Skip to main content
0

Introduction

CySEC issued Circular C799 on September 8, 2026, detailing the new joint guidelines for estimating aggregated annual costs and losses from major ICT-related incidents. It affects regulated financial entities and specifies a consistent methodology for annual reporting. The first submission deadline is September 30, 2026, for incidents in 2025.

CySEC Circular C799 – At a Glance

  • Issued date: 8 September 2026
  • Applies to: Regulated Financial Entities
  • Deadline: 30 September 2026 for 2025 incidents
  • Key requirement: Estimate and report aggregated costs and losses of ICT incidents
  • Submission method: CySEC Portal

What Does This Circular Require?

What firms must do. Estimate and report aggregated annual costs and losses from major ICT-related incidents using the specified Report.

Legal basis. Joint Guidelines under Regulation (EU) 2022/2554

Regulatory objective. Ensure accurate reporting of costs and losses from ICT incidents to mitigate risks and ensure transparency.

Who Is in Scope?

The circular applies to various regulated financial entities that have experienced major ICT-related incidents.

  • CIFs
  • Crypto-Asset Service Providers
  • Issuers of Asset-Referenced Tokens
  • Central Securities Depositories
  • Central Counterparties
  • Trading Venues
  • Alternative Investment Fund Managers
  • Management Companies
  • Crowdfunding Services Providers

Key Requirements Breakdown

Reporting / Submission Requirements

Select a reference year and report annually by June 30th following the reference year; incidents in 2025 must be reported by September 30, 2026.

Data or Form Requirements

Report on Aggregated Annual Costs and Losses from Major ICT-Related Incidents

Practical Implementation: What Firms Should Do

In practice, firms should identify all major ICT-related incidents from the completed calendar or accounting year and calculate both costs and losses. Consistency in selecting the reference year is crucial. Reports are only needed if incidents occurred.

Key Dates and Deadlines

Step-by-Step Submission Process

  1. Identify major ICT-related incidents for the selected reference year.
  2. Aggregate costs and losses for those incidents.
  3. Select a consistent reference year (calendar or accounting).
  4. Review the Joint Guidelines thoroughly.
  5. Submit the Report via CySEC Portal under the correct title.

Compliance Officer Checklist

  • Identify ICT incidents
  • Calculate costs and losses
  • Select reference year
  • Review guidelines
  • Submit report

Evidence to Retain

  • Aggregated costs and losses calculations
  • Selected reference year documentation

Why This Matters

Accurate reporting minimizes the risks associated with ICT incidents such as financial loss and reputational damage. CySEC’s guidelines aim to standardize this process, enhancing transparency and risk management across financial entities.

Frequently Asked Questions

What types of entities are affected?

CIFs, Crypto-Asset Service Providers, Issuers of Asset-Referenced Tokens, Central Securities Depositories, Central Counterparties, Trading Venues, Alternative Investment Fund Managers, Management Companies, and Crowdfunding Services Providers.

What incidents must be reported?

Entities must report aggregated costs and losses from major ICT-related incidents occurring in the selected reference year.

When is the first report due?

For incidents occurring in 2025, reports are due by September 30, 2026.

How should the report be submitted?

Submit via CySEC Portal under ‘Estimation of Aggregated Annual Costs and Losses Caused by Major ICT-Related Incidents’.

Is there a specific methodology for choosing the reference year?

Entities may choose either the completed calendar year or the accounting year in which financial statements are finalized, and must apply this choice consistently.

How CX Financia Can Support You

CX Financia assists with Regulatory Compliance and Risk Management, ensuring you comply with these new reporting obligations. Contact us to simplify your ICT reporting process.

Read the CySEC Circular C799

Read more at Regulatory Updates

Disclaimer

General information, not regulatory advice…

Close Menu