Klavius

CSSF 22/806 after DORA: which outsourcing rules apply to a Luxembourg fund manager

A white clay sorting gate on the indigo Klavius ribbon, sending cloud tiles one way and document tiles the other
In brief

Since Circular CSSF 25/883 of 9 April 2025, Circular 22/806 no longer applies to Luxembourg fund managers that are DORA financial entities. Their ICT contracts now fall under DORA and Circular 25/882, and the delegation of fund management, control and support functions under Circular 18/698. The one exception is a management company authorised only under Article 125-1 of Chapter 16, still under 22/806 for ICT outsourcing.

Short answer: for almost every Luxembourg fund manager, Circular CSSF 22/806 no longer applies. Since Circular CSSF 25/883 of 9 April 2025, investment fund managers that are financial entities under DORA have been removed from its scope. Their ICT arrangements are governed by DORA and Circular CSSF 25/882, and the rest of what they delegate by Circular CSSF 18/698. One exception remains: management companies authorised only under Article 125-1 of Chapter 16 of the 2010 Law, which fall outside DORA (CSSF 25/883, point 3).

The question keeps coming up for a reason. The circular's page on cssf.lu still tags it as relevant for alternative investment fund managers and Chapter 15 management companies (checked on 27 September 2026), and the CSSF amended it again on 27 August 2026. This post sets out what changed, and which rule governs which arrangement.

What 22/806 used to mean for fund managers

When it was published on 22 April 2022, Circular 22/806 integrated the EBA Guidelines on outsourcing and brought the CSSF's ICT outsourcing requirements, until then spread across several circulars, into one document. Fund managers were in scope for one kind of arrangement only. The circular applied in full to "investment fund managers incorporated under Luxembourg law within the meaning of circular CSSF 18/698" when performing ICT outsourcing, and it specified that "the relevant provisions related to outsourcing of circular CSSF 18/698 do not apply to IFMs in case of ICT outsourcing arrangements" (22/806 as amended by 25/883, page 11, shown as deleted in the track changes).

In other words, from 2022 a Luxembourg ManCo or AIFM ran two regimes side by side: 22/806 for its cloud, software and IT services, and 18/698 for the delegation of fund management functions.

What 25/883 changed in April 2025

DORA has applied since 17 January 2025, and it lists managers of alternative investment funds and management companies among the financial entities it covers (DORA, Article 2(1)(k) and (l)). To avoid two sets of rules for the same ICT contracts, the CSSF amended 22/806 on 9 April 2025. For the entities that were in scope "only when performing ICT outsourcing", the circular states that "Circular CSSF 22/806 no longer applies. Those entities have been removed from the scope" (CSSF 25/883, point 3(c)).

Point 3(d) keeps one category: management companies authorised only under Article 125-1 of Chapter 16, "which consequently are not in the scope of DORA", for which 22/806 "continues to apply in full when performing ICT outsourcing". The consolidated circular now lists them, and no other fund manager, among the entities it covers (CSSF 22/806, point 2). For DORA entities, ICT arrangements are "covered by Circular CSSF 25/882 on requirements on the use of ICT third-party services for Financial Entities subject to DORA and DORA regulation" (22/806, footnote 11).

The amendment of 27 August 2026, Circular 26/915, brings third-country branches into the DORA scope. Along the way it restates which fund managers are DORA financial entities: Chapter 15 management companies, Chapter 16 companies under Article 125-2, Luxembourg branches under Chapter 17, investment companies without a management company (SIAGs), authorised AIFMs and internally managed AIFs (CSSF 26/915, chapter 1). Its changes concern third-country branches and the channel for reporting major ICT incidents, not the position described above.

Which rule applies to which arrangement

ArrangementChapter 15 ManCo, Article 125-2 ManCo, authorised AIFM, SIAG, FIAAGManCo authorised only under Article 125-1
ICT services: cloud, software, hosting, dataDORA, Articles 28 to 30, and Circular 25/882Circular 22/806, Parts I and II
Portfolio management, risk management, UCI administration, valuation, marketingCircular 18/698, chapter 6Circular 18/698, chapter 6
Compliance, internal audit, accountingCircular 18/698, sub-chapters 5.1 and 5.3Circular 18/698, sub-chapters 5.1 and 5.3

Circular 18/698 covers both kinds of management company in the second and third rows: it applies to management companies under Articles 125-1 and 125-2 of Chapter 16 as well as to Chapter 15 ManCos and AIFMs (CSSF 18/698, cover letter).

What DORA asks instead for ICT

For a ManCo or an AIFM, the ICT side of the old 22/806 file now sits under DORA. Four obligations do most of the work.

  • A register of every ICT contract. Financial entities "maintain and update at entity level" a register of information on all contractual arrangements for ICT services, distinguishing those that support critical or important functions, and report on it at least yearly (Article 28(3)).
  • Notice before the critical ones. They "inform the competent authority in a timely manner about any planned contractual arrangement on the use of ICT services supporting critical or important functions" (Article 28(3)).
  • An assessment before signing. Before any ICT contract, the entity assesses whether it supports a critical or important function, whether supervisory conditions are met, and the relevant risks (Article 28(4)).
  • Contracts and exits. The contract sets out rights and obligations in writing, including the service levels (Article 30), and ICT services supporting critical or important functions need exit strategies (Article 28(8)).

Our post on the DORA register of information covers the annual collection, and the free DORA contract clause checker tests a contract against Article 30.

Where Klavius fits

The table above is why one provider can sit in two files. A fund administrator is a delegate under 18/698, and it is also an ICT third-party provider under DORA if it runs your investor portal. Klavius keeps it as one record. Delegate Oversight runs the 18/698 due-diligence questionnaires, reminders and escalations, and the DORA module starts from the register of information you already filed and populates third parties, critical functions and ICT risks. The officers validate and sign. The Delegate Oversight and DORA pages show both.

Sources

← All posts