← Regulators
MiCA EU 2023/1114 DORA EU 2022/2554 Luxembourg

Who is the CSSF: Luxembourg's financial regulator and single MiCA authority

The CSSF supervises the professionals and products of Luxembourg's vast financial sector — and, under MiCA, it is the country's single competent authority for crypto, unlike France's split. What it does, its role under MiCA and DORA, and who sits on its Executive Board through a 2026 change. Every fact sourced.

Luxembourg is one of the world’s largest fund and financial-services centres, and the regulator that supervises almost all of it is the Commission de Surveillance du Secteur Financier (CSSF). Under MiCA, Luxembourg took a different path from France: instead of splitting crypto supervision between two authorities, it made the CSSF its single competent authority. The CSSF is also a key supervisor under DORA. This is a profile of what the CSSF is, what it does, and who runs it. Every fact is sourced.

Quick facts

  • Full name: Commission de Surveillance du Secteur Financier (CSSF) — Luxembourg’s Financial Sector Supervisory Commission
  • Role: the public institution that supervises the professionals and products of the Luxembourg financial sector (CSSF); Luxembourg’s single MiCA competent authority and a key DORA supervisor
  • Founding law: created by the Law of 23 December 1998
  • MiCA: the Law of 6 February 2025 designated the CSSF as Luxembourg’s sole MiCA authority — covering both crypto-asset service providers and stablecoin issuers in one regulator
  • DORA: the CSSF and the Commissariat aux Assurances (CAA) are Luxembourg’s designated DORA competent authorities (the CAA for insurance, the CSSF for the rest)
  • Leadership: an Executive Board (a Director General plus two to four Directors). Director General: Claude Marx (since 2016); as of the official governance page (updated 5 February 2026), the Board is Claude Marx, Claude Wampach, Marco Zwick, Jean-Pierre Faber and Pascale Toussing (CSSF — Governance)
  • Seat: 283 route d’Arlon, Luxembourg
  • Website: cssf.lu

What the CSSF is — and what it is not

The CSSF is the public institution that supervises the professionals and products of Luxembourg’s financial sector (CSSF) — banks, investment firms, payment and e-money institutions, and above all the country’s enormous investment-fund industry. It was created by the Law of 23 December 1998. It is also Luxembourg’s National Resolution Authority and the national competent authority within European Banking Supervision, sitting as a voting member of the EBA and ESMA.

What it is not: it is not the data protection authority. Luxembourg’s GDPR regulator is the CNPD — the one that issued the €746 million Amazon fine. The CSSF’s relevance here is MiCA and DORA, the financial side of EU digital regulation.

The CSSF under MiCA: one authority, not two

This is the CSSF’s distinguishing feature against its French neighbour. France splits crypto supervision between the AMF (service providers) and the ACPR (stablecoins). Luxembourg did the opposite: the Law of 6 February 2025 named the CSSF as the country’s sole MiCA authority. So in Luxembourg, one regulator handles:

  • crypto-asset service providers (CASPs) — exchanges, custodians, brokers — and their authorisation;
  • stablecoin issuers — both e-money tokens (EMTs) and asset-referenced tokens (ARTs);
  • crypto-asset white papers and market abuse.

For a firm choosing where to base its EU crypto operations, that single-authority model is part of Luxembourg’s pitch: one supervisor, one process.

The CSSF under DORA

Under DORA, Luxembourg designated two competent authorities: the CSSF for the bulk of the financial sector, and the Commissariat aux Assurances (CAA) for the insurance sector. The CSSF supervises the digital operational resilience — ICT risk management, incident reporting, resilience testing — of the banks, investment firms, funds and other entities in its remit, and from early 2026 has been collecting the DORA register of information from supervised entities (CSSF — DORA register of information). The EU-level oversight of critical ICT providers sits with the three European Supervisory Authorities — see the DORA pillar.

Who runs it — and a 2026 change on the board

The CSSF’s senior executive authority is its Executive Board, made up of a Director General and between two and four Directors. Claude Marx has been Director General since 2016. As of the official governance page, updated 5 February 2026, the Executive Board comprises Claude Marx, Claude Wampach, Marco Zwick, Jean-Pierre Faber and Pascale Toussing (CSSF — Governance); the Luxembourg government proposed the appointment of Pascale Toussing as a Director of the CSSF in January 2026 (CSSF). Because the board changed in early 2026, the safe move is to check the CSSF governance page for the current Director General rather than rely on an older source.

What this means for you

  • If you run crypto services or issue stablecoins into Luxembourg: the CSSF is your single authority for everything MiCA — CASP authorisation, stablecoins, white papers. You do not deal with two regulators as you would in France.
  • If you run a fund or financial entity under DORA: the CSSF is your DORA supervisor (unless you are an insurer, in which case it is the CAA), and it is actively collecting the register of information from supervised entities.
  • If your question is about personal data, not financial supervision: that is the CNPD, not the CSSF.
  • If you are a journalist or researcher: “Luxembourg’s financial regulator” = the Commission de Surveillance du Secteur Financier (CSSF), created by the Law of 23 December 1998, seated at 283 route d’Arlon, the country’s single MiCA authority since the Law of 6 February 2025.

TL;DR

The CSSF (Commission de Surveillance du Secteur Financier) is Luxembourg’s financial sector supervisor, created by the Law of 23 December 1998, overseeing the country’s banks, investment firms and vast fund industry. Under MiCA it is Luxembourg’s single competent authority — covering crypto-asset service providers and stablecoin issuers in one regulator (the Law of 6 February 2025), unlike France’s AMF/ACPR split. Under DORA it is a competent authority alongside the Commissariat aux Assurances. It is run by an Executive Board led by Director General Claude Marx (since 2016), with a board change in early 2026 (Pascale Toussing proposed as a Director). Luxembourg’s GDPR regulator is the separate CNPD.

Sources