2025-04-09

Added · Updated

Circular CSSF 25/881 amending Circular CSSF 20/750 on ICT and security risk management

Circular CSSF 20/750 is amended to restrict its scope to non-DORA entities supervised by the CSSF, excluding financial entities defined in Article 2 of DORA. The amendment removes specific requirements for Payment Service Providers (PSPs), including Guideline 3.8 on relationship management and the PSP ICT assessment, which are transferred to the new Circular CSSF 25/880. The remaining provisions of Circular CSSF 20/750 are updated to directly incorporate the relevant text of the EBA Guidelines on ICT and security risk management. These changes apply with immediate effect to credit institutions, professionals of the financial sector, POST Luxembourg, payment institutions, and electronic money institutions.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Scan of the document's first page
Share

CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: Amended

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CSSF

CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.

Topics