2026-09-08 | C799Added · Updated
CySEC requires specific regulated entities, including CIFs, Crypto-Asset Service Providers, and Central Securities Depositories, to estimate and report aggregated annual costs and losses arising from major ICT-related incidents. Entities must use the "Report on Aggregated Annual Costs and Losses from Major ICT-Related Incidents" for a chosen reference year, which can be a completed calendar or accounting year. This report is due by 30 June each year following the reference year, but only from entities that experienced major ICT-related incidents during the relevant reporting period. For incidents incurred in 2025, the submission deadline is 30 September 2026, with all reports to be submitted through CySEC’s Portal.
CySEC published 3 documents in the last 30 days — get each new one by email the day it lands.
1
_______________________________________________________________ TO : Regulated Entities:
i. CIFs
ii. Crypto-Asset Service Providers authorised by CySEC under the
Regulation (EU) No 2023/1114
iii. Issuers of Asset-Referenced Tokens when the Home Member
State of the issuer of the said token is the Republic and which has been authorised by CySEC, in accordance with Article 21 of Regulation (EU) 2023/1114
iv. Central Securities Depositories that have been authorised in the
Republic for the basic services of Section A of Regulation (EU) no. 909/2014 and/or for non-banking ancillary services of Section B of Regulation (EU) no. 909/2014
v. Central counterparties that fall under Regulation (EU) No.
648/2012 who are established in the Republic
vi. Trading venues of the Republic
vii. Alternative Investment Fund Managers of the Republic
viii. Management companies authorised by CySEC
ix. Crowdfunding services providers authorised by CySEC
FROM : Cyprus Securities and Exchange Commission DATE : 8 September 2026 CIRCULAR No : C799 SUBJECT : Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU 2022/2554 Following CySEC’s Circular C735 and the adoption of Joint Guidelines of the European Supervisory Authorities (“ESAs”) on the estimation of aggregated annual costs and losses caused by major ICT-related incidents (the ‘Joint Guidelines’), the Cyprus Securities and Exchange Commission (‘CySEC’) hereby provides Regulated Entities with additional information concerning the submission of the reporting template set out in the Joint Guidelines.
Read the rest free, and get an email when CySEC publishes again
Source: Cyprus Securities and Exchange Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CySEC
CySEC published 3 documents in the last 30 days. We email you each new one the day it's published.