Entry into force, signatories and annex
CSSF Circular 25/881 amending CSSF 20/750 on ICT and security risk management (as amended by Circular CSSF 26/915) · CSSF 25/881
This circular shall apply with immediate effect.
Claude WAMPACH, Director — Marco ZWICK, Director — Jean-Pierre FABER, Director — Françoise KAUTHEN, Director — Claude MARX, Director General
Annex — Circular CSSF 20/750 as amended by Circular CSSF 25/881.
Luxgap note — the annex to this circular reproduces the consolidated text of CSSF 20/750, in its version “as amended by Circulars CSSF 22/828 and CSSF 25/881”. To avoid publishing a second copy of it, the annex is not reproduced here: read Circular CSSF 20/750 in its current consolidated version, which further incorporates the amendments made by Circular CSSF 26/915, subsequent to the annex reproduced in this PDF.
Luxgap note — the English text above is transcribed from the English PDF published by the CSSF, which is not consolidated by Circular CSSF 26/915, whereas the French PDF is. The two official versions therefore differ on one point: the English one also names “branches in Luxembourg of PSP incorporated in a third country”. Each version is reproduced as the CSSF published it, without harmonisation.
In Luxembourg, the sole competent authority is the CSSF, which exercises prudential supervision over the covered financial entities. Circular CSSF 25/881 of 9 April 2025 amends Circular CSSF 20/750 to align the ICT requirements baseline (transposing the EBA guidelines) with the directly applicable DORA regulation. Documented specificity: the English PDF published by the CSSF, not consolidated by Circular CSSF 26/915, additionally names branches in Luxembourg of PSP incorporated in a third country, whereas the French version does not mention them.
Luxgap practice: never rely on a single language PDF, check the scope of entities against both official versions and always work from the current consolidated version incorporating Circular CSSF 26/915.