{"id":"circulars/cssf-25-880","title":"Circular CSSF 25/880","type":"circular","date":"2025-04-09","kind":"circular","html":"<p>Circular CSSF 25/880 is a CSSF circular on relationship management of payment service users and PSP ICT assessment, published 9 April 2025.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, E-money institutions, Payment institutions, Payment institutions/electronic money institutions/AISPs.</p>\n<p>Main topic: DORA. Keywords: Cloud, Cybersecurity, Information and communications technology (ICT), Information security, Outsourcing.</p>\n<h2>Text</h2>\n<p>Circular CSSF 25/880 on relationship management of payment service users and PSP ICT assessment To all Payment Service Providers as referred to in Article 1(37) of the Law of 10 November 2009 on payment services (LPS).</p>\n<p>Luxembourg, 9 April 2025 Ladies and Gentlemen, As of 17 January 2025, the provisions of the Digital Operational Resilience Act 1 (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. DORA has introduced, inter alia, harmonised requirements for information and communication technology (ICT) risk management framework. In view of reducing the overlap with the DORA regulation, the European Banking Authority (“EBA”) reviewed its existing Guidelines on ICT and security risk management EBA/GL/2019/04 (the “EBA Guidelines”), which were built on the provisions of Article 74 of Directive 2013/36/EU (“CRD”) 2 and Article 95(3) of Directive (EU) 2015/2366 (Payment Services Directive 2, “PSD2”) 3. The EBA Guidelines are implemented in Luxembourg by way of Circular CSSF 20/750 on ICT and security risk management. The EBA arrived at the view that the entities subject to the EBA Guidelines should be narrowed down and the scope of the Guidelines reduced to Guideline 3.8 on relationship management of the payment service users in relation to the provision of payment services. To do so, the EBA issued EBA/GL/2025/02 amending EBA/GL/2019/04 on ICT and security risk management (“new EBA Guidelines”). The EBA further explained that National Competent Authorities have the possibility to subject Payment Service Providers (“PSPs”) that are not covered by DORA to national requirements irrespective of the existence or not of EBA Guidelines 4. This circular transposes the new EBA Guidelines, which will be applicable for all PSPs, including branches in Luxembourg of PSPs incorporated in a third country, and POST Luxembourg, within the scope of the Law of 10 November 2009 on payment services (LPS) and supervised by the CSSF. Furthermore, the existing additional national requirement for annual reporting of the risk assessment related to payment services (PSP ICT assessment), which was previously part of Circular CSSF 20/750 is integrated into this circular.</p>\n<p>Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (DORA)</p>\n<p><a href=\"https://eur-lex.europa.eu/eli/dir/2013/36/oj/eng\" target=\"_blank\" rel=\"noreferrer\">https://eur-lex.europa.eu/eli/dir/2013/36/oj/eng</a></p>\n<p>3 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35–127) (PSD2) 4</p>\n<p>EBA/GL/2025/02 and corresponding press release</p>\n<p>This circular is divided into three chapters: •</p>\n<p>Chapter</p>\n<p>implements</p>\n<p>the</p>\n<p>EBA</p>\n<p>Guidelines</p>\n<p>EBA/GL/2025/02</p>\n<p>amending</p>\n<p>Guidelines</p>\n<p>EBA/GL/2019/04 on ICT and security risk management. The CSSF considers that the content of these Guidelines reflects its expectations as regards the relationship management of the payment service user and has, via this circular, integrated them into its administrative practice and regulatory approach; •</p>\n<p>Chapter 2 lists the requirements on PSP ICT assessment, according to which PSPs are asked to provide the CSSF with an updated and comprehensive PSP ICT assessment. This has not changed with the entry into application of DORA and PSPs shall continue to fulfil the requirements stated under points 8 to 11 of this circular;</p>\n<p>Chapter3 provides for the entry into force of this circular.</p>\n<p>TABLE OF CONTENTS Chapter 1.</p>\n<p>Relationship management of the payment service users (PSUs) .................</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-25-880/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf25_880eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}