CySEC, DORA and the New Cyber-Resilience Rules for Cyprus's Financial Sector
Cyprus's financial firms are operating under a markedly tougher cybersecurity regime, but the driving force is not a stand-alone national scheme. It is the EU's Digital Operational Resilience Act (DORA), which has applied directly across all member states since 17 January 2025. As the national competent authority for its regulated entities, the Cyprus Securities and Exchange Commission (CySEC) is responsible for supervising and enforcing these rules on the island.
DORA is a regulation rather than a directive, which means it takes effect uniformly across the EU without needing to be transposed into Cypriot law. It applies to a broad range of financial entities, including Cyprus Investment Firms (CIFs), fund managers, payment and electronic money institutions, insurers and crypto-asset service providers. The aim is to ensure these firms can withstand, respond to and recover from disruptions to their information and communication technology (ICT), such as cyberattacks and system failures.
What DORA actually requires
DORA is built around five areas of obligation:
- ICT risk management - a documented framework to identify, protect against, detect and recover from ICT risks, with oversight by the firm's management body.
- Incident reporting - classifying ICT-related incidents and reporting major ones to the regulator through a structured process of initial, intermediate and final reports, with voluntary notification of significant cyber threats.
- Digital operational resilience testing - regular testing of systems, with threat-led penetration testing required for the most critical entities.
- ICT third-party risk management - due diligence and contractual controls over outsourced ICT providers, plus a register of those arrangements.
- Information sharing - voluntary exchange of cyber threat intelligence between financial entities.
How CySEC is implementing it
CySEC has issued guidance to translate DORA into practical obligations for supervised firms. In April 2025 it published Circular C700, setting out the two central reporting duties: the reporting of major ICT-related incidents, and the submission of a Register of Information covering contractual arrangements with ICT third-party service providers that support critical or important functions.
In January 2026, CySEC followed with Circular C751, which consolidates reporting, governance and portal-related obligations. Its points include the requirement that the Register of Information be submitted annually - with a reference date of 31 December and a filing deadline of 28 February - in the prescribed XBRL-CSV format rather than as a spreadsheet. Firms must also maintain a documented ICT risk-management framework reviewed at least annually, and register their designated ICT auditor and ICT risk manager through the CySEC portal.
What it means for firms
For regulated businesses in Cyprus, the practical message is that cyber-resilience is now a formal, enforceable part of the supervisory relationship rather than a matter of good practice. Non-compliance can attract administrative penalties and supervisory action. Firms are expected to demonstrate clear governance and accountability for ICT risk, tested recovery arrangements, and an accurate register of their technology suppliers.
Smaller entities are not exempt, although the burden is scaled. Certain smaller investment firms and microenterprises may apply a simplified ICT risk-management framework, and some obligations are proportionate to a firm's size and risk profile. Even so, the core expectation applies across the board: that a financial firm can keep operating, and recover, when its technology is attacked or fails.