2022-12-29

Added · Updated

Amendment of Circular CSSF 20/750 on ICT and Security Risk Management

Payment service providers (PSPs) must submit a standardized PSP ICT Assessment form annually to the CSSF via the eDesk portal, covering the previous calendar year and due no later than 31 March. The assessment must be validated by the PSP's management body, specifically the member responsible for the ICT function, and submitted by a management body member. Institutions whose business models do not include payment services are exempt, as are EEA branches established in Luxembourg that offer such services, while Luxembourg-based PSPs with branches in other EEA countries must include those branches in their assessment. The amended paragraph 4 of Circular CSSF 20/750 entered into force on the publication date of this circular.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Scan of the document's first page
Share

CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Circular CSSF 20/750 on ICT and…2020Circular CSSF 20/750 on ICT and Security Risk Management Requirements (2020-08-25)Amendment of Circular CSSF20/750 on ICT and Security Ri…2022-12-29 · this documentAmendment of Circular CSSF 20/750 on ICT and Security Risk Management (2022-12-29)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CSSF

CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.