2026-09-30

Added

Cyber Reporting Updates

This Circular updates the Cyber Reporting Management System (CRMS) for Authorised Persons within the scope of Regulation (EU) 2022/2554 (DORA Regulation). It introduces Frequently Asked Questions (FAQs), enhancements to the CRMS including a reclassification functionality for major incidents in line with Commission Implementing Regulation (EU) 2025/302, and updates to user access management and submission controls. Additionally, the Malta Financial Services Authority is making available illustrative examples and updating supporting documentation for Major ICT-Related Incidents, Significant Cyber Threats, and Information-Sharing Arrangements. Authorised Persons are required to ensure access to the CRMS Project within the Licence Holder Portal, as failure to submit required notifications and reports may lead to regulatory action.

Malta Financial Services Authority logo

Malta

Malta Financial Services Authority

Scan of the document's first page
Share

MFSA published 2 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free, and get an email when MFSA publishes again

Lineage: In force

Regulation (EU) 2022/2554 of th…2022Circular of 2025not in RegAlertCyber Reporting Updates2026-09-30 · this document
amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Malta Financial Services Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from MFSA

MFSA published 2 documents in the last 30 days. We email you each new one the day it's published.