after becoming aware of it, then an intermediate report within 72 hours of that notification and a final report within one month, under Article 5 of Commission Delegated Regulation (EU) 2025/301. For comparison, the US public-company rule allows four business days from a materiality determination.
When is the DORA register of information due in Luxembourg?
The standing rule in Circular CSSF 25/882 is that the register for a given year is submitted between 28 February and 31 March of the following year, through the CSSF eDesk portal. For the 2026 cycle the window ran from 11 February to 31 March 2026, with 31 December 2025 as the reference date.

Sources

Primary sources only, fetched and read in full rather than summarised. Checked 30 August 2026.

  • DORA (the regulation) · Regulation (EU) 2022/2554 of 14 December 2022, in force 16 January 2023, applicable from 17 January 2025 (Article 64); scope in Article 2, definitions in Article 3, pillars in Chapters II-VI
  • Incident reporting deadlines · Commission Delegated Regulation (EU) 2025/301 of 23 October 2024, Article 5 (4 hours / 24 hours / 72 hours / one month)
  • Register of information · Commission Implementing Regulation (EU) 2024/2956, templates B_02.03 (intra-group links) and B_05.02 (ICT service supply chains)
  • Third-country branches in scope · Circular CSSF 26/915 of 27 August 2026, giving effect to the European Commission DORA Q&A of 17 December 2025
  • CSSF communiqué on third-country branches · CSSF, Application of DORA to third-country branches in Luxembourg, 27 August 2026
  • Register submission window · CSSF, DORA submission timeframe for the register of information, eDesk portal open from 11 February 2026 (reference date 31 December 2025)
  • Outsourcing regime rewritten · Circulars CSSF 25/882 and 25/883 of 9 April 2025 (register cycle; scope of Circular CSSF 22/806) and Circular CSSF 25/893 of 27 May 2025 (incident reporting)
  • US initiators in Luxembourg funds · CSSF, Origin of UCI initiators in Luxembourg, situation as at 30 June 2026 (US: EUR 1,309.608 bn, 19.4 %)
  • Luxembourg fund industry size · CSSF press release 26/16 of 6 August 2026: EUR 6,731.325 bn of net assets at 30 June 2026, across 2,968 UCIs
  • SEC withdrawal of proposed cyber rules · SEC, Withdrawal of proposed regulatory actions, 90 FR 25531, 17 June 2025 (includes the 2022 adviser and 2023 broker-dealer cybersecurity proposals)
  • US public-company disclosure rule · SEC cybersecurity disclosure rule, 88 FR 51896, effective 5 September 2023 (Item 1.05 Form 8-K within four business days of a materiality determination)

Nothing here is legal advice: it is an operator's reading of published sources. Your compliance and legal teams own the interpretation. Site language: en.