Welcome to our EU site – choose your Jurisdiction

INVESTMENT SERVICES & CAPITAL MARKETS

MIFID and MIFIR

ESMA publishes supervisory briefing on triangular passporting

On 7 July 2026, ESMA published a new supervisory briefing on triangular passporting under MIFID II, which aims to clarify the appropriate use of the practice, enhance certainty and improve supervisory consistency.

It forms part of the EU’s wider simplification drive, seeking to reduce the burden of regulation by setting clear expectations for firms. Triangular passporting occurs where an investment firm authorised in one Member State (Member State A) uses a branch or tied agent in another Member State (Member State B) to provide investment services cross-border into a third Member State (Member State C), under the Article 34 freedom to provide services under MIFID II.

The practice is not covered or prohibited under MIFID II, but ESMA recognises that this model can create: (i) compliance complexity for firms (which may need to comply with conduct of business rules in multiple Member States); (ii) investor protection risks (such as determining where complaints should be directed); and (iii) uncertainty over supervisory responsibilities.

ESMA’s briefing does not create new legal obligations, is non-binding, and is not subject to a “comply or explain” mechanism, nor does it prescribe a single supervisory approach. However, investment firms using, or considering, triangular passporting may expect greater scrutiny of their approach to the practice, including by national supervisors. Notably, the European Banking Authority has not co-authored the supervisory briefing, so at this stage there is no new guidance on triangular passporting for firms within scope of the Capital Requirements Directive (CRD) or existing Payment Services Directive (PSD2). Currently, CRD and PSD2 make no explicit provision for triangular passporting, but support for it can be found in various supervisory publications, while Recital 56 of the European Commission’s proposal for the Payment Services Directive 3 explicitly acknowledges the possibility of triangular passporting.

Under the briefing, ESMA expects firms relying on triangular passporting to notify their home supervisor (in Member State A) and specify which authorised services and activities they intend to provide, using the relevant MiFID II templates related to Article 34. They should regularly review and, where necessary, carry out internal risk assessments of, the model. Firms relying on tied agents are expected to explicitly authorise the tied agent to provide cross-border services on behalf of the firm (given the tied agent’s separate legal personality).  Firms should not use the structure to engage in “forum shopping” – for example, establishing a branch or tied agent in Member State B in order to passport services into Member State C may be considered to circumvent the MIFID II Article 35 branch establishment requirements. ESMA also expects firms to give clients clear information on who is providing the service, which authority supervises it, how complaints can be made, and which redress and compensation arrangements may be available. Clients will be entitled to submit complaints to either the head office or the branch/tied agent that is supplying the service.

On the supervisory side, ESMA expects the home Member State supervisor (in Member State A) to notify the supervisors in Member States B and C of the firm’s intention to rely on triangular passporting. ESMA provides some guidance on the responsibilities of the supervisors in Member States A-C but notes that a degree of supervisory cooperation will be required and refers to existing Level 2 measures under MIFID II (Commission Delegated Regulation (EU) 2017/586 and Commission Delegated Regulation (EU) 2017/980) which require supervisors to exchange information and cooperate in any cross-border supervisory activities


New ESMA MIFIR Q&As

On 10 July 2026, ESMA published the following question and answer relating to the Markets in Financial Instruments Regulation (MIFIR) Regulation – Secondary Markets

 

European Commission adopts MIFIR RTS amendments on derivatives, package orders and consolidated tape

On 13 July 2026, the European Commission adopted a Delegated Regulation amending regulatory technical standards (RTS) under MIFIR to implement amendments arising from the MIFIR Review (Regulation (EU) 2024/791) and support the establishment of the over-the-counter (OTC) derivatives consolidated tape.

The Delegated Regulation amends the RTS in:

The Delegated Regulation also corrects an unintended amendment in Delegated Regulation (EU) 2017/587 by reinstating the requirement for investment firms to take reasonable steps to ensure certain transactions are made public as a single transaction, and by removing a provision that had been inadvertently retained.

The Regulation will enter into force on the 20th day following its publication in the Official Journal of the European Union, with the majority of the amendments applying from 1 March 2027.


ESMA follow-up report to its peer review on supervision of cross-border activities of investment firms under MIFID II

On 20 July 2026, ESMA published a follow-up report to its 2022 peer review on the supervision of cross-border activities of investment firms.

The report assesses the progress made by national competent authorities (NCAs) in implementing recommendations issued in 2022 and covers the Netherlands, Germany, the Czech Republic, Luxembourg, Cyprus and Malta.

The follow-up shows that the peer review has successfully driven improvements across the supervisory cycle and helped strengthen the supervision of cross-border investment services within the EU Single Market.

The report highlights notable progress in three key areas:

  • Stronger authorisation controls– NCAs have enhanced assessments of firms’ cross-border plans. 
  • Data-driven and risk-based supervision– NCAs are increasingly using data to monitor cross-border activities, tailoring supervisory action based on identified risks. 
  • Enhanced cooperation and enforcement– NCAs have undertaken more targeted supervisory actions, reported enforcement cases where relevant and strengthened cooperation.

The report also encourages NCAs with significant outbound cross-border activities to ensure that their supervisory and enforcement approaches match the scale and complexity of these activities and keeps pace with evolving risks. 

Effective supervision of cross-border activities remains essential to ensuring that investors receive consistent levels of protection regardless of where investment services are provided.

ESMA encourages all NCAs, and in particular those where outgoing cross-border activities is significantly growing, to reflect on the report’s conclusions. 

As retail cross-border investment services continue to expand, ESMA will maintain its focus on fostering supervisory convergence, enhancing cooperation among national supervisors and supporting data-driven, risk-based supervision. These efforts aim to ensure stronger investor protection and contribute to the effective functioning of the EU Single Market.


EU Delegated Regulation on order execution policies under MIFID II published in Official Journal

On 23 July 2026, Commission Delegated Regulation (EU) 2026/825 supplementing MIFID II was published in the Official Journal of the European Union.

The Delegated Regulation sets out regulatory technical standards (RTS) specifying the criteria to be taken into account by investment firms when establishing and assessing the effectiveness of their order execution policies. The Delegated Regulation is based on the final draft RTS published by the European Securities and Markets Authority in April 2025. The European Commission subsequently adopted the Delegated Regulation in April of this year.

The Delegated Regulation will repeal Delegated Regulation (EU) 2017/575, which sets out data to be published by execution venues on the quality of execution of transactions on their venues, and Delegated Regulation (EU) 2017/576, which sets out obligations for investment firms to publish information on the identity of execution venues and the quality of execution obtained.

The Delegated Regulation enters into force on 12 August 2026, 20 days after its publication in the Official Journal, and will apply from 12 February 2028.


ESMA authorises EuroCTP as the Consolidated Tape Provider for shares and exchange-traded funds

On 27 July 2026, ESMA authorised EuroCTP B.V. (EuroCTP) to operate as the Consolidated Tape Provider (CTP) for shares and exchange-traded funds (ETFs).

Retail investors, academics, civil society organisations and regulators will be able to benefit from the data free of charge. Other users will have access to the data for a reasonable fee and will be able to use it for internal purposes and with clients.

ESMA has granted EuroCTP a transition period until 30 September 2026, to allow for the finalisation of operational and technical arrangements required for the start of the service.

After the transition period, EuroCTP will be responsible for operating the consolidated tape for shares and ETFs for a period of five years under ESMA’s direct supervision, in line with the MIFIR framework. The five-year period will begin on the date EuroCTP starts its operations.

ESMA encourages data contributors and other market participants to maintain a high level of engagement with EuroCTP to ensure a smooth and timely launch of the consolidated tape activities.

Market Abuse Regulation

Delegated Regulations on disclosures and trading under MAR published in Official Journal

On 16 July 2026, the European Commission published two Delegated Regulations under the Market Abuse Regulation (MAR), in the Official Journal of the European Union, to reflect amendments introduced by the Listing Act (Regulation (EU) 2024/2809):

  • Delegated Reulation (EU) 2026/788 amending Delegated Regulation (EU) 2016/522 to: (i) reflect the broader scope of the exemptions from the prohibition for persons discharging managerial responsibilities to trade during closed periods set out in Article 19(12) of the MAR; (ii) establish a list of designated trading venues that have significant cross-border dimensions for the purpose of implementing the mechanism to exchange order data referred to in Article 25a of the MAR with respect to shares; and (iii) update Annex II on the practices specifying the indicators of market manipulation, to account for technical developments such as algorithmic trading, and to correct a few erroneous cross-references.

The Amending Regulation will enter into force on 5 August 2026, being the 20th day following publication in the Official Journal.

  • Delegated Regulation (EU) 2026/789 setting out the requirements on the disclosure of inside information in protracted processes, including the conditions and arrangements for the delay of disclosure. Under Article 17(1) of MAR, issuers must disclose inside information as soon as possible, although Article 17(4) permits delayed disclosure in certain circumstances. The Listing Act amended this regime by excluding intermediate steps in protracted processes from disclosure, provided confidentiality is maintained, and by clarifying when disclosure may be delayed. The Delegated Regulation sets out non exhaustive lists of: (i) final events or circumstances that trigger disclosure along with the timing of such disclosure; and (ii) situations where there is a contrast between inside information whose disclosure is intended to be delayed, and the most recent public announcement or communication by the issuer or emission allowance market participant on the same subject.

The Regulation entered into force on 19 July 2026, being the third day following publication in the Official Journal.

Central Securities Depositories Regulation (CSDR) and settlement discipline

European Commission adopts Delegated Regulations on amending RTS under CSDR

On 6 July 2026, the European Commission adopted two Delegated Regulations under the Central Securities Depositories Regulation No 909/2014 (CSDR):

  • The first Delegated Regulation amends the regulatory technical standards (RTS) laid down in Commission Delegated Regulation (EU) 2018/1229 on settlement discipline, to introduce measures aimed at improving settlement efficiency in the EU and supporting the transition from a T+2 to a T+1 settlement cycle on 11 October 2027.

The revised RTS strengthen allocation, confirmation and settlement processes, establish earlier deadlines for the provision of settlement information by professional and retail clients, and enhance the monitoring, reporting and analysis of settlement fails. The Delegated Regulation is based on the final report published by ESMA in October 2025.

The RTS on settlement discipline will generally apply from 7 December 2026, except for certain specified provisions which will apply in 2027.

The amendments align the RTS with the reforms introduced by the CSDR Refit Regulation (EU) 2023/2845. The Delegated Regulation specifies: (i) the information the CSD is to provide to the competent authority for the purposes of the review and evaluation; (ii) the information that the CSD’s competent authority is to supply to other authorities when sharing the results of the review and evaluation; and (iii) the information that the competent authorities responsible for supervising different CSDs within the same group are to supply to one another when performing the review and evaluation. The Delegated Regulation is based on the final report published by ESMA in February 2025.

The RTS on the review and evaluation process will apply one year after it enters into force.

ESMA Statement on T+1 settlement preparations

On 20 July 2026, ESMA published a statement highlighting key deadlines and action points for firms to take when preparing for the transition to a T+1 settlement cycle, which takes effect on 11 October 2027.

ESMA states that while readiness surveys conducted by the EU T+1 Industry Committee show an overall good and increasing level of awareness and commitment to the transition, implementation levels remain uneven across EU financial markets, sectors and firms.

While the rules have been known since mid-October 2025, ESMA proposed amendments to Commission Delegated Regulation (EU) 2018/1229 to set new requirements, which are particularly relevant for the transition to T+1. ESMA states that firms should consider these in combination with the recommendations of the EU T+1 Industry Committee and accelerate the technical work needed to prepare for the transition to T+1 settlement.

The statement also highlights the following key compliance deadlines:

  • First deadline: 7 December 2026 —for the requirements to improve the first post-trade step, the exchange of allocations and confirmations, in terms of timing and through the default use of international communication standards
  • Final deadline: 11 October 2027—for the requirements to optimise the settlement layer, including sending instructions early enough to securities settlement systems, and the generalisation of certain functionalities in central securities depositories (CSDs), such as auto-partial settlement, hold and release, and auto-collateralisation.

ESMA and the national competent authorities are in the last stages of reviewing the Level 3 guidelines on allocations and confirmations. ESMA considers that the guidelines and the Committee’s recommendations will give firms a clear basis for finalising their implementation of electronic, standardised and timely allocation and confirmation processes.

ESMA states that different implementation strategies are possible and firms should undertake thorough analysis and planning, prioritise automation and standardisation, consider new partnerships where relevant, and ensure timely data quality (including correct reference data and standard settlement instructions).

ESMA also reiterates that no-one can be ready in isolation. Firms should assess the readiness of their entire ecosystem, up and down the trading and settlement chain—clients, brokers, custodians, CSD participants, CSDs, central counterparties, trading venues, vendors and outsourcing providers—to enable early testing, identify defects and reduce disruption risk at go-live on 11 October 2027.

The regulator warns that insufficient preparedness could trigger significant operational and reputational risks, including flawed interdependencies with financial market infrastructures and IT providers, inability to meet client demands, and higher IT and training costs from last-minute remediation.

EMIR

ESMA final draft RTS on CCP admission criteria elements

On 8 July 2026, ESMA published its Final Report on the Regulatory Technical Standards (RTS) concerning the central counterparties’ (CCPs) admission criteria elements, following the review of the European Market Infrastructure Regulation (EMIR 3).

EMIR 3 introduces amendments to the provisions on participation requirements in CCPs, including for non-financial counterparties (NFCs). 

The RTS specify the elements which CCPs should consider when establishing their admission criteria for clearing members. This includes considerations related to NFC clearing members and sponsored membership models. The RTS do not set the actual admission criteria but instead define the elements for CCPs to consider.

ESMA conducted a public consultation on the draft RTS in the last quarter of 2025 and held a public hearing in November 2025. The Final Report considers the feedback received during this process.  

The RTS will now be submitted to the European Commission for endorsement, following which they will be subject to scrutiny by the European Parliament and the Council.

EBA, EIOPA and ESMA propose amendments to bilateral margin requirements

On 3 August 2026, the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) published a final report on draft Regulatory Technical Standards (RTS), proposing to simplify the bilateral margin requirements of the European Commission’s Delegated Regulation (EU) 2016/2251.

The proposed amendments aim to simplify the bilateral margin framework for counterparties that are subject to initial margin requirements and that are below the €8 billion threshold for exchanging initial margin foreseen by EMIR. The changes are intended to facilitate the phase-out of initial margin requirements for these counterparties. They also support greater consistency with the treatment applied in other jurisdictions. 

In the current framework, counterparties that are below the threshold are exempt from exchanging initial margin for new uncleared over-the counter (OTC) derivative contracts but continue to exchange initial margin for existing contracts. With the proposed amendments, counterparties would no longer be required to exchange initial margin for either new or existing contracts if they are below the threshold.

The amendments respond to requests from market participants and support the ESAs’ broader objectives of simplification and burden reduction.

The Final Report has been submitted to the European Commission together with the draft RTS for endorsement. Following the Commission’s review and adoption process, the RTS will be subject to scrutiny by the European Parliament and the Council before being published in the Official Journal of the European Union.

Market Data

ESMA launches data collection under the first phase of European Single Access Point (ESAP)

On 10 July 2026, ESMA launched the collection of information from Officially Appointed Mechanisms (OAMs) and National Competent Authorities (NCAs) – “collection bodies” – for the first phase of implementation of the European Single Access Point (ESAP).

From 10 July 2026, OAMs and NCAs started providing to ESAP the information and the metadata collected from entities. This marks the first milestone towards the go-live of the ESAP platform, which will become accessible to the public by July 2027 as required by the ESAP Regulation. 

ESAP will provide free, easy and centralised access to financial and sustainability information about entities and their products. 

Over the next 12 months, ESAP will gather a meaningful set of EU-wide information ahead of the platform’s public opening. 

Information in scope of the first phase of ESAP relates to the Transparency Directive, the Prospectus Regulation and the Short-selling Regulation. Further information will come in scope of the platform in the coming years as established by the applicable legislation.

OPERATIONAL RESILIENCE AND ICT RISK

EBA, EIOPA and ESMA support ESRB warning on systemic cyber risks from frontier AI models

On 7 July 2026, the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) welcome and support the warning from the European Systemic Risk Board (ESRB) (also published on 7 July 2026) on the systemic cyber risks posed by frontier AI models.

Recent advances have significantly enhanced the ability of frontier AI models to identify and exploit high-severity vulnerabilities in IT systems within very short timeframes. While the EU’s regulatory framework – including DORA and the AI Act – provides a solid foundation for managing cyber and AI-related risks, the speed and scale of these tools raise concerns that AI-enabled cyber-attacks could undermine the operational resilience of financial entities.

Since the release of the first frontier AI models, the ESAs have raised awareness about the ICT risks posed by the widespread adoption of these models and engaged with EU competent authorities to ensure that financial entities take appropriate mitigation measures. In their first annual report on major ICT-related incidents under DORA, the ESAs encouraged financial entities to strengthen cybersecurity measures to maintain their resilience amid the rapid evolution of highly capable AI-driven tools.

Against this backdrop, the ESAs concur with the ESRB warning and urge financial entities to make appropriate arrangements to adapt their cybersecurity capabilities. They also invite competent authorities to reflect these developments in their supervisory activities. Finally, the ESAs note the ESRB’s call on the European Union to scale up its capacity, expertise and strategic autonomy in this critical area, which requires that all parties are involved, including AI providers, software providers, security firms, open-source maintainers, financial institutions, and authorities at both national and Union level.

The ESAs are working closely with the EU supervisory community to ensure that financial entities across the EU proactively identify and mitigate these risks in line with the requirements of the Digital Operational Resilience Act (DORA), which establishes a harmonised framework for mitigating ICT risks in the financial sector.

In their capacity as Overseers of Critical ICT Third-Party Providers, the ESAs are also engaging with these providers on the measures they are taking to adapt to the situation, in order to manage risks and ensure the continuity of services provided to the EU financial sector.

The warning by the ESRB highlights how frontier AI models are transforming the cybersecurity landscape by enabling threat actors to increase the speed, scale, and sophistication of cyber-attacks in the short to medium term. The ESRB urged all EU stakeholders, including financial institutions, to enhance their cybersecurity capacities and encouraged relevant authorities to reflect these risks in their supervisory and oversight work.

The ESAs will continue to closely monitor the use and development of highly cyber-capable frontier AI models and assess their potential impact on the financial sector. To promote a consistent, risk-based and forward-looking supervisory approach in this area, the ESAs are also working with national supervisors to clarify supervisory expectations and will communicate them consistently to financial entities to ensure compliance with the existing regulatory framework.

EBA, EIOPA and ESMA call for enhanced governance and consistent supervision to mitigate ICT risks from frontier AI models in the EU financial sector

On 31 July 2026, the European Supervisory Authorities (EBA, EIOPA and ESMA – the ESAs) published a statement calling for a cross-sectoral, risk-based and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.

The statement takes into account existing regulatory requirements, the European Commission’s Action Plan on Cybersecurity and Artificial Intelligence, as well as recent publications by the European Systemic Risk Board (ESRB), the European Union Agency for Cybersecurity (ENISA), the Single Supervisory Mechanism (SSM) and other competent authorities.

The ESAs outline measures to help financial entities strengthen their operational resilience against cyber risks linked to frontier AI models. Particular emphasis is placed on the prevention, detection and management of these risks.

The statement underlines that financial entities should have robust governance and risk management frameworks in place to support the effective management and mitigation of cyber risks associated with frontier AI models. It also updates on ongoing and planned DORA oversight activities for critical ICT third-party providers (CTPPs) to address this risk.

The ESAs encourage both financial entities and competent authorities to use the statement as a basis for supervisory dialogue, taking into account existing supervisory expectations. Such an approach would help ensuring that the EU financial system remains resilient against the risks driven by frontier AI technologies.

CRYPTO-ASSETS

Crypto-Assets Service Providers (CASPs)

ESMA launches Common Supervisory Action (CSA)  on crypto-asset service providers’ digital operational resilience for custody 

On 8 July 2026, ESMA announced the launch of a common supervisory action (CSA) on the digital operational resilience of crypto-asset service providers (CASPs), with a particular focus on custody services.

The CSA will assess the maturity of CASPs’ operational resilience frameworks in relation to custody activities, focusing on risks inherent to distributed ledger technology (DLT). These include governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and reliance on third-party providers.

National competent authorities will conduct the review on a risk-based sample of authorised CASPs between the second half of this year and the first half of 2027. ESMA will consolidate the findings into a final report for its board of supervisors following completion of the exercise in the second half of 2027.

Markets in Crypto-Assets Regulation (MICA)

FINANCIAL CRIME

Anti-money Laundering

AMLA final draft RTS on pecuniary sanctions, administrative measures and periodic penalty payments

On 8 July 2026, the EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) published its final report with draft regulatory technical standards (RTS) under Article 53(10) of the sixth Anti-Money Laundering Directive (EU) 2024/1640 (AMLD 6).

The RTS establish a framework for assessing the gravity of breaches, determining the level of pecuniary sanctions and administrative measures, and imposing periodic penalty payments (PePPs). They set out indicators for assessing breaches, classify breaches into four levels of severity, and establish criteria for determining sanctions and other measures. They also include provisions relating to natural persons, including senior management and supervisory board members, and procedural aspects for the imposition of PePPs.

Following the February consultation, AMLA made targeted amendments, including clarifications on the application of the framework to non-financial sector firms, confirmation that category 3 and 4 breaches constitute “serious, repeated or systematic” breaches for the purposes of AMLD 6, and revisions allowing supervisors to rely on any reliable and relevant information when assessing breaches.

The draft RTS will now be submitted to the European Commission for adoption before publication in the Official Journal of the EU.

EU AMLA final draft ITS on cooperation within the AML/CFT supervisory system for the purposes of direct supervision

On 21 July 2026, the EU Anti-Money Laundering Authority (AMLA) published a final report containing final draft implementing technical standards (ITS) that set out AMLA’s cooperation with national financial supervisors to select and directly supervise some of the most significant cross-border financial institutions in the EU.

The final draft ITS cover how entities are selected, how supervision passes between national and EU level, and how AMLA and national supervisors will work side by side.  From 2028, AMLA will directly supervise some of the most impactful, cross-border financial institutions at group level. Until now, this supervision has rested with national supervisors. The new ITS will ensure consistent and uninterrupted supervision as responsibility moves between national and EU level.

The final draft ITS set out a clear, step-by-step process for identifying which firms AMLA will supervise: national supervisors gather and quality-check the data, and AMLA carries out the risk assessment and makes the selection, with the results published on its website. When an entity moves to or from AMLA’s supervision, the transferring authority hands over the firm’s full supervisory history to the receiving authority, preventing disruptions.

The final draft ITS were developed in close cooperation with national supervisors. They are designed for proportionality: entities are asked for detailed data only once they have been identified as eligible. Where supervisors can already establish that a firm does not qualify, it is exempted from reporting altogether. Once adopted by the European Commission, the ITS will apply to the data collection and selection process leading up to the start of direct supervision in 2028.

SUSTAINABLE FINANCE

ESG Ratings Regulation

New ESMA ESG Ratings Q&As

On 10 July 2026, ESMA published the following question and answer relating to the EU ESG Ratings Regulation (ESGRR):


Delegated Regulations on transparency and integrity of ESG rating activities published in Official Journal

On 28 July 2026, two Delegated Regulations supplementing the Environmental, Social and Governance (ESG) Ratings Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities were published in the Official Journal of the European Union:  

  • Commission Delegated Regulation (EU) 2026/871 which sets out the regulatory technical standards (RTS) specifying the elements of ESG rating products to be disclosed to the public and to users of ESG ratings, rated items and issuers of rated items.
  • Commission Delegated Regulation (EU) 2026/872 which sets out the RTS specifying the measures and safeguards to be implemented by ESG rating providers to separate their ESG rating activities from their other activities.

Both Regulations are based on the final draft RTS published by ESMA in October 2025. They were subsequently adopted by the European Commission in April.

The Regulations will enter into force on 17 August 2026, being the 20th day following publication in the Official Journal.  However, they have applied from 2 July 2026 to align with the date of application of the ESG Ratings Regulation.


Delegated Regulations on fees and fines for ESG rating providers published in Official Journal

On 30 July 2026, two Delegated Regulations supplementing the Environmental, Social and Governance (ESG) Ratings Regulation (EU) 2024/3005 on the transparency and integrity of ESG rating activities were published in the Official Journal of the European Union:

Both Regulations were adopted by the European Commission in April and will enter into force on 19 August 2026, being the 20th day following their publication in the Official Journal.

CYSEC DEVELOPMENTS

Circular C790: ML/TF risks following the end of MiCA Transitional Period

On 7 July 2026, CySEC issued Circular C790 (the ‘Circular’), to inform the Regulated Entities that the MiCA transitional period has ended on 1 July 2026. Following this date, firms are required to obtain authorisation as Markets in Crypto-Assets Regulation (‘MiCAR’) -compliant crypto-asset service providers (‘CASPs’) in order to continue providing crypto-asset services within the European Union.

The EU’s Authority for Anti-Money Laundering and Countering the Financing of Terrorism (‘AMLA’) has published an Advisory Note, which highlights the money laundering and terrorist financing (‘ML/TF’) risks that may arise following the conclusion of the MiCA transitional period and outlines mitigating measures that may be adopted by unauthorised virtual asset service providers (‘VASPs’) and authorised CASPs to support the application of a risk-based approach and contribute to safeguarding the integrity of the EU financial system.

For further information on the ML/TF risks and suggested mitigation measures, please refer to the Circular.

CySEC further reminds Regulated Entities that compliance with applicable AML/CFT obligations remains their responsibility throughout the transition period and after the completion of any customer migration or wind-down activities.

In addition, CySEC draws the attention of Regulated Entities to the FATF Report Understanding and Mitigating the Risks of Off-shore VASPs, which highlights the ML/TF risks arising from relationships, transactions or business activities involving unauthorised or offshore VASPs. In this regard, Regulated Entities should identify and assess such risks and apply appropriate risk mitigations measures in accordance with a risk-based approach.

Finally, CySEC urges the Regulated Entities to consider the specific ML/TF risks that may arise following the end of the MiCA Transitional Period and enhance their risk-based approach under the Prevention and Suppression of Money Laundering Activities Law (L. 188(I) 2007), as amended.


Circular C791: AMLA’s public consultations regarding the draft ITS under article 69(3) of Regulation (EU) 2024/1624 and the draft RTS under article 40(2) of Directive (EU) 2024/1640

On 15 July 2026, CySEC issued Circular C791 (the ‘Circular’), to inform the Regulated Entities that the Anti-Money Laundering Authority (the ‘AMLA’) has launched public consultations on the following:

Article 69(3) of Regulation (EU) 2026/1624 (AMLR) – on the format for reporting suspicions and providing transaction records

  • The draft ITS document, Interpretative Note, Annexes and the link to respond to the consultation paper are available on the relevant website of AMLA.
  • The deadline for the submission of comments is 20 September 2026.
  • A Public Hearing on the draft ITS is planned for 9 September 2026, 10:00 – 12:00 CEST

Article 40(2) of Directive (EU) 2024/1640 (AMLD 6) – on the assessment of the inherent and residual risk profile of obliged entities in the non-financial sector

  • The draft RTS document, Annexes I and II and the link to respond to the consultation paper are available on the relevant website of AMLA.
  • The deadline for the submission of comments is 27 September 2026.
  • A Public Hearing on the draft ITS is planned for 10 September 2026.

– A Press Release, a Factsheet and a List of Surveys are also available here.

CySEC notes that the two consultations are open to all stakeholders. As regards the draft RTS of article 40(2) of AMLD 6 on the risk assessment of non-financial sector obliged entities (i.e. ASPs and Crowdfunding Service Providers), according to the relevant AMLA’s press release, input from the businesses and professionals affected is essential to inform AMLA’s approach.

CySEC urges the Regulated Entities to respond to the substantive consultation papers.

Circular C792: Active Account Requirement and Representativeness Obligation under Articles 7a and 7b of Regulation (EU) No 648/2012 (‘EMIR’)

On 17 July 2026, the Cyprus Securities and Exchange Commission (“CySEC”) issued Circular C792 (the ‘Circular’), drawing the attention of Financial and Non-Financial Entities to the active account requirement (‘AAR’), the related representativeness obligation, the associated notification and reporting requirements applicable under Articles 7a and 7b of EMIR.

Background: Financial and Non-Financial Counterparties above the clearing thresholds should have arrangements to clear OTC derivatives that are declared subject to clearing (Section 1 of the link) with a CCP. With the advent Regulation EU 2024/2987 amending EMIR (colloquially called EMIR 3) an additional obligation came into effect.

Financial and non-financial counterparties above the clearing thresholds which trade with the following subset of OTC derivatives declared subject to clearing:

  1. Interest rate derivatives denominated in Euro or Polish zloty (e.g. Interest Rates Swaps on EURIBOR 12 month with a 2-year maturity); and/or
  2. short-term interest rate derivatives denominated in euro (e.g. Overnight Index Swap on €STR with a 10-day maturity)

Are required to establish an Active Account with an EU authorised CCP (i.e. a CCP established in the EU and authorised in the EU not a third country CCP recognised by ESMA to offer clearing services in the EU). The said parties are required to clear from that Active Account a representative volume/number of transactions that concern the instrument categories referenced in points a) and b) above.

No action is required where Financial and non-Financial counterparties are either below the clearing thresholds and/or do not trade with the instruments mentioned in points a) or b). In all other cases affected Financial and non-Financial counterparties must take the appropriate actions to ensure compliance with EMIR 3 and follow the instructions of Circular C792, outlined below.

Where Financial and Non-Financial Counterparties fall within the scope of the AAR, they should ensure compliance with, inter alia, the following requirements:

  • Notification and Reporting Requirements
    • Complete the notification template and send it to CySEC and ESMA through the email addresses emir@cysec.gov.cy and AAR-notifications@esma.europa.eu.
    • Submit their first report on the AAR to CySEC by 31 July 2026. The first submission should include any backload data demonstrating compliance with the AAR for the period starting 25 June 2025 along with data for 2026. Thereafter, reporting will take place on a six-month basis, with submissions due on 31 January and 31 July each year, each covering a twelve-month reference period.

The above information should be provided to CySEC using the ESMA reporting templates and following the instructions through the email address emir@cysec.gov.cy.

  • Implementation Requirements:
    • Establish and maintain an active account with an authorised EU CCP;
    • Have in place appropriate legal, operational and IT arrangements to satisfy the operational requirements under EMIR and Regulation (EU) 2026/305;
    • Establish adequate processes to monitor compliance with the representativeness obligation on an ongoing basis;
    • Have arrangements with CCPs, clearing members and relevant service providers support the operational use of the active account at all times;  
    • Maintain sufficient records and controls to demonstrate compliance with the AAR; and
    • Establish appropriate procedures and controls to monitor ongoing compliance with the operational, representativeness, notification and reporting requirements under Articles 7a and 7b of EMIR and Regulation (EU) 2026/305.

Why Choose Complyport?

Red line drawing of a hand with three stars above, symbolizing rewards or achievement.

Extensive Regulatory Expertise

With over 25 years of experience in the financial services industry, Complyport offers unparalleled expertise in regulatory compliance, ensuring your firm stays ahead of evolving regulations.

Icon: gear with circular arrows around it and a checkmark, symbolizing a completed automated process or successful system update

Comprehensive Service Offering

From AML audits to risk management and regulatory reporting, Complyport provides a full spectrum of compliance services, allowing you to streamline your compliance processes and focus on your core business activities.

Red outline light bulb icon with rays, signaling a bright idea or insight.

Tailored Compliance Solutions

We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Three red outlined people with three arrows pointing toward the central figure, emphasizing the focal person in a team.

Client-Centric Approach

We prioritise open and transparent communication, building strong relationships with our clients based on trust and mutual respect. Our commitment to excellence ensures that we deliver high-quality services with courtesy, patience, and flexibility.

Red outline of a person standing beside a multi-arrow signpost, indicating directions (icon-style illustration).

Senior-Level Guidance

Our team of seasoned professionals, including former regulators and industry experts, leads all engagements, offering deep insights and practical advice to help you manage compliance risks effectively.

Red line illustration of a brain fused with a lightbulb and gear, symbolizing ideas and thinking for innovation and problem solving.

Innovative Fintech, Regtech and AI Solutions

Leveraging cutting-edge fintech, regtech and AI tools, Complyport enhances your compliance processes with advanced technology, ensuring accuracy, efficiency and real-time regulatory updates. Our innovative solutions empower your firm to stay compliant while maximising operational efficiency.

Key Figures

Over 25 Years

Providing Compliance Excellence

Over 1,500

Successful FCA, EU and UAE Authorisations

Over 1,000

Active Firms Receiving
Regulatory Support

8 Lots

FCA/PRA Skilled Person
& Consultancy Panel

Speak to an Expert