2026-09-08 | C799

Added · Updated

Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU 2022/2554

CySEC requires specific regulated entities, including CIFs, Crypto-Asset Service Providers, and Central Securities Depositories, to estimate and report aggregated annual costs and losses arising from major ICT-related incidents. Entities must use the "Report on Aggregated Annual Costs and Losses from Major ICT-Related Incidents" for a chosen reference year, which can be a completed calendar or accounting year. This report is due by 30 June each year following the reference year, but only from entities that experienced major ICT-related incidents during the relevant reporting period. For incidents incurred in 2025, the submission deadline is 30 September 2026, with all reports to be submitted through CySEC’s Portal.

Cyprus Securities and Exchange Commission logo

Cyprus

Cyprus Securities and Exchange Commission

Scan of the document's first page
Share

CySEC published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free, and get an email when CySEC publishes again

Source: Cyprus Securities and Exchange Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CySEC

CySEC published 3 documents in the last 30 days. We email you each new one the day it's published.