On 9 April 2025, the Commission de Surveillance du Secteur Financier issued several new circulars related to information and communication technologies risk management and the use of ICT third parties, aiming to align existing circulars and practices with the Digital Operational Resilience Act.
On 2 July 2024, the Luxembourg law (“Law”) implementing the new EU framework for the effective and harmonized management of digital risks in the financial sector, namely the Digital Operational Resilience Act (DORA), was published in the Luxembourg official gazette. Like DORA, the Law will apply from 17 January 2025.