CySEC Circular C751: DORA Reporting & Governance Requirements, Deadlines & What Firms Must Do
Introduction
CySEC Circular C751 is a practical follow-up for firms already inside the DORA framework, clarifying where supervisory attention is now falling. Issued further to Circular C700, it sharpens four existing expectations: incident classification, the Register of Information format, ICT governance, and CySEC Portal designations. For most firms, the work is to confirm they can evidence that existing [DORA reporting requirements] are met. Firms looking to evaluate their current frameworks can leverage our specialized Regulatory Compliance Services to ensure full alignment.
CySEC Circular C751 – At a Glance
- Issued date: 19 January 2026 (Circular C751), signed by the Chairman, Dr George Theocharides, and issued further to Circular C700, to provide guidance on obligations arising under DORA (Regulation (EU) 2022/2554).
- Applies to: Regulated Entities — Cyprus Investment Firms (CIFs), Central Securities Depositories, Trading Venues, Crypto-Asset Providers (CASPs), Alternative Investment Fund Managers (AIFMs) and UCITS Management Companies.
- Deadline: no new deadline is introduced. C751 confirms the standing requirement that the Register of Information be submitted annually, no later than 28 February each year, with reference date 31 December of the preceding year.
- Key requirement: comply with in-force DORA duties across four areas — correct classification and timely reporting of major ICT-related incidents; submission of the Register of Information in XBRL-CSV format; a documented, independently governed and audited ICT risk management framework under Article 6; and two CySEC Portal designations (ICT auditor and ICT risk control-function owner).
- Legal Foundation: Regulation (EU) 2022/2554 (DORA).
- Submission method: the Register of Information is generated with XBRL-compatible software, compressed (zipped) and submitted through the CySEC XBRL Portal in XBRL-CSV format. Portal designations are made under the Auditors and Personnel sections of the CySEC Portal.
What Does This Circular Require?
C751 requires Regulated Entities to consult Commission Delegated Regulation (EU) 2024/1772 and classify and report major ICT-related incidents correctly and on time; to submit the Register of Information in XBRL-CSV format via the CySEC XBRL Portal, no later than 28 February each year; to maintain a well-documented ICT risk management framework meeting the Article 6 DORA requirements; and (for entities other than microenterprises) to designate the ICT auditor and the ICT risk control-function owner in the CySEC Portal. These are obligations already in force; C751 provides guidance, reminders and format confirmation rather than a new rule.
Legal basis. The circular is issued further to Circular C700, providing guidance on obligations arising under Regulation (EU) 2022/2554 (the Digital Operational Resilience Act, DORA), with reference to Commission Delegated Regulation (EU) 2024/1772 (ICT incident classification) and Commission Delegated Regulation (EU) 2024/1774 (ICT risk management).
Regulatory objective. CySEC has expressly framed C751 around observed deficiencies — CySEC reports that incidents that should have been reported as major were not, while other incidents reported as major were incorrectly classified. The circular therefore signals where supervisory scrutiny is likely to concentrate: correct incident classification, the accepted Register submission format, independent governance of the ICT risk framework, and current CySEC Portal designations. The practical implication is that an arrangement which exists on paper but cannot be evidenced is the kind of gap most likely to attract attention.
Who Is in Scope?
The circular is addressed to the following Regulated Entities:
- Cyprus Investment Firms (CIFs)
- Central Securities Depositories
- Trading Venues
- Crypto-Asset Providers (CASPs)
- Alternative Investment Fund Managers (AIFMs)
- UCITS Management Companies
Any reference in DORA to “financial entities” is, for the purposes of this circular, to be understood as a reference to the Regulated Entities above.
Proportionality and thresholds:
- Microenterprises: several duties apply to entities other than microenterprises — the Article 6(4) independent control function, the internal audit under Article 6(6), and both CySEC Portal designations. Microenterprises review their framework periodically rather than at least annually.
- Small and non-interconnected (Class 3) investment firms: are reminded that they are subject to a simplified ICT risk management framework, applying the principle of proportionality as set out in Title III of Commission Delegated Regulation (EU) 2024/1774.
Key Requirements Breakdown
What firms must do. C751 demands that firms classify major ICT incidents via Commission Delegated Regulation (EU) 2024/1772 and submit the Register of Information in XBRL-CSV format via the CySEC portal by 28 February. Our team provides comprehensive AML and DORA Compliance Support to help firms transition from manual Excel reporting to automated, audit-ready compliance.
Major ICT-Related Incident Classification and Reporting
Regulated Entities are required to carefully consult Commission Delegated Regulation (EU) 2024/1772 on the criteria for classifying ICT-related incidents and cyber threats, which sets the applicable materiality thresholds and specifies the content and format of major-incident reports. Firms should also take into consideration the diagram in the Annex to that Regulation (as discussed in the Final Report accompanying the relevant Regulatory Technical Standards) to ensure correct classification and timely reporting of major ICT-related incidents upon detection. From a compliance-monitoring perspective, the priority is a consistent, documented methodology, with the classification rationale captured at the time of detection.
Register of Information — Submission Format and Deadline
CySEC has discontinued “Build in Excel” submissions. Regulated Entities must use XBRL-compatible software validated against the European Banking Authority (EBA) XBRL Standards. Submitting non-compliant files is a primary trigger for regulatory scrutiny. New entrants navigating these technical reporting standards can rely on our Financial Services Licensing desk for structural governance support.
ICT Risk Management Framework and Governance
C751 reiterates the Article 6 DORA requirements. Firms must establish, implement and maintain a well-documented framework enabling effective and continuous management of ICT risk. Under Article 6(4), entities other than microenterprises shall assign responsibility for managing and overseeing ICT risk to a control function with an appropriate level of independence, and ensure segregation between ICT risk management, control and internal audit functions in line with the three-lines-of-defence model (or an equivalent framework). Under Article 6(5), the framework shall be documented and reviewed at least once a year (periodically for microenterprises), and upon major incidents, supervisory instructions, or conclusions from resilience testing or audit; a review report shall be submitted to CySEC upon request, based on Chapter V of Commission Delegated Regulation (EU) 2024/1774. Under Article 6(6), the framework of non-microenterprises shall be subject to regular internal audit by auditors with sufficient knowledge, skills and expertise in ICT risk and an appropriate level of independence, with scope and frequency commensurate to the firm’s ICT risk profile. Under Article 6(7), firms shall establish a formal follow-up process for timely verification and remediation of critical ICT audit findings.
Practical Implementation: The Evidence Trail
Supervisory concern often arises from the evidence trail. Firms must document incident-classification rationale at the time of detection and ensure their Article 6 ICT risk management framework is independently governed.
Controls that exist on paper but cannot be evidenced are difficult to rely on during an inspection. Utilizing independent Internal Audit Services is the most effective way to stress-test your DORA readiness.
CySEC Portal Designations
Regulated Entities other than microenterprises are required to designate two roles in the CySEC Portal. First, the ICT auditor responsible for the internal audit of the ICT risk management framework (per Article 6(6)) is designated under the Auditors section, by completing the legal-entity or natural-person details and selecting the “Is ICT” option. Second, the person responsible for the control function entrusted with managing and overseeing ICT risk (per Article 6(4)) is designated under the Personnel section. These are concrete, checkable items: a firm either has made the designations or it has not.
Practical Implementation: What Firms Should Do
In practice, supervisory concern often arises less from misunderstanding a rule than from the evidence trail behind it. With C751, firms should be able to demonstrate not only that they understand the DORA requirements, but that they have operationalised them and can evidence each area.
The recurring practical considerations a firm should check are: whether incident-classification decisions are documented against the 2024/1772 criteria at the time of detection, rather than reconstructed later; whether the most recent Register submission was a valid XBRL-CSV file and the proof of submission retained; whether the annual ICT risk framework review was actually performed, minuted and, where relevant, the report made available to CySEC; whether the internal-audit follow-up process shows critical findings being remediated; and whether the CySEC Portal designations are current after any change of auditor or responsible person. Controls that exist on paper but cannot be evidenced are, for supervisory purposes, difficult to rely on.
Key Dates and Deadlines
| Date | What happens |
| 19 January 2026 | Circular C751 issued, providing guidance on in-force DORA reporting, governance and portal obligations. It introduces no new deadline. |
| 28 February (annually) | Standing deadline for submitting the Register of Information via the CySEC XBRL Portal, with reference date 31 December of the preceding year. Confirmed — not created — by C751. |
Step-by-Step Submission Process
The following covers the Register of Information submission via the CySEC XBRL Portal, the principal reporting action C751 addresses.
- Confirm the entity is in scope as a Regulated Entity and identify its reference date (31 December of the year preceding the reporting date).
- Obtain XBRL-compatible software that supports mapping and validation against EBA rules and generates fully compliant XBRL files.
- Generate the Register of Information in XBRL-CSV format — the only format accepted by the EBA.
- Validate the file against the EBA rules within the software and correct any errors before proceeding. [CONFIRM]
- Compress (zip) the XBRL file(s) as required for submission.
- Log in to the CySEC XBRL Portal. [CONFIRM]
- Upload the zipped XBRL-CSV file through the CySEC XBRL Portal. [CONFIRM] (portal upload click-steps not detailed in the circular)
- Confirm the submission was accepted and retain the proof of submission. [CONFIRM]
- Complete the submission no later than 28 February, well ahead of the deadline to allow for any format or validation issues.
Separately, entities other than microenterprises must complete the CySEC Portal designations: under the Auditors section, add the ICT auditor and select the “Is ICT” option; under the Personnel section, designate the ICT risk control-function owner.
Compliance Officer Checklist
- Document the firm’s ICT-incident classification methodology against Commission Delegated Regulation (EU) 2024/1772, including the Annex diagram, and retain the dated classification rationale for each incident.
- Review recent incidents for correct major / non-major classification and confirm timely reporting upon detection; record any reclassification and its basis.
- Confirm the Register of Information is generated in valid XBRL-CSV format using EBA-validated software, zipped and submitted via the CySEC XBRL Portal; retain the validation output and proof of submission.
- Diarise the annual Register deadline (28 February, reference date 31 December of the prior year) and test the file well ahead of the date.
- Confirm the ICT risk management framework is documented per Article 6 of DORA, with an independent control function and three-lines-of-defence segregation (non-microenterprises).
- Record the annual framework review (and any event-driven reviews), basing the review report on Chapter V of Commission Delegated Regulation (EU) 2024/1774, ready to provide to CySEC on request.
- Confirm regular internal audit of the ICT risk framework by suitably qualified, independent auditors, and evidence the formal follow-up and remediation of critical findings.
- If a Class 3 small and non-interconnected investment firm, confirm and document the simplified framework under Title III of Regulation (EU) 2024/1774.
- Designate the ICT auditor in the CySEC Portal under Auditors with the “Is ICT” option, and the ICT risk control-function owner under Personnel; verify both remain current.
Evidence to Retain
- The documented ICT-incident classification methodology and the dated classification rationale for each incident, mapped to the 2024/1772 criteria and Annex diagram.
- A valid XBRL-CSV Register file for the latest submission, plus the validation output and proof of submission.
- The documented ICT risk management framework and the record of its at-least-annual (and event-driven) review, including the review report based on Chapter V of Regulation (EU) 2024/1774.
- Evidence of independent internal audit of the framework and the formal follow-up showing critical findings remediated.
- For Class 3 firms, documentation of the simplified framework under Title III of Regulation (EU) 2024/1774.
- Confirmation that the CySEC Portal designations (ICT auditor under Auditors with “Is ICT”; ICT risk control-function owner under Personnel) are complete and current.
- A record of senior-management or board oversight of the above, and the owner, date and outcome of each review.
Why This Matters
C751 does not create a new obligation or a new deadline, but it makes plain where supervisory attention is falling. Because CySEC has expressly framed the circular around observed deficiencies — incidents wrongly classified in both directions — the message is that correct, documented classification and demonstrable compliance now matter as much as the underlying rule. An incident log without a documented classification rationale, a framework reviewed but not minuted, a Register filed in the wrong format, or a Portal entry never updated are exactly the gaps most likely to attract scrutiny. The confirmation that the Register must be filed in XBRL-CSV only, by the standing 28 February deadline, is an operational-readiness point: firms should confirm their tooling produces a valid file well before filing, rather than discovering a format issue at the point of submission.
Frequently Asked Questions
What is CySEC Circular C751?
C751, dated 19 January 2026 and issued further to Circular C700, provides guidance to Regulated Entities on certain obligations arising under DORA. It covers four areas: major ICT-related incident reporting, the Register of Information submission format, the ICT risk management framework, and CySEC Portal designations.
Does C751 introduce a new obligation or a new deadline?
No. C751 provides guidance and reminders on obligations already in force under DORA. It responds to deficiencies CySEC has observed and confirms format and governance expectations. The Register of Information deadline it confirms — 28 February annually, reference date 31 December of the prior year — is a standing requirement, not a new one.
Who does C751 apply to?
It is addressed to Regulated Entities: Cyprus Investment Firms, Central Securities Depositories, Trading Venues, Crypto-Asset Providers (CASPs), Alternative Investment Fund Managers and UCITS Management Companies.
What format must the Register of Information now be submitted in?
XBRL-CSV only. Following Circular C719, CySEC has discontinued the “Build in Excel” submission; XBRL-CSV is the only format accepted by the EBA. Files must be produced with XBRL-compatible, EBA-validated software, compressed (zipped) and submitted through the CySEC XBRL Portal, no later than 28 February each year.
How should we classify a major ICT-related incident?
By reference to Commission Delegated Regulation (EU) 2024/1772, which sets the classification criteria, materiality thresholds and the content and format of major-incident reports. CySEC also points firms to the classification diagram in the Annex to that Regulation to support correct and timely classification on detection.
What do we need to designate in the CySEC Portal?
Regulated Entities other than microenterprises must designate the ICT auditor responsible for the internal audit of the ICT risk management framework under the Auditors section (selecting “Is ICT”), and the person responsible for the ICT risk control function under the Personnel section, in line with Articles 6(6) and 6(4) of DORA respectively.
How CX Financia Can Support You
For Regulated Entities, the priority is to demonstrate a structured, audit-ready review of DORA reporting requirements. CX Financia supports firms through [Regulatory Compliance Services] and Internal Audit advisory—including DORA gap assessments, ICT risk framework design, and the independent audits required under Article 6.
Ensure Your DORA Framework Withstands Scrutiny
Don’t wait for a CySEC inspection to discover gaps in your evidence trail. Schedule a targeted gap assessment to ensure your reporting is XBRL-compliant and your governance meets Article 6 standards.
Book a Consultation with Our Compliance Team
Disclaimer
General information, not regulatory advice. Firms should refer to the text of Circular C751 and seek tailored advice on their specific circumstances.
