2025-04-09
Added · Updated
Payment Service Providers supervised by the CSSF must implement processes to enhance payment service users' awareness of security risks, including providing assistance, guidance, and options to disable functionalities or adjust spending limits. PSPs are required to submit an updated and comprehensive PSP ICT Assessment via the CSSF’s eDesk portal annually by 31 March, covering the previous calendar year. The assessment must be validated by the Management body and submitted exclusively by a management body member, while EEA branches established in Luxembourg are exempt from this submission requirement.