2025-09-12
The Financial Sector Conduct Authority and Prudential Authority have issued a draft determination mandating a standardized notification template for material IT and cyber incidents under their 2023 and 2024 Joint Standards. Financial institutions must submit incident reports using this template, with stakeholder comments due by 5 October 2025 to designated regulatory email addresses. The directive streamlines compliance reporting and strengthens regulatory oversight of cybersecurity resilience across the financial sector.
Joint Communication 3 of 2025 For consultation - Determination of the notification template in terms of Joint Standard 1 of 2023 – IT Governance and Risk Management for Financial Institutions and Joint Standard 2 of 2024 – Cybersecurity and Cyber Resilience Requirements for Financial Institutions
3.2 Comments are due on 5 October 2025 and must be submitted to PA-Standards@resbank.co.za for the attention of Kalai Naidoo and FSCA.RFDStandards@fsca.co.za for the attention of Andile Mjadu. UNATHI KAMLANA FUNDI TSHAZIBANA Commissioner: Chief Executive Officer: Financial Sector Conduct Authority Prudential Authority DATE: 3/09/2025 DATE:3/09/2025