{"id":"circulars/cssf-25-881","title":"Circular CSSF 25/881","type":"circular","date":"2025-04-09","kind":"circular","html":"<p>Circular CSSF 25/881 is a CSSF circular amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management, published 9 April 2025.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2000-12-15-n1\" class=\"wikiLink\" data-target=\"laws/2000-12-15-n1\">Law of 15 December 2000 on postal services and postal financial services</a>, <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>, <a href=\"/lhoft?page=laws%2F1993-04-05-n1\" class=\"wikiLink\" data-target=\"laws/1993-04-05-n1\">Law of 5 April 1993 on the financial sector</a>.</p>\n<p>Relevant for: AIFMs, AISPs, Central Securities Depositories (CSDs), Credit institutions, Crowdfunding service providers, Crypto-Assets Service Providers (CASPs), Data Reporting Service Providers (DRSPs), E-money institutions, Investment firms, Investment fund managers, Issuers of ARTs, Issuers of E-Money Tokens (EMTs), Issuers of Tokens, Management companies - Chapter 15, Management companies - Chapter 16, Payment institutions, Payment institutions/electronic money institutions/AISPs, Pension funds, SICARs, Specialised PFS, Support PFS.</p>\n<p>Main topic: DORA. Keywords: Cloud, Cybersecurity, Information and communications technology (ICT), Information security, Outsourcing.</p>\n<p>Amends <a href=\"/lhoft?page=circulars%2Fcssf-20-750\" class=\"wikiLink\" data-target=\"circulars/cssf-20-750\">Circular CSSF 20/750</a>. Amended by <a href=\"/lhoft?page=circulars%2Fcssf-26-915\" class=\"wikiLink\" data-target=\"circulars/cssf-26-915\">Circular CSSF 26/915</a>.</p>\n<h2>Text</h2>\n<p>on requirements regarding information and communication technology (ICT) and security risk management</p>\n<p>on requirements regarding information and technology (ICT) and security risk management</p>\n<p>communication</p>\n<p>To all credit institutions and to all professionals of the financial sector within the meaning of the Law of 5 April 1993 on the financial sector (LFS). To POST Luxembourg governed by the Law of 15 December 2000 on postal financial services1. To all payment institutions and to all electronic money institutions within the meaning of the Law of 10 November 2009 on payment services (LPS). Luxembourg, 9 April 2025 Ladies and Gentlemen, As of 17 January 2025, the provisions of the Digital Operational Resilience Act 2 (“DORA”) are applicable to the financial entities as defined in DORA and supervised by the CSSF. DORA has introduced, inter alia, harmonised requirements for information and communication technology (ICT) risk management framework. In view of reducing the overlap with the DORA regulation, the European Banking Authority (“EBA”) reviewed its existing Guidelines on ICT and security risk management EBA/GL/2019/04 (the “EBA Guidelines”), which were built on the provisions of Article 74 of Directive 2013/36/EU (CRD) 3 and Article 95(3) of Directive (EU) 2015/2366 (Payment Services Directive 2, “PSD2”) 4. The EBA Guidelines are implemented in Luxembourg by way of Circular CSSF 20/750 on ICT and security risk management. The EBA arrived at the view that the entities subject to the EBA Guidelines should be narrowed down and the scope of the Guidelines reduced to Guideline 3.8 on relationship management of the payment service users in relation to the provision of payment services. To do so, the EBA issued EBA GL 2025/02 amending EBA GL/2019/04 on ICT and security risk management (“new EBA Guidelines”). The EBA further explained that National Competent Authorities have the possibility to subject Payment Service Providers (PSPs) that are not covered by DORA to national requirements irrespective of the existence or not of EBA Guidelines 5.</p>\n<p>For the sake of clarity, the wording “postal financial services” has the meaning provided for in Article 1 of the Law of 15 December 2000, as amended.</p>\n<p>Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 3</p>\n<p><a href=\"https://eur-lex.europa.eu/eli/dir/2013/36/oj/eng\" target=\"_blank\" rel=\"noreferrer\">https://eur-lex.europa.eu/eli/dir/2013/36/oj/eng</a></p>\n<p>Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (OJ L 337, 23.12.2015, p. 35–127)</p>\n<p>EBA/GL/2025/02 and corresponding press release</p>\n<p>Consequently, to provide legal clarity to the market and clarify its expectations, the CSSF is taking two steps: 1. amend Circular CSSF 20/750 on requirements regarding ICT and security risk management: o</p>\n<p>to reduce the scope to “non-DORA entities”, i.e. the entities that are subject to CSSF supervision but are not financial entities as defined in Article 2 of DORA and therefore not subject to DORA requirements. The amended Circular CSSF 20/750 also remains applicable to entities which are not in the scope of DORA, when providing payment services, such as POST Luxembourg and branches in Luxembourg of PSP incorporated in a third country 6. In fact, the CSSF considers that financial entities subject to the supervision of the CSSF falling under Circular CSSF 20/750 but not falling under DORA shall continue to fulfil its expectations with regard to the ICT and security risk management by complying with this circular;</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-25-881/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf25_881eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}