{"id":"circulars/cssf-22-828","title":"Circular CSSF 22/828","type":"circular","date":"2022-12-29","kind":"circular","html":"<p>Circular CSSF 22/828 is a CSSF circular, published 29 December 2022. Subject: Amendment of Circular CSSF 20/750 on requirements regarding information and communication (ICT) and security risk management.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Payment institutions, Payment institutions/electronic money institutions/AISPs, Specialised PFS, Support PFS.</p>\n<p>Keywords: Cloud, Cybersecurity, eDesk, Information and communications technology (ICT), Information security, Operational risk, Payment Service Provider (PSP), Payment services, Postal financial services, Risk management.</p>\n<p>Amends <a href=\"/lhoft?page=circulars%2Fcssf-20-750\" class=\"wikiLink\" data-target=\"circulars/cssf-20-750\">Circular CSSF 20/750</a>.</p>\n<h2>Text</h2>\n<p>Circular CSSF 22/828 Amendment of Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management</p>\n<p>Circular CSSF 22/828 Re: Amendment of Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management</p>\n<p>Luxembourg, 29 December 2022</p>\n<p>Ladies and Gentlemen,</p>\n<p>To all credit institutions and to</p>\n<p>for payment service providers (PSPs)” of Circular CSSF 20/750 to introduce a</p>\n<p>The objective of this circular is to amend paragraph 4. “Additional requirement all PFS</p>\n<p>form regarding the updated and comprehensive risk assessment of the ICT and</p>\n<p>To all payment institutions and to all electronic money institutions</p>\n<p>security risks related to payment services provided by PSPs (named “PSP ICT Assessment”), and to provide further information on the objective, the scope and the submission process and deadline related to this form. The PSP ICT Assessment form shall be used for the first time concerning the calendar year 2022 and submitted to the CSSF no later than 31 March 2023. The amended version of paragraph 4 is presented in “track changes” in the Annex of the present circular. The revised version of paragraph 4 will enter into force on the date of publication of the present circular. This circular is applicable as of its publication date.</p>\n<p>Claude WAMPACH</p>\n<p>Marco ZWICK</p>\n<p>Jean-Pierre FABER</p>\n<p>Françoise KAUTHEN</p>\n<p>Claude MARX</p>\n<p>Annex: Amended version of paragraph 4 of the Circular CSSF 20/750</p>\n<p>Annex: Amended version of paragraph 4 of Circular CSSF 20/750 4. Additional requirement for payment service providers (PSPs) 1</p>\n<p>As provided for in paragraph 24 of Guideline “3.3.5. Reporting” and in accordance with Article 105-1(2) of the LPS, PSPs are required to provide the CSSF with an updated and comprehensive risk assessment related to payment services (hereafter “PSP ICT Assessment”). The form and deadlines are as follows: a.</p>\n<p>for credit institutions, this assessment, signed by the management body, must be submitted as soon as possible after the closing of the financial year and no later than 30 April of each year;</p>\n<p>for payment institutions and electronic money institutions, this assessment must be included in a dedicated section of the management report on internal control, which must be published in accordance with the requirements set out in Circular CSSF 15/614, no later than the last day of the third month following the closing date of the financial year; and</p>\n<p>for POST Luxembourg, this assessment must be included in a dedicated section of the management report on internal control, to be published in accordance with the requirements set out in Circular CSSF 98/143, at the latest one month after the annual general meeting approving the annual accounts of the PSP.</p>\n<p>The CSSF has developed a standardised form for the PSP ICT Assessment to be used by all PSPs. The objective of this standardised PSP ICT Assessment form is to give guidance to the PSPs on the CSSF's expectations on the information to be provided via the PSP ICT Assessment, and hence achieve a certain level of harmonisation and comparability among the PSPs' ICT Assessments. Concerning the scope of the PSP ICT Assessment, the following is to be highlighted: •</p>\n<p>Institutions whose business model does not include the provision of payment services (as defined in article 1(38) of the LPS), do not have to provide the PSP ICT Assessment. As soon as the business model of an institution includes the provision of payment services, it shall submit to the CSSF for that calendar year a PSP ICT Assessment.</p>\n<p>EEA Branches established in Luxembourg, which offer payment services, do not have to provide the CSSF with a PSP ICT Assessment.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-22-828/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf22_828eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}