On 29 September 2026 the CSSF added seven field-level instructions to the ESAs' guidance on DORA major ICT incident reports, aimed at better data quality.
Luxembourg financial entities must keep a DORA register of all ICT third-party contracts and file it yearly; the hard part is data quality, not the template.
BCBS 239 sets 14 principles for aggregating and reporting risk data; for Luxembourg banks the ECB's May 2024 guide and CSSF Circular 12/552 make them concrete.