2026-09-30
Added
This Circular updates the Cyber Reporting Management System (CRMS) for Authorised Persons within the scope of Regulation (EU) 2022/2554 (DORA Regulation). It introduces Frequently Asked Questions (FAQs), enhancements to the CRMS including a reclassification functionality for major incidents in line with Commission Implementing Regulation (EU) 2025/302, and updates to user access management and submission controls. Additionally, the Malta Financial Services Authority is making available illustrative examples and updating supporting documentation for Major ICT-Related Incidents, Significant Cyber Threats, and Information-Sharing Arrangements. Authorised Persons are required to ensure access to the CRMS Project within the Licence Holder Portal, as failure to submit required notifications and reports may lead to regulatory action.
MFSA published 2 documents in the last 30 days — get each new one by email the day it lands.
Circular
Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Cyber Reporting Updates This Circular is an update to Circular titled Cyber Reporting Management System (CRMS) published by the Authority in January 2025. As outlined by the latter circular, Authorised Persons within scope (see Article 2 of the DORA Regulation) of Regulation (EU) 2022/2554 (the ‘DORA Regulation’): 1) shall report Major ICT-Related Incidents, 2) are to notify Significant Cyber Threats on a voluntary basis, and 3) shall notify their voluntary participation in, or, as applicable, the cessation of their membership from, InformationSharing Arrangements to the Authority. The Authority is implementing a number of changes, including the introduction of Frequently Asked Questions (FAQs), updates to the CRMS within the Licence Holder (LH) Portal, and revisions to supporting documentation. These updates are intended to provide further guidance to Authorised Persons. Frequently Asked Questions (FAQs) The Authority released FAQs covering each of the three Cyber Reporting areas (Major ICTRelated Incidents, Significant Cyber Threats, and Information-Sharing Arrangements) under the DORA Regulation. The three sets of FAQs are available on the MFSA website (our work > Supervisory ICT Risk and Cybersecurity), under the following tabs; ‘Major ICT-Related Incident Reporting’, ‘Significant Cyber Threat Notification’ and ‘Information-Sharing Arrangement Notification’. Cyber Reporting Management System (‘CRMS’)
Read the rest free, and get an email when MFSA publishes again
Source: Malta Financial Services Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from MFSA
MFSA published 2 documents in the last 30 days. We email you each new one the day it's published.