CESOP in Luxembourg: AED filing through MyGuichet.lu
In Luxembourg, CESOP reporting goes to the AED through a certified MyGuichet.lu business space, and the certification step is where most first-quarter delays begin. The Administration de l’enregistrement, des domaines et de la TVA collects each quarter’s cross-border payment file from payment service providers and passes it to the Commission’s Central Electronic System of Payment information. Before the first upload the provider needs a business eSpace, an authentication product, a signed mandate and an RCS extract, and the AED has to accept them. This piece covers the legal basis, the certification, the upload rules, the two validation layers and four cases from practice.
1. The legal basis
Council Directive (EU) 2020/284 added the payment-data duties to the VAT Directive, and Council Regulation (EU) 2020/283 amended Regulation (EU) No 904/2010 to create CESOP. Luxembourg transposed the Directive by the law of 26 July 2023, which amended the VAT law of 12 February 1979. The bill behind it, no. 8207, inserted a new Article 70ter into the VAT law.
The obligation has applied since 1 January 2024. A payment service provider that provides payment services in the EU must monitor the beneficiaries of cross-border payments and report those receiving more than 25 cross-border payments in a calendar quarter. Providers that do not provide payment services in the EU have no reporting duty.
2. Which providers are in scope
The AED’s guidance on Guichet.lu makes a point that is easy to miss: not every provider under PSD2 (Directive (EU) 2015/2366) reports. The CESOP definition in Article 243a of the VAT Directive is limited to four categories:
- credit institutions, including EU branches of credit institutions headquartered outside the EU that provide payment services;
- e-money institutions, which the guidance reads as covering e-wallet and e-voucher providers;
- payment institutions, the residual category — card issuing, acquiring, processing, payment initiation, and platforms acting for both payer and payee;
- post office giro institutions that provide payment services.
Luxembourg is a home Member State for a large number of passported e-money and payment institutions. For them the AED file covers the home-state leg only. Services provided in another Member State as host — through a branch, agents or the freedom to provide services — are reported to that Member State’s tax administration in a separate file.
3. Step one: a MyGuichet.lu business eSpace
Every CESOP filing in Luxembourg runs through a business eSpace (espace professionnel) on MyGuichet.lu. Creating one requires an authentication product:
- a LuxTrust product;
- a Luxembourg identity card with an activated electronic certificate; or
- an eIDAS means of identification issued in another EU or EEA country.
A person without a Luxembourg national identification number (matricule) can request one for professional purposes through a separate Guichet.lu procedure. All notifications — validation messages and the results of each upload — go to the e-mail address given when the eSpace is created. The AED therefore recommends a working mailbox that several people can read.
4. Step two: certifying the CESOP eSpace
An ordinary business eSpace is not enough. Before filing, the provider must run the online procedure “AED – Request for certification of a CESOP business eSpace” to prove that the person acting may represent the provider. The supporting documents are:
- the mandate form for certifying a CESOP business eSpace (procuration), duly signed; and
- a recent extract from the Registre de commerce et des sociétés showing that the signatory may act for the legal person.
Once the AED has checked and accepted the file, users get access to the certified eSpace, where they find the upload procedure. Colleagues can be invited, and they see the same information whatever role they are given. The provider must track who has access. The AED strongly recommends at least two administrators and an eSpace used for CESOP only, so that access is limited to the people concerned.
5. Step three: the upload
The quarterly file is the CESOP XML message of cross-border payments, uploaded through the procedure “AED – Upload a CESOP payment data message” in the certified eSpace or in the MyGuichet.lu app. The procedure requires authentication with LuxTrust or eIDAS. It can also be pre-filled through the MyGuichet.lu API via the State API Gateway, which matters for firms that want to automate filing.
The technical limits are strict:
- one file per procedure, with a maximum size of 80 MB;
- the file may be XML or a zip compressed with DEFLATE, provided the unzipped file is under 900 MB;
- a zip may contain only one XML file and may not be password-protected or encrypted;
- a message split into several files — for size or for organisational reasons — needs one procedure per file;
- every file name follows the Commission’s convention:
PMT-<quarter>-<year>-<country MS>-<pspID>-<partNumber>-<totalParts>.
Files must be validated first with the Commission’s validation module. A file the module would reject will be rejected straight away.
6. Deadlines
Each file is due before the end of the month following the calendar quarter it covers.
| Quarter | Period | Upload by |
|---|---|---|
| Q1 | January to March | 30 April |
| Q2 | April to June | 31 July |
| Q3 | July to September | 31 October |
| Q4 | October to December | 31 January |
The first file, for Q1 2024, was due before the end of April 2024.
7. Two validation layers
The AED validates every uploaded XML itself before anything goes to the Commission. There are two outcomes at that level:
- No errors: the file goes to the Commission and an acknowledgment of receipt appears in the eSpace.
- Errors found (“FULL REJECTION”): the file is not sent to central CESOP. A list of errors is posted to the eSpace instead, and the message is treated as void. The provider must start a new procedure with a correct file — a new-data message, MessageTypeIndic CESOP100 — before the deadline.
Central CESOP then validates every message syntactically and semantically. The AED posts the Commission’s validation result message to the eSpace — the IE3V01 message defined in the XSD User Guide. Because some rules need historical data that only the central system holds, only CESOP can say whether a message is fully valid. A file the AED accepted can still come back PARTIALLY REJECTED. The provider must then follow the correction mechanism in the Commission’s documentation — correlation identifiers, the right MessageTypeIndic — and upload the correction through a new procedure.
8. Worked case: a newly authorised EMI with a non-resident director
Facts: an e-money institution authorised by the CSSF in the spring starts serving merchants in other Member States in June. Its managing director lives in Belgium and holds no LuxTrust product. Q3 is its first quarter above the threshold.
What the rule says: the Q3 file is due by 31 October through a certified CESOP eSpace. An eIDAS identity from another EU country is an accepted authentication product.
What the practitioner does: the director creates the business eSpace with the Belgian eID in July, signs the mandate form, and files the certification request with a fresh RCS extract. Once certified, the director invites the head of compliance and a reporting analyst as administrators and sets the eSpace e-mail to a shared reporting mailbox.
Outcome: the certification is done before the first file exists, and the October upload runs with two administrators, so it does not hinge on one person being available.
9. Worked case: a quarter too big for one upload
Facts: a Luxembourg payment institution’s Q2 message comes to 1.4 GB of XML.
What the rule says: one procedure takes one file of up to 80 MB, compressed or not, and the unzipped file must stay under 900 MB. A split message needs one procedure per file, each named with its part number and total parts.
What the practitioner does: splits the message into parts small enough that each zip stays under 80 MB, names them ...-1-n to ...-n-n, validates each with the Commission module and opens one upload procedure per part.
Outcome: a set of acknowledgments, one per part, all filed against the quarter.
10. Worked case: a full rejection at the AED
Facts: a file uploaded on 24 July returns FULL REJECTION with an error list in the eSpace.
What the rule says: a fully rejected message never reached CESOP and is treated as void. The fix is not a correction message. It is a new CESOP100 message in a new procedure, before 31 July.
What the practitioner does: fixes the listed errors, re-runs the Commission module, and uploads the corrected file as a new-data message. A fresh MessageRefId is the safe choice, so that the new file cannot be mistaken for the rejected one.
Outcome: acknowledgment on the new upload, and later the IE3V01 result from CESOP.
11. Worked case: partially rejected by CESOP
Facts: the AED accepted the Q1 file, but the IE3V01 result says PARTIALLY REJECTED for a handful of payee records.
What the rule says: the accepted records stand. The rejected ones must be corrected under the Commission’s correction mechanism, and the correction goes in a new upload procedure.
What the practitioner does: builds a corrective message (CESOP101) for the rejected records only, referencing the original message, and uploads it.
Outcome: the quarter closes with the original file, the correction, both AED acknowledgments and both IE3V01 results on file.
FAQ
Who receives CESOP data in Luxembourg?
The AED (Administration de l’enregistrement, des domaines et de la TVA), through its CESOP service. It validates the files and forwards them to the Commission’s central system.
Which channel is used?
A certified CESOP business eSpace on MyGuichet.lu, through the procedure “AED – Upload a CESOP payment data message”. API pre-filling through the State API Gateway is available.
What do we need to certify the eSpace?
The signed mandate form for certifying a CESOP business eSpace and a recent RCS extract proving the signatory’s authority.
What is the file size limit?
One file per procedure, at most 80 MB. Zipped files are accepted if the unzipped XML is under 900 MB, the zip holds one XML only, and it is not password-protected or encrypted.
Our file was fully rejected. Do we send a correction?
No. A fully rejected file never reached CESOP, so you send a new CESOP100 message in a new procedure before the deadline.
How do we contact the AED?
The CESOP service at aed.cesop@en.etat.lu or (+352) 247 80 800.
What to do, today
- Head of regulatory reporting: check that your CESOP eSpace is certified, used for CESOP only, and has at least two administrators.
- Compliance: put the eSpace access list into your quarterly privileged-access review.
- Data team: build the 80 MB / 900 MB split logic and the Commission file-naming rule into the export, not into a manual step.
- Passported firms: map each host Member State you serve; each needs its own file to its own tax administration, alongside the AED file.
Related: Building the CESOP file · The Luxembourg reporting calendar · CESOP in France


