The two steps taken by the CSSF
CSSF Circular 25/881 amending CSSF 20/750 on ICT and security risk management (as amended by Circular CSSF 26/915) · CSSF 25/881
Consequently, to provide legal clarity to the market and clarify its expectations, the CSSF is taking two steps:
1. amend Circular CSSF 20/750 on requirements regarding ICT and security risk management:
— to reduce the scope to “non-DORA entities”, i.e. the entities that are subject to CSSF supervision but are not financial entities as defined in Article 2 of DORA and therefore not subject to DORA requirements. The amended Circular CSSF 20/750 also remains applicable to entities which are not in the scope of DORA, when providing payment services, such as POST Luxembourg and branches in Luxembourg of PSP incorporated in a third country. In fact, the CSSF considers that financial entities subject to the supervision of the CSSF falling under Circular CSSF 20/750 but not falling under DORA shall continue to fulfil its expectations with regard to the ICT and security risk management by complying with this circular;
— to remove the specific elements only applicable to PSPs (whether they are also in scope of DORA or not) which are regrouped in a new dedicated circular (see point 2 below), i.e. Guideline 3.8. on relationship management of the payment service users and section 4 of the circular related to PSP ICT assessment; and
— to remove a few other obsolete sections and provisions of the circular.
2. issue a new circular, Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment, applicable to all PSPs within the scope of LPS and supervised by the CSSF, including branches in Luxembourg of PSPs incorporated in a third country, and POST Luxembourg which:
— implements the EBA Guidelines 2025/02 amending EBA GL/2019/04 on ICT and security risk management. i.e. the contents of Guideline 3.8 referred to above;
— integrates the existing additional national requirement for annual reporting of the risk assessment related to payment services (PSP ICT assessment), which was previously part of Circular CSSF 20/750.
Footnote 6: This is the reason why references to elements of compliance with the Law of 10 November 2009 on payment services (LPS) which apply to POST Luxembourg and branches in Luxembourg of PSP incorporated in a third country are retained in this circular.
In Luxembourg, the CSSF is the sole competent authority for this dual framework. Circular 25/880 integrates an additional national requirement specific to the Grand Duchy: the annual reporting of the PSP ICT risk assessment, which does not exist under the EBA Guidelines alone. References to the Law of 10 November 2009 on payment services (LPS) are retained for POST Luxembourg and Luxembourg branches of third-country PSPs.
Luxgap practice: check that your CSSF reporting calendar properly integrates this annual PSP ICT assessment deadline under 25/880, and no longer under 20/750, to avoid a filing breach at the next inspection.