2022-12-29

Added · Updated

Amendment of Circular CSSF 20/750 on ICT and Security Risk Management

Payment service providers (PSPs) must submit a standardized PSP ICT Assessment form annually to the CSSF via the eDesk portal, covering the previous calendar year and due no later than 31 March. The assessment must be validated by the PSP's management body, specifically the member responsible for the ICT function, and submitted by a management body member. Institutions whose business models do not include payment services are exempt, as are EEA branches established in Luxembourg that offer such services, while Luxembourg-based PSPs with branches in other EEA countries must include those branches in their assessment. The amended paragraph 4 of Circular CSSF 20/750 entered into force on the publication date of this circular.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

We email you every new CSSF publication the day it's published.

Share