2021-03-15

Added · Updated

Instruction No. 4/2021 on ICT and Security Risk Management for Payment Service Providers

This Instruction mandates Payment Service Providers (PSPs) with headquarters in Portugal to comply with the European Banking Authority's Guidelines on ICT and security risk management, specifically requiring the annual submission of an operational and security risk assessment report. PSPs must prepare this report based on data as of June 30 each year and submit it to the Bank of Portugal by July 31 of the same year via the BPnet portal. The first report, covering the period ending June 30, 2021, was due by July 31, 2021. This measure aims to ensure that PSPs effectively control operational and security risks, including cybersecurity incidents, related to their payment services.

Banco de Portugal logo

Portugal

Banco de Portugal

Scan of the document's first page
Share

BDP published 1 document in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: In force

Instruction No. 1/2019: Reporti…2019Instruction No. 1/2019: Reporting of Severe Incidents (2019-01-15)Instruction No. 4/2021 on ICTand Security Risk Management …2021-03-15 · this documentInstruction No. 4/2021 on ICT and Security Risk Management for Payment Service Providers (2021-03-15)
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Banco de Portugal — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from BDP

BDP published 1 document in the last 30 days. We email you each new one the day it's published.