2021-03-15

Added · Updated

Instruction No. 4/2021 on ICT and Security Risk Management for Payment Service Providers

This Instruction mandates Payment Service Providers (PSPs) with headquarters in Portugal to comply with the European Banking Authority's Guidelines on ICT and security risk management, specifically requiring the annual submission of an operational and security risk assessment report. PSPs must prepare this report based on data as of June 30 each year and submit it to the Bank of Portugal by July 31 of the same year via the BPnet portal. The first report, covering the period ending June 30, 2021, was due by July 31, 2021. This measure aims to ensure that PSPs effectively control operational and security risks, including cybersecurity incidents, related to their payment services.

Banco de Portugal logo

Portugal

Banco de Portugal

Click to view full text