2025-04-09
Added · Updated
Payment Service Providers supervised by the CSSF must implement processes to enhance payment service users' awareness of security risks, including providing assistance, guidance, and options to disable functionalities or adjust spending limits. PSPs are required to submit an updated and comprehensive PSP ICT Assessment via the CSSF’s eDesk portal annually by 31 March, covering the previous calendar year. The assessment must be validated by the Management body and submitted exclusively by a management body member, while EEA branches established in Luxembourg are exempt from this submission requirement.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment
CIRCULAR CSSF 25/880 2/6
Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment To all Payment Service Providers as referred to in Article 1(37) of the Law of 10 November 2009 on payment services (LPS). Luxembourg, 9 April 2025 Ladies and Gentlemen, As of 17 January 2025, the provisions of the Digital Operational Resilience Act1 (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. DORA has introduced, inter alia, harmonised requirements for information and communication technology (ICT) risk management framework. In view of reducing the overlap with the DORA regulation, the European Banking Authority (“EBA”) reviewed its existing Guidelines on ICT and security risk management EBA/GL/2019/04 (the “EBA Guidelines”), which were built on the provisions of Article 74 of Directive 2013/36/EU (“CRD”)2 and
Article 95(3) of Directive (EU) 2015/2366 (Payment Services Directive 2, “PSD2”) 3. The EBA
Guidelines are implemented in Luxembourg by way of Circular CSSF 20/750 on ICT and security risk management. The EBA arrived at the view that the entities subject to the EBA Guidelines should be narrowed down and the scope of the Guidelines reduced to Guideline 3.8 on relationship management of the payment service users in relation to the provision of payment services. To do so, the EBA issued EBA/GL/2025/02 amending EBA/GL/2019/04 on ICT and security risk management (“new EBA Guidelines”). The EBA further explained that National Competent Authorities have the possibility to subject Payment Service Providers (“PSPs”) that are not covered by DORA to national requirements irrespective of the existence or not of EBA Guidelines4. This circular transposes the new EBA Guidelines, which will be applicable for all PSPs, including branches in Luxembourg of PSPs incorporated in a third country, and POST Luxembourg, within the scope of the Law of 10 November 2009 on payment services (LPS) and supervised by the CSSF. Furthermore, the existing additional national requirement for annual reporting of the risk assessment related to payment services (PSP ICT assessment), which was previously part of Circular CSSF 20/750 is integrated into this circular. 1 Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (DORA) 2 https://eur-lex.europa.eu/eli/dir/2013/36/oj/eng 3 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35–127) (PSD2) 4 EBA/GL/2025/02 and corresponding press release
CIRCULAR CSSF 25/880 3/6
This circular is divided into three chapters:
CIRCULAR CSSF 25/880 4/6
TABLE OF CONTENTS
Chapter 1. Relationship management of the payment service users (PSUs) .......................... 5
Chapter 2. PSP ICT assessment...................................................................................... 5
Chapter 3. Date of application ........................................................................................ 6
CIRCULAR CSSF 25/880 5/6
Chapter 1. Relationship management of the payment
service users (PSUs)5
CIRCULAR CSSF 25/880 6/6 risk assessment for these branches deviates from that of the PSP, it should be made clear in the PSP ICT Assessment6.
10. All PSPs must submit the duly completed PSP ICT Assessment form on an annual basis to
the CSSF no later than 31 March each year and covering the previous calendar year.
11. The PSP ICT Assessment form is published in the CSSF’s eDesk portal which is available at
https://edesk.apps.cssf.lu/.
The PSP ICT Assessment shall be validated by the Management body of the PSP, i.e. at least by the member of the Management body responsible for the ICT function. This validation shall be specified in the respective section of the PSP ICT Assessment. The duly completed and validated PSP ICT Assessment shall be submitted annually by a member of the management body to the CSSF exclusively via the CSSF’s eDesk portal.
Chapter 3. Date of application
12. This circular shall apply with immediate effect.
Claude WAMPACH
Director
Marco ZWICK
Director
Jean-Pierre FABER
Director
Françoise KAUTHEN
Director
Claude MARX
Director General
6 See EBA Q&A ID number 2018_4176
Read the rest free
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works