Pideeco
InfoNEWS

Circular CSSF 25/881 (as amended by Circular CSSF 26/915) (Updated) amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management

CSSF updates ICT and security risk management requirements: CSSF Circular 25/881 amends the Luxembourg framework for ICT and security risk management to reflect the application of DORA and reduce regulatory overlap. It narrows the relevant EBA Guidelines and maintains specific requirements for PSPs and non-DORA entities. The circular was further amended in August 2026 to reflect DORA's application to certain third-country branches.

27 Aug 2026LU_CSSF