Article M.3

Amendment 1 — the scope of application (Chapter 1)

CSSF Circular 25/881 amending CSSF 20/750 on ICT and security risk management (as amended by Circular CSSF 26/915) · CSSF 25/881

In line with step 1 above, this circular amends Circular CSSF 20/750 by specifying the following:

1. the scope of application of Circular CSSF 20/750 has been modified to consider the entry into application of DORA. The scope is now described in Chapter 1:

a. For financial entities as defined in Article 2 of DORA and supervised by the CSSF, Circular CSSF 20/750 no longer applies. They have been removed from the scope;

b. For entities falling under Circular CSSF 20/750 but not falling under DORA, Circular CSSF 20/750 continues to apply in full.