The DORA Regulation and the review of the EBA Guidelines
CSSF Circular 25/881 amending CSSF 20/750 on ICT and security risk management (as amended by Circular CSSF 26/915) · CSSF 25/881
As of 17 January 2025, the provisions of the Digital Operational Resilience Act (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. DORA has introduced, inter alia, harmonised requirements for information and communication technology (ICT) risk management framework.
In view of reducing the overlap with the DORA regulation, the European Banking Authority (“EBA”) reviewed its existing Guidelines on ICT and security risk management EBA/GL/2019/04 (the “EBA Guidelines”), which were built on the provisions of Article 74 of Directive 2013/36/EU (CRD) and Article 95(3) of Directive (EU) 2015/2366 (Payment Services Directive 2, “PSD2”). The EBA Guidelines are implemented in Luxembourg by way of Circular CSSF 20/750 on ICT and security risk management.
The EBA arrived at the view that the entities subject to the EBA Guidelines should be narrowed down and the scope of the Guidelines reduced to Guideline 3.8 on relationship management of the payment service users in relation to the provision of payment services. To do so, the EBA issued EBA GL 2025/02 amending EBA GL/2019/04 on ICT and security risk management (“new EBA Guidelines”). The EBA further explained that National Competent Authorities have the possibility to subject Payment Service Providers (PSPs) that are not covered by DORA to national requirements irrespective of the existence or not of EBA Guidelines.
In Luxembourg, the competent authority is exclusively the CSSF, which exercised the option left by the EBA: Circular CSSF 25/881 of 9 April 2025 amends Circular 20/750 to narrow its scope to Guideline 3.8, while preserving the CSSF's ability to subject PSPs outside the DORA scope to national requirements. Financial entities within the meaning of DORA fall directly under the DORA regulation.
Luxgap practice: do not delete your 20/750 policies before confirming, activity by activity, your status under DORA and any residual PSP qualification subject to CSSF requirements.