2025-04-09

Added · Updated

Circular CSSF 25/881 amending Circular CSSF 20/750 on ICT and security risk management

Circular CSSF 20/750 is amended to restrict its scope to non-DORA entities supervised by the CSSF, excluding financial entities defined in Article 2 of DORA. The amendment removes specific requirements for Payment Service Providers (PSPs), including Guideline 3.8 on relationship management and the PSP ICT assessment, which are transferred to the new Circular CSSF 25/880. The remaining provisions of Circular CSSF 20/750 are updated to directly incorporate the relevant text of the EBA Guidelines on ICT and security risk management. These changes apply with immediate effect to credit institutions, professionals of the financial sector, POST Luxembourg, payment institutions, and electronic money institutions.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

We email you every new CSSF publication the day it's published.

Topics
Share