{"id":"circulars/cssf-21-787","title":"Circular CSSF 21/787","type":"circular","date":"2021-12-17","kind":"circular","html":"<p>Circular CSSF 21/787 is a CSSF circular, published 17 December 2021 and updated 28 November 2025. Subject: Application of the EBA Guidelines (EBA/GL/2021/03) on major incident reporting under PSD2. It was repealed by <a href=\"/lhoft?page=circulars%2Fcssf-25-893\" class=\"wikiLink\" data-target=\"circulars/cssf-25-893\">Circular CSSF 25/893</a>.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, E-money institutions, Payment institutions, Payment institutions/electronic money institutions/AISPs, Specialised PFS, Support PFS.</p>\n<p>Keywords: Information security, Payment Service Provider (PSP), Payment services.</p>\n<p>Repeals <a href=\"/lhoft?page=circulars%2Fcssf-18-704\" class=\"wikiLink\" data-target=\"circulars/cssf-18-704\">Circular CSSF 18/704</a>.</p>\n<h2>Text</h2>\n<p>Circular CSSF 21/787 APPLICATION OF THE EBA GUIDELINES (EBA/GL/2021/03) ON MAJOR INCIDENT REPORTING UNDER PSD2</p>\n<p>Circular CSSF 21/787 RE: Application of the EBA Guidelines (EBA/GL/2021/03) on Major Incident Reporting under PSD2</p>\n<p>Luxembourg, 17 December 2021</p>\n<p>Ladies and Gentleman, The purpose of the present circular is to inform you that the CSSF, in its capacity as</p>\n<p>To all payment service providers</p>\n<p>competent authority, applies the revised guidelines of the European Banking Authority (EBA) on the notification of major operational or security incidents of 10 June 2021 (i.e. EBA/GL/2021/03; hereafter “the Guidelines”), in accordance with article 96 of the Directive (EU) 2015/2366 (hereafter “PSD2”), replacing as from 1 January 2022 the EBA guidelines EBA/GL/2017/10. Consequently, the CSSF has integrated the Guidelines into its administrative practice and regulatory approach with a view to promote supervisory convergence in this field at European level. This circular also provides certain details concerning the reporting obligations, in particular the notification process to the CSSF, related to major operational or security incidents (hereafter “major incidents”) as provided by Article 105-2(1) of the amended law of 10 November 2009 on payment services (hereafter “Law”), which stipulates that payment services providers (hereafter “PSP”) shall notify the CSSF without undue delay of major incidents.</p>\n<p>The Guidelines</p>\n<p>The Guidelines apply to PSPs as defined in article 1(37) of the Law. The Guidelines specify, in particular, the criteria for the classification of major incidents by PSPs, as well as the format and procedures the latter should follow to communicate such incidents to the competent authority in the home Member State. The Guidelines apply to all incidents included under the definition of “operational or security incident”, according to point 15 of the Guidelines, which covers both external and internal events that could be either malicious or accidental. Compared to the EBA guidelines EBA/GL/2017/10, the revised Guidelines aim at: •</p>\n<p>optimising and, where possible, simplifying the reporting of major incidents under PSD2 and the underlying reporting templates, in order to ease the reporting burden on PSPs and to improve the meaningfulness of the reports received;</p>\n<p>capturing additional security incidents that would not qualify as major under the criteria set in the original guidelines but that experience has shown are material;</p>\n<p>reducing the number of operational incidents that will be reported but that do not have a significant impact on the operations of PSPs.</p>\n<p>The Guidelines are attached in annex 2 of the present circular, and published on the EBA’s website under the following link: <a href=\"https://www.eba.europa.eu/regulation-and-policy/payment-services-andelectronic-money/guidelines-on-major-incidents-reporting-under-psd2\" target=\"_blank\" rel=\"noreferrer\">https://www.eba.europa.eu/regulation-and-policy/payment-services-andelectronic-money/guidelines-on-major-incidents-reporting-under-psd2</a></p>\n<p>II. Deadlines for classification and notification of major incidents Please find here below the main deadline requirements: •</p>\n<p>PSPs should classify the operational or security incident within 24 hours of its detection.</p>\n<p>PSPs should submit an initial report to the CSSF within 4 hours from the moment the operational or security incident has been classified as major. The CSSF will acknowledge to the PSP the receipt of the initial report and communicate to the PSP a unique reference code, which the PSP shall indicate in any subsequent reports related to the same incident.</p>\n<p>PSPs should submit the intermediate report when regular activities have been recovered and business is back to normal, or in case where regular activities have not yet been recovered, within three working days from the submission of the initial report.</p>\n<p>PSPs should deliver the final report to the CSSF a maximum of 20 working days after business is deemed back to normal.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-21-787/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf21_787eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}