I am text block. Click edit button to change this text. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.
CySEC Circular C754: Cross-Border Data Collection Requirements, Deadlines & What CIFs Must Do
Introduction
CySEC Circular C754 reopens the annual ESMA-initiated cross-border data collection exercise for Cyprus Investment Firms that provide investment services into other EEA states on a freedom-to-provide-services basis. It is a recurring reporting obligation, not a new conduct rule, but the mechanics matter this year: the scope test turns on whether the firm served more than 50 active retail clients in at least one host Member State during 2025, and firms must respond to CySEC whether they are in scope or out of scope. The first response — a single company email address if in scope, or a positive out-of-scope confirmation if below the threshold — was due by 18 February 2026. Detailed completion instructions and the questionnaire deadline follow in companion Circular C757. Resolving these overlapping multi-jurisdictional obligations requires robust [Cross-Border and MiFID II Advisory] to map your passporting footprint accurately. Firms should run the scope assessment against the 50-retail-client threshold per host state, document the conclusion, and respond either way.
CySEC Circular C754 – At a Glance
- Issued date: 9 February 2026 (Circular C754), issued pursuant to section 25(1)(c)(ii) and (iii) of the CySEC Law. Signed by Dr George Theocharides, Chairman.
- Applies to: Cyprus Investment Firms (CIFs) authorised by 31 December 2025 that provided cross-border services on a freedom-to-provide-services basis to more than 50 active retail clients (including clients treated as professionals on request under Section II of Annex II of MiFID II) in at least one host EEA Member State during 2025.
- Deadline: Wednesday 18 February 2026 — confirm in-scope or out-of-scope status to CySEC by email to riskstatistics.cifs@cysec.gov.cy. (The questionnaire submission deadline of 27 March 2026 is set by companion Circular C757.)
- Key requirement: assess scope against the 50-active-retail-client threshold per host Member State and respond to CySEC either way — providing a single valid company email address if in scope, or positively confirming out-of-scope status if below the threshold.
- Submission method: email to riskstatistics.cifs@cysec.gov.cy for the scope response; the exercise itself is then completed via the EU online questionnaire (electronic form), with the link sent by CySEC only to in-scope CIFs.
What Does This Circular Require?
What firms must do. Every CIF authorised by 31 December 2025 must assess whether it falls under the scope of this exercise by consulting all of the information in the circular, and must respond to CySEC. CIFs that fall in scope must provide a single, valid company email address (for example compliance@ or info@) to which the electronic form will be forwarded, by emailing riskstatistics.cifs@cysec.gov.cy by 18 February 2026. CIFs that do not reach the materiality threshold of more than 50 active retail clients in at least one EEA Member State should inform CySEC, by the same email and the same date, that they are not required to complete the Form. CySEC will send the link to the electronic form only to CIFs that fall in scope.
Legal basis. The circular is issued pursuant to section 25(1)(c)(ii) and (iii) of the CySEC Law. The exercise is initiated by ESMA and conducted via the EU’s online platform.
Regulatory objective. The exercise gathers data on investment services provided by Investment Firms to retail clients in host EEA Member States under the freedom to provide services, analysed per host Member State. It is an existing annual data collection refreshed with technical improvements to the EU reporting template, giving ESMA and national regulators a view of cross-border retail activity rather than a firm-by-firm conduct inspection. Managing this fluid supervisory environment requires structured Regulatory Compliance Services to maintain ongoing alignment
Who Is in Scope?
The obligation to complete the cross-border online questionnaire applies to:
- Cyprus Investment Firms (CIFs) authorised by 31 December 2025
- that provided cross-border services on a freedom-to-provide-services basis
- to more than 50 active retail clients — including clients treated as professionals on request under Section II of Annex II of MiFID II —
- in at least one host EEA Member State (the EEA includes Norway, Iceland and Liechtenstein) during 2025.
The reporting period is 1 January 2025 to 31 December 2025, with reference date 31 December 2025. The threshold is assessed per host Member State, so a firm may be in scope for one jurisdiction and not others.
Edge cases and exceptions:
- Freedom of establishment (branches): services provided on a freedom-of-establishment basis are excluded — CIFs should not account for branch activity. Only freedom-to-provide-services activity is counted.
- Inactive clients: excluded only where three conditions are cumulatively met — inactivity lasted at least one year; no investment or ancillary services were provided to the client; and the CIF no longer receives any revenues from the client. Where the firm still receives any form of remuneration during the inactivity period (for example, a fee on an open but dormant securities account), CySEC expects the client to be counted.
- Assessing where services are provided: CIFs may use the client’s place of residence to assess whether investment services and activities are provided in another Member State.
- Out-of-scope firms: CIFs below the threshold in every host Member State are not required to complete the Form, but must still positively inform CySEC of that fact — silence is not an acceptable response.
Key Requirements Breakdown
Reporting / Submission Requirements
C754 sets the first, gating response: by 18 February 2026, every CIF must email riskstatistics.cifs@cysec.gov.cy to either provide a single valid company email address (in scope) or confirm it is not required to complete the Form (out of scope). CySEC then sends the link to the electronic form only to in-scope CIFs. The questionnaire itself is completed via the EU online platform; its submission deadline (27 March 2026) and detailed completion instructions are set by the companion Circular C757, referenced in C754 as a forthcoming new circular.
Data or Form Requirements
The exercise is conducted via the EU’s online questionnaire (electronic form). It collects data on cross-border investment services provided to retail clients — and to clients treated as professionals on request under Section II of Annex II of MiFID II — analysed per host Member State, for the 2025 reporting period. ESMA has introduced technical improvements to the reporting template this year. The field-level content and structure of the electronic form are set out in Circular C757 [CONFIRM — completion detail is provided in C757, not in C754].
Technical / System Requirements
The questionnaire is hosted on the EU’s online platform. CySEC forwards the link to the electronic form to the single company email address supplied by each in-scope CIF; firms should ensure that mailbox is monitored and that the address is a valid, actively used company account. The portal access mechanics, credentials and any session constraints are governed by Circular C757 [CONFIRM — not specified in C754].
Validation or Approval Process
Before responding, the firm must assess whether it falls under the scope of the exercise by consulting all of the information in the circular (the reporting period, the freedom-of-services basis, the inactive-client test and the residence proxy) and reach a documented scope conclusion. The scope determination — in scope, and for which host states, or out of scope — should be recorded with the supporting figures and sign-off before the email response is sent. Any validation or approval built into the electronic form itself is governed by Circular C757 [CONFIRM — not specified in C754].
Practical Implementation: What Firms Should Do
In practice, the recurring issue with reporting exercises of this kind is rarely understanding the questions; it is the evidence trail behind the answers. The exercise turns on a scope test — the 50-active-retail-client threshold per host Member State — and a firm’s answer to that test is itself a compliance judgement that should be documented. Firms should be able to show how they extracted their cross-border client population, how they distinguished freedom-of-services activity from branch activity, how the inactive-client test was applied, and how the scope conclusion was reached and approved. The same applies to the out-of-scope route: a firm telling CySEC it falls below the threshold should be able to show the calculation that supports that statement.
The most common mistakes are practical ones: scope assessments performed but not documented; client residence data that is incomplete or stale; the freedom-of-services and freedom-of-establishment populations not clearly separated; the inactive-client definition applied inconsistently with the revenue-still-received carve-out; and treating silence as sufficient when out of scope. What CySEC expects is a considered, defensible scope determination and a timely response either way. CySEC has stated that it will not send reminders to CIFs that fail to comply, and that failure to comply promptly and duly may attract the administrative penalties of section 37(5) of the CySEC Law.
Key Dates and Deadlines
| Date | What happens |
| 9 February 2026 | Circular C754 issued, reopening the ESMA cross-border data collection exercise for the 2025 reporting year. |
| 18 February 2026 (Wednesday) | Deadline (C754) to respond to CySEC by email to riskstatistics.cifs@cysec.gov.cy — provide a single valid company email address if in scope, or positively confirm out-of-scope status if below the 50-retail-client threshold. |
| 27 March 2026 | Deadline to submit the completed cross-border questionnaire, as set by companion Circular C757 (referenced in C754 point 1.9). Detailed completion instructions are provided in that circular. |
Step-by-Step Submission Process
- Confirm the CIF was authorised by 31 December 2025, so that it is potentially within scope of the exercise.
- Extract the firm’s full cross-border client population for the reporting period 1 January 2025 to 31 December 2025 (reference date 31 December 2025), and record the data source and extraction method.
- Separate freedom-of-services activity from freedom-of-establishment (branch) activity, and exclude branch activity from the count.
- Apply the inactive-client test — exclude a client only where all three conditions are cumulatively met, keeping any client from whom a fee is still received.
- Allocate clients to host Member States using client residence, and assess the more-than-50-active-retail-client threshold for each host state separately, including clients treated as professionals on request under Section II of Annex II of MiFID II.
- Record the scope conclusion — in scope (and for which host states) or out of scope — with the supporting figures, owner, date and sign-off.
- Respond to CySEC by email to riskstatistics.cifs@cysec.gov.cy by 18 February 2026: if in scope, provide a single valid company email address to which the electronic form will be forwarded; if out of scope, positively confirm the firm is not required to complete the Form. Retain the sent email.
- If in scope, await the link to the electronic form, which CySEC sends only to in-scope CIFs, and monitor the mailbox given to CySEC.
- Complete the cross-border electronic form on the EU online platform following the instructions in Circular C757 [CONFIRM — field-level completion steps, per-host-state contributions and portal mechanics are set out in C757, which is not reproduced here].
- Submit the completed questionnaire by the C757 deadline of 27 March 2026, and retain evidence of submission [CONFIRM submission-confirmation artefact against C757].
Compliance Officer Checklist
- Confirm authorisation status (authorised by 31 December 2025) and record the determination.
- Extract the cross-border client population for 1 January 2025 to 31 December 2025 and document the data source and method.
- Separate freedom-of-services from freedom-of-establishment (branch) activity and exclude the latter.
- Apply the inactive-client test (three cumulative conditions) and retain the rationale, keeping clients from whom any fee is still received.
- Allocate clients to host Member States by residence and assess the more-than-50 threshold per host state, including elective professionals under Annex II Section II.
- Record the scope conclusion (in scope and for which host states, or out of scope) with supporting figures, owner, date and sign-off.
- Send the required email to riskstatistics.cifs@cysec.gov.cy by 18 February 2026 — company email address if in scope, out-of-scope confirmation if below the threshold — and retain the sent email.
- If in scope, confirm receipt of the electronic-form link and complete and submit the questionnaire by 27 March 2026 per Circular C757.
- UUpdate the internal [Compliance Monitoring Services] protocols and regulatory-reporting log to record the exercise, the conclusion and the evidence retained.
Evidence to Retain
- The dated scope determination, including the per-host-state figures and the in-scope/out-of-scope conclusion.
- The extraction of the cross-border client population, with data source and method.
- The rationale for the freedom-of-services vs freedom-of-establishment split.
- The inactive-client analysis, including the treatment of clients from whom a fee is still received.
- A dated copy of the email sent to riskstatistics.cifs@cysec.gov.cy (in-scope email address or out-of-scope confirmation).
- Evidence of submission of the completed questionnaire per host Member State, where in scope [CONFIRM confirmation artefact against C757].
- A record of who prepared, reviewed and approved the scope conclusion and the responses, and when.
Why This Matters
C754 is a time-bound reporting obligation with a firm first deadline of 18 February 2026, and both in-scope and out-of-scope firms must respond — silence is not an option. CySEC has been explicit that it will not send reminders, and that failure to comply promptly and duly may attract the administrative penalties of section 37(5) of the CySEC Law. Although the exercise drives a data collection rather than a firm-level inspection, the scope decision is a compliance judgement that should be defensible: a firm should be able to show how it counted its cross-border clients, applied the threshold per host state, and reached its conclusion. Because the exercise maps directly onto a firm’s passporting footprint, it also functions as a useful annual checkpoint on whether cross-border activity, client categorisation and regulatory reporting are aligned.
Frequently Asked Questions
What is CySEC Circular C754?
C754, dated 9 February 2026, reopens the annual ESMA-initiated cross-border data collection exercise for the 2025 reporting year. It is conducted via the EU’s online questionnaire and collects data on investment services provided by CIFs to retail clients in host EEA Member States under the freedom to provide services. It is an existing annual obligation refreshed with technical changes to the EU template, not a new conduct rule.
Which firms have to complete the questionnaire?
CIFs authorised by 31 December 2025 that provided cross-border services on a freedom-to-provide-services basis to more than 50 active retail clients — including clients treated as professionals on request under Section II of Annex II of MiFID II — in at least one host EEA Member State during 2025. The threshold is assessed per host Member State.
What do we do if we are below the threshold?
Firms below the more-than-50-active-retail-client threshold in every host Member State must still positively inform CySEC that they are not required to complete the Form, by email to riskstatistics.cifs@cysec.gov.cy by 18 February 2026. Not responding is not an option.
Does branch (freedom-of-establishment) activity count?
No. The exercise covers only services provided on a freedom-to-provide-services basis. Activity carried out through a branch under freedom of establishment is excluded from the count and from the questionnaire.
How are inactive clients treated?
Inactive clients are excluded only where three conditions are cumulatively met: inactivity for at least one year, no investment or ancillary services provided, and no revenues received from the client. If the firm still receives any fee — such as a charge on an open but dormant securities account — the client should be counted.
When is the questionnaire itself due?
C754 sets 18 February 2026 as the deadline to respond on scope. The deadline to submit the completed questionnaire — 27 March 2026 — and the detailed completion instructions are set by the companion Circular C757, which C754 flags as a forthcoming new circular.
How CX Financia Can Support You
For CIFs with cross-border activity, the priority is a structured, evidenced exercise: which clients were counted, how the freedom-of-services population was isolated, how the threshold was applied per host state, what was submitted, and what supporting records have been retained.
CX Financia provides end-to-end support across all phases of your regulatory obligations. From deploying robust Regulatory Compliance Services to tailoring precision Cross-Border and MiFID II Advisory blueprints, we ensure your cross-border numbers are pristine. Our team is fully equipped to deploy independent Internal Audit Services, organize your overarching Compliance Monitoring Services, and deliver thorough reporting Submission-Readiness Support so you submit to the EU portal with absolute confidence.
Key Regulatory References
For detailed technical specifications, cross-border frameworks, and official regulatory reporting guidelines, you can verify the authoritative requirements directly via the official portals:
-
CySEC Official Circulars: Check the Cyprus Securities and Exchange Commission (CySEC) Regulatory Framework for the latest directives on submission readiness and local AML compliance mandates (such as Circular C754 regarding Electronic Cross-Border Activity).
-
ESMA Interactive Rules: Consult the European Securities and Markets Authority (ESMA) to review cross-border investment firm data collection standards, MiFID II passporting rules, and pan-European compliance monitoring expectations.
Disclaimer
General information, not regulatory advice. Firms should refer to the text of Circular C754 (and companion Circular C757) and seek tailored advice on their specific circumstances.
