Circular C799: Joint Guidelines on Costs & Losses from Major ICT-related incidents under DORA
On September 8, 2026, the Cyprus Securities and Exchange Commission (CySEC) issued Circular C799, providing regulated entities with additional information on the submission of the reporting template set out under the European Supervisory Authorities’ Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (DORA).
The reporting requirement covers the aggregated annual costs and losses arising from major ICT-related incidents during the selected reference year.
The Report should be submitted only by financial entities that have experienced major ICT-related incidents during the relevant reporting period.
Key points of the Circular:
1. Scope of application
Circular C799 applies to the following regulated entities:
- Cyprus Investment Firms (CIFs)
- Crypto-Asset Service Providers authorised by CySEC under Regulation (EU) 2023/1114 (MiCA)
- Issuers of Asset-Referenced Tokens where the Republic of Cyprus is the issuer’s Home Member State and the issuer has been authorised by CySEC in accordance with Article 21 of MiCA
- Central Securities Depositories authorised in the Republic for the relevant basic and/or non-banking ancillary services under Regulation (EU) No 909/2014
- Central counterparties falling under Regulation (EU) No 648/2012 and established in the Republic
- Trading venues of the Republic
- Alternative Investment Fund Managers of the Republic
- Management companies authorised by CySEC
- Crowdfunding service providers authorised by CySEC
2. Reporting of ICT-related costs and losses
Regulated entities that have experienced major ICT-related incidents must estimate and report to CySEC the aggregated annual costs and losses arising from those incidents.
The Report should aggregate all costs and losses associated with major ICT-related incidents occurring during the selected reference year.
Entities should also carefully review the ESAs’ Joint Guidelines when preparing the Report.
3. Selection of the reference year
Entities may select either:
- the completed calendar year, or
- the completed accounting year for which the entity has finalised its financial statements.
The selected reference year must be clearly stated in the Report and should be applied consistently in future in future estimations and reporting.
4. Reporting deadlines
The Report must be submitted to CySEC no later than June 30 each year, following the reference year in which the major ICT-related incidents occurred.
For example, where an entity selects the 2026 calendar year as its reference year and experiences major ICT-related incidents during that year, the relevant Report must be submitted by June 30, 2027.
For major ICT-related incidents incurred during 2025, however, the Report must be submitted by September 30, 2026.
5. Submission method
The reporting template is downloadable from the Circular and must be submitted exclusively through the CySEC Portal under the title:
“Estimation of Aggregated Annual Costs and Losses Caused by Major ICT-Related Incidents”.
For more regulatory reporting obligations to meet in 2026, please visit the SALVUS Regulatory Reporting Obligations Calendar™.
Contact us at compliance@salvusfunds.com if you have any questions or require support with your DORA reporting obligations and regulatory requirements. Our Regulatory Compliance team is ready to support you.
#StayAhead