INVESTMENT SERVICES & CAPITAL MARKETS
MIFID and MIFIR
Delegated Regulation on volume cap and transparency calculations published in Official Journal
On 1 June 2026, Commission Delegated Regulation (EU) 2026/392 amending the regulatory technical standards (RTS) in Delegated Regulation (EU) 2017/577, was published in the Official Journal of the European Union.
The Delegated Regulation is based on the European Securities and Markets Authority May 2025 final report and reflects amendments to the MIFIR framework, including those introduced by Regulation (EU) 2024/791. These include extending record-keeping obligations to five years for operators of trading venues, approved publication arrangements and consolidated tape providers, and replacing the double volume cap with a single volume cap, together with related changes to publication requirements. It also removes provisions relating to the previous volume cap reporting framework, including associated reporting requirements and formats.
The Regulation further reflects amendments introduced by Directive (EU) 2024/790 to the definition of ‘systematic internaliser’.
It also updates provisions on data reporting formats, clarifying that XML should be used for periodic reporting, while allowing ESMA and competent authorities to specify formats for ad hoc requests. To minimise burden, it encourages the use of existing datasets, including transaction data reported under Article 26 of MIFIR.
The Delegated Regulation will enter into force on 21 June 2026, being the 20th day following its publication in the Official Journal.
Commission Delegated Directive on third-party execution and research services under MIFID II published in Official Journal
On 2 June 2026, Commission Delegated Directive (EU) 2026/374 amending Delegated Directive (EU) 2017/593 under MIFID was published in the Official Journal of the European Union.
The Directive updates the rules on the provision of third-party execution and research services to investment firms that provide portfolio management or other investment or ancillary services. The amendments reflect changes introduced by Directive (EU) 2024/2811, allowing investment firms greater flexibility to pay for research and execution services either jointly or separately.
The Delegated Directive introduces enhanced requirements where firms operate research payment accounts, including obligations on budgeting, controls, and audit trails, and reinforces that research charges must be based on a pre-set budget and not linked to transaction volumes. It also imposes a strengthened obligation on firms to assess the quality, value and usability of third-party research on at least an annual basis against robust criteria, and to take remedial action where deficiencies are identified.
The Directive will enter into force on 22 June 2026, being the 20th day following publication in the Official Journal. Member states must transpose the Directive by 5 June 2026, with application from 6 June 2026.
European Parliament reaches provisional agreement on simplified rules for small “mid-cap” companies under Omnibus IV
On 9 June 2026, the European Parliament announced that it has reached a provisional agreement with the Council of the EU on a package of measures to simplify regulatory requirements for a new category of undertakings named small “mid-cap” companies (SMCs) that falls between SMEs and large enterprises
The undertakings are defined in the press release as companies with fewer than 1,000 employees and either up to EUR200 million in turnover or EUR172m in total assets, and the measures form part of the European Commission’s Omnibus IV legislative proposal, adopted in May 2025. The agreement is intended to support scaling businesses and avoid “cliff-edge” increases in regulatory obligations when firms outgrow SME status, by extending to SMCs a range of exemptions and lighter requirements currently available to SMEs.
The simplified regime will apply across several EU frameworks, including the General Data Protection Regulation, where lighter record-keeping obligations will apply for low-risk processing data and capital markets rules including MIFID and the Prospectus Regulation, enabling easier access to SME growth markets and simplified disclosure requirements. Additional simplifications are introduced in other areas.
The measures remain subject to formal adoption by both institutions before publication in the Official Journal of the European Union and entry into force. Member states will have 15 months to introduce the Directive into their national legislation.
ESMA statement on the application of the national product intervention measures on binary options to event contracts
On 3 July 2026, ESMA issued a statement reminding firms of their obligation to assess whether newly offered products fall within the scope of existing product intervention measures on binary options.
The statement responds to the growing popularity of prediction markets – or event contracts – and increasing retail participation globally. Event contracts are products whose financial outcome is binary (a fixed payout or no payout at all) and depends on a yes-or-no answer to a question about a future event. Event contracts exist for a wide variety of event questions. Whether they qualify as financial instruments depends on the event question. Event contracts may (also) qualify as bets under national gambling legislation.
Where event contracts are financial instruments, they classify as derivatives and, given the binary outcome, fall within the scope of the existing national product intervention measures on binary options adopted by national competent authorities prohibiting their marketing, distribution or sale to retail clients.
The statement also reminds firms that the distribution of event contracts qualifying as financial instruments in the EU requires an authorisation as investment firm, even where only distributed to non-retail clients.
ESMA selects Etrading Software (Netherlands) B.V. as Consolidated Tape Provider for OTC derivatives
On 6 July 2026, ESMA announced that it had selected Etrading Software (Netherlands) B.V. as the Consolidated Tape Provider (CTP) for over-the-counter (OTC) derivatives. This constitutes an important step in improving transparency for OTC derivatives markets under MIFIR.
ESMA selected Etrading Software (Netherlands) B.V. following a comprehensive assessment of its application against the criteria set out in MIFIR. The selected applicant has demonstrated its ability to meet ESMA’s expectations, including in relation to data quality, resilience, and the dissemination of consolidated market data.
ESMA will invite Etrading Software (Netherlands) B.V. to apply for authorisation without delay. Once authorised, the CTP will operate the consolidated tape for OTC derivatives for a period of five years under ESMA’s direct supervision.
EMIR
ESMA publishes preliminary findings on the Active Account Requirement and the first Annual Report of the Joint Monitoring Mechanism
On 6 July 2026, ESMA published the Interim Report of the Effectiveness of the Active Account Requirement and the First Annual Report of the Joint Monitoring Mechanism.
By way of background, the Active Account Requirement, introduced under the European Market Infrastructure Regulation (EMIR), is designed to mitigate financial stability risks stemming from EU entities’ excessive exposures to Tier 2 CCPs that provide clearing services of substantial systemic importance to the Union.
Under EMIR, ESMA is required to assess the effectiveness of the AAR and prepare a report in close cooperation with the European System of Central Banks (ESCB) and the European Systemic Risk Board (ESRB), and after consulting the JMM.
Preliminary findings on the Active Account Requirement
Based on available data, analytics and industry feedback, the Interim Report provides preliminary findings on the Active Account Requirement (AAR) implementation during 2025 and early 2026.
The preliminary findings show that:
As of February 2026, around 500 entities had notified ESMA and national competent authorities that they are subject to the AAR.
- These entities represent a significant share of EU activity in relevant derivatives markets, with more than 90% of notional outstanding held by EU entities in the scope of the requirement.
- Notifications are spread across most Member States, with particularly strong representation in France, Germany and the Netherlands, and banks accounting for around half of notifying entities.
- In terms of impact, the report identifies early signs of increased clearing activity at EU central counterparties (EU CCPs), particularly among smaller entities, with some entities fully relocating their positions to the EU.
- The findings also point to a gradual, but limited, shift in market shares from systemically important third-country central counterparties (Tier 2 CCPs) to EU CCPs in certain AAR-related products.
Joint Monitoring Mechanism – Supporting coordinated cross sectoral oversight of the EU clearing landscape
Together with the AAR interim report, ESMA has also published the first Annual Report of the Joint Monitoring Mechanism (JMM), which plays a key role in monitoring developments and assessing financial stability risks across EU CCPs, clearing members and clients.
The Annual Report presents the outcomes of the joint cross-sectoral monitoring activities during its first year of operation in 2025.
Key findings include:
- The results of the JMM’s AAR monitoring activities, which form the preliminary findings presented in the Interim Report.
- An analysis of broader cross-border developments beyond the AAR, with a particular focus on the United States. The analysis confirms considerable cross-border dependencies, reflecting the global nature of EU and US cleared markets and their participants. While these linkages support market efficiency, liquidity and risk sharing, they may also create channels through which shocks could propagate.
- An assessment of trends affecting EU CCPs, highlighting the expansion of asset classes and products cleared in the EU and illustrating the capacity of EU CCPs to respond to evolving regulatory and market conditions.
- A stocktaking exercise of existing EU-wide stress tests, with a view to explore synergies with aspects related to the broader EU clearing ecosystem.
Given the recent entry into force of the AAR and the remaining data gaps, ESMA will conduct the effectiveness assessment in two stages. This Interim Report constitutes the first stage, and its findings should be considered preliminary, without prejudice to the findings of the final comprehensive assessment to be conducted in 2027, when a more complete data set will be available.
As a next step, ESMA will develop a dedicated methodology to assess the effectiveness of the AAR, which will inform the second stage of the final assessment in 2027.
Transaction reporting under MIFIR, EMIR and SFTR
ESMA identifies up to €1 billion in potential annual savings from simplifying EU transaction reporting
On 2 July 2026, ESMA published its final report on the simplification of transaction reporting, setting out a clear path towards a ‘Report Once’ approach.
ESMA’s review confirms that the main drivers of cost and complexity include frequent and unsynchronised regulatory changes, duplication of reporting across frameworks and channels, and dual-sided reporting and associated reconciliation processes.
In response, ESMA recommends a staged approach combining short-term burden reduction with a long-term structural reform. At the core of this strategy is the development of a single integrated transaction reporting framework across MIFIR, EMIR and SFTR, based on a “report once” principle.
This integrated model would allow transaction data to be reported once through a common modular structure to reflect product specificities within one single framework. Such data that then can be reused across authorities and supervisory mandates, reducing duplication while preserving the information needed for effective supervision.
The report is a key deliverable under ESMA’s broader Simplification and Burden Reduction (SBR) initiative, aimed at addressing the growing complexity and operational costs associated with EU reporting requirements.
Significant cost savings for market participants
The report is supported by a comprehensive cost-benefit analysis (CBA), including a study involving market participants.
The analysis indicates that the proposed “report once” scenario could deliver:
- annual net savings of €250 million to €1.0 billion,
- a reduction in recurring costs of around 22%–24%, and
- 10-year discounted cumulative net benefits of €1.2 billion to €4.9 billion.
Implementation costs are expected to be recovered within three to four years, after which efficiency gains would materialise on a sustained basis.
Alongside the long-term reform, ESMA proposes a set of intermediate measures to provide more immediate burden reduction. These include:
- expanding the use of delegated reporting arrangements,
- streamlining intragroup exemption procedures,
- targeted adjustments at ESMA level to reduce low-value or duplicative reporting requirements.
These measures are designed to address key cost drivers while ensuring compatibility with the future integrated framework.
Following the publication of the Final Report, ESMA will engage with EU institutions on the proposed recommendations.
The implementation of the integrated “report once” approach will require targeted legislative changes, a phased implementation and an inclusive dialogue with industry technical experts, allowing for coordinated development of reporting templates, data standards and streamlined infrastructure.
ESMA
ESMA work programme 2026
ESMA letter to the European Commission on de-prioritisation of deliverables under 2026 annual work programme
On 2 June 2026, ESMA published a letter addressed to the European Commission de-prioritising certain 2026 deliverables under its annual work programme.
Due to the increased workload arising from the market integration and supervision package (MISP) proposal and the broader political focus towards simplification and burden reduction, ESMA confirms that a small number of planned policy deliverables (set out in Table A of Annex I in the work programme) may become obsolete or altered depending on the final outcome of the legislative negotiations of the MISP package.
To avoid duplication or inconsistency, ESMA has also decided to postpone related consultations until after the package is adopted.
ESMA will now reallocate resources to higher priority workstreams. These include:
- preparing for the supervision and authorisation of consolidated tape providers and environmental, social and governance (ESG) rating providers;
- continued work on simplification and burden reduction, particularly in data reporting;
- T+1 settlement preparation;
- targeted convergence actions to support effective implementation of the Markets in Crypto-Assets Regulation and the revised European Market Infrastructure Regulation;
- assessing the impact of tokenisation and monitoring risks arising from geopolitical instability;
- delivery of the European Single Access Point; and
- initial work on new mandates such as the Retail Investment Strategy.
ESMA also calls on the European Commission to consider repealing or making optional certain recurring reporting mandates, to allow ESMA greater flexibility in aligning outputs with evolving current policy priorities and market developments.
OPERATIONAL RESILIENCE
ICT risk
BCBS report on ICT risk management for non-malicious incidents
On 2 June 2026, the Basel Committee on Banking Supervision (BCBS) published a report outlining observed practices in banks’ information and communication technology (ICT) risk.
The report aims to compare regulatory, supervisory and industry practices across jurisdictions relevant to addressing non-malicious ICT incidents in global systemically important banks, domestic systemically important banks and other banks of interest (e.g., digital-only banks) that affect the delivery of critical operations. It complements the BCBS’s earlier cyber resilience work.
Drawing on a survey of 16 jurisdictions and industry engagement, the BCBS identifies key findings, including that non malicious ICT incidents have varied across jurisdictions in recent years and are most driven by change control gaps, weaknesses in system design, capacity and performance issues, and failures linked to external dependencies.
The report highlights core practices adopted by banks relating to governance, business continuity, change management, technology solutions and third-party risk management. It is intended to serve as a reference point for firms and supervisors in strengthening their ICT risk management practices for their specific circumstances.
The BCBS will continue to monitor developments related to the digitalisation of finance and financial technology from a prudential perspective, including developments in AI models and the implications for banks’ cybersecurity.
ESAs 2025 report on major ICT-related incidents
On 3 June 2026, the European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority) published their first annual report on major ICT-related incidents under the Digital Operational Resilience Act (DORA).
The report covers 2025 and records 3,383 major incidents across all financial sectors. The ESAs emphasise that this figure does not indicate structural weakness as the direct impact on clients and transactions was generally limited.
The report also highlights that ICT risks are increasingly borderless, with around one third of incidents having a cross-border impact. System failures and external events were the main drivers. Nearly one third of incidents originated from third-party failures, with the ESAs highlighting the critical role of outsourced services and the need for robust third-party risk management and oversight. By contrast, the relatively low number of cybersecurity-related incidents suggested that existing safeguards and detection mechanisms were broadly effective. While the sector has demonstrated resilience to ICT-related threats, the ESAs stress that firms must maintain high cybersecurity standards, particularly to keep pace with the potential use of highly capable AI-driven tools.
CRYPTO-ASSETS
Markets in Crypto-Assets Regulation (MICAR)
ESMA Public Statement on the end of the MICA transitional period
On 23 June 2026, ESMA issued a Public Statement calling on unauthorised crypto-asset service providers to wind down orderly, while also safeguarding clients’ interests, as the transitional period under the Markets in Crypto-Assets Regulation (MICA) ends on 1 July 2026.
In the Public Statement ESMA states that it expects unauthorised crypto-asset service providers (CASPs) to take immediate steps to wind down their EU activities in an orderly manner, while also safeguarding clients’ interests and mitigating risks to market integrity. In particular, unauthorised CASPs must:
- Immediately stop onboarding new EU clients, refrain from opening new client relationships or accounts, and cease marketing activities and solicitation.
- Limit the provision of services to actions necessary to sell or transfer crypto-assets, reallocate assets, or close positions. Custody of clients’ crypto-assets can only continue for the period strictly necessary to complete an orderly exit.
- Communicate clearly, promptly and repeatedly with clients (retail and institutional) about the measures taken to safeguard their assets and the wind-down plans so that clients know the timeline to dispose of, transfer, reallocate or close their positions. CASPs’ communications should include a deadline by which any residual positions would be closed automatically and information about client protection requirement.
ESMA also reminds CASPs established outside the EU that they cannot provide MICA services to EU clients or solicit EU clients. This also applies in a business-to-business context. In this regard, ESMA reminds that MICA prohibits CASPs from outsourcing or delegating certain services, notably custody, to entities that are not authorised as CASPs.
ESMA reminds clients of unauthorised CASPs, whether EU or non-EU entities, that they do not benefit from MICA safeguards, including protections for client assets.
FINANCIAL CRIME
Anti-money Laundering
AMLA consults on draft guidelines on ongoing monitoring of business relationships
On 3 June 2026, the EU Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) launched a consultation on draft guidelines on ongoing monitoring of business relationships under Article 26(5) of Regulation 2024/1624.
The guidelines aim to ensure a proportionate, risk‑based and effective application of monitoring obligations across all obliged entities and set out key principles including:
- expectations for updating customer information through periodic and event‑driven reviews
- the sources of information that may be used alongside non‑exhaustive lists of factors to assess during periodic customer information reviews and event trigger reviews
- how monitoring frameworks should be designed and implemented to detect unusual or suspicious activity, using appropriate manual or automated controls.
They further reflect the need for clear governance, adequate documentation, appropriate staff training, and the responsible use of advanced analytical tools, supported by effective human oversight, where appropriate.
The deadline for comments is 3 September 2026, with a public hearing scheduled for 2 July 2026. Final guidelines are expected in Q4.
FUNDS
UCITS and AIFs
ESMA launches Common Supervisory Action with NCAs on the risk management function
On 3 July 2026, ESMA launched a Common Supervisory Action (CSA) on risk management function of UCITS management companies and Alternative Investment Fund Managers (AIFMs) across the European Union.
The CSA will be conducted throughout 2026 and 2027, in close collaboration with National Competent Authorities (NCAs).
The objective of the CSA is to assess how market participants comply with key risk-related provisions under the UCITS and AIFMD frameworks. The focus will be on the effectiveness, independence and expertise of the risk management function.
Risk management is a core function of investor protection and financial stability. It ensures that material risks, such as market, credit, liquidity, counterparty, and operational risks, are properly identified, measured, monitored, and managed.
As part of this exercise, NCAs will focus on three key areas:
- governance and organisation of the risk management function;
- identification, measurement and monitoring of risks; and
- reporting to senior management and governing bodies.
The CSA will be conducted using a common assessment framework developed by ESMA. This framework sets out the scope, methodology, supervisory expectations, and supervisory expectations and timeline for the exercise, ensuring a comprehensive and convergent approach across the EU.
Throughout the exercise, NCAs will share knowledge and supervisory experiences through ESMA, further supporting supervisory convergence in the oversight of risk management function.
ESMA will publish a final report with the results of the exercise in 2028.
SUSTAINABLE FINANCE
Corporate Sustainability Due Diligence Directive (CSDDD)
European Commission consults on guidelines to support implementation of the Corporate Sustainability Due Diligence Directive
On 12 June 2026, the European Commission launched a consultation on the development of guidelines to support the effective implementation of the Corporate Sustainability Due Diligence Directive (EU) 2024/1760 (CS3D).
The European Commission will issue guidelines that provide practical orientation to companies on how to fulfil their due diligence obligations, to Member State authorities on how to implement and enforce CS3D, and to stakeholders on how to pursue their rights. The guidelines will also be relevant for companies and other stakeholders in non-EU countries that are linked to the supply chains of companies with obligations under CS3D.
The deadline for comments is 24 July 2026.
Sustainable Finance Disclosure Regulation (SFDR)
Council of EU adopts negotiating position on SFDR 2.0
On 24 June 2026, the Council of the EU announced that it has agreed its negotiating mandate on proposed reforms to the Sustainable Finance Disclosure Regulation (EU) 2019/2088 (SFDR) — known as the SFDR 2.0 proposal, adopted in November 2025.
The SFDR requires market participants to disclose how they integrate social, environmental and governance sustainability risks and adverse impacts into their investment offers. The reforms aim to simplify the sustainability-related transparency requirements, reduce administrative burdens, and improve the comparability of financial products for investors.
Overall, the Council supports the proposed changes which include the introduction of three new product categories: “sustainable”, “transition”, and “ESG basics”, to replace the current framework and address concerns around existing concepts that have led to greenwashing.
However, its negotiating mandate also introduces the following amendments:
- For products classified as “sustainable” or “transition”, firms disclosing principal adverse impacts will have to use at least three prescribed indicators (to be set by the European Commission) to support claims and improve cross-product comparability.
- Investments in fossil fuel companies may qualify as transition investments where 20% of capital expenditure is aligned with EU taxonomy (green classification) rules and the company has a clear, time-bound emissions reduction strategy; such investments will be subject to a fourth mandatory adverse impact indicator.
- General-purpose issuances by EU public sector bodies may be included in the “transition” category under certain conditions.
- Alternative investment funds marketed exclusively to professional investors may be exempt from applying the categorisation provisions.
The Council’s mandate will form the basis for negotiations with the European Parliament once it has adopted its own respective position.
Taxonomy
ESMA consults on simplifying EU Taxonomy disclosure framework
On 1 July 2026, ESMA launched a consultation on technical advice to the European Commission on selected KPIs under the Taxonomy Disclosures Delegated Act, focusing on simplification and reduction of reporting burdens for market participants.
The consultation builds on recent simplification efforts under the Commission’s Omnibus package and aims to support the broader review of Taxonomy reporting, focusing on simplifying the reporting framework while preserving the relevance of disclosures for investors.
ESMA proposes several simplifications to the Taxonomy disclosure framework for non-financial undertakings and asset managers. These include the operational expenditure key performance indicator (OpEX), addressing stakeholder concerns about complexity and reporting burden. ESMA also seeks feedback on a possible pragmatic solution for group-level reporting in mixed groups, based on the parent undertaking’s reporting model.
The European Commission requested each European Supervisory Authority (ESA) to provide advice on targeted aspects of the review the Taxonomy disclosure framework. The ESAs are requested to address specific issues within their remit, as well as horizontal topics of common interest. The EBA consultation is accessible here, while EIOPA’s consultation can be found here.
The consultation will run for six weeks, until 12 August 2026, in parallel to the consultations by the other ESAs. ESMA will hold a public hearing to present the proposals and engage with stakeholders on 22 July 2026.
Following the consultation, ESMA will deliver its final technical advice by end-October 2026, as requested by the European Commission.
CYSEC DEVELOPMENTS
Circular C782: AMLA’s public consultation regarding the draft GLs under article 26(5) of Regulation (EU) 2024/1624
On 9 June 2026, CySEC issued Circular C782 (the ‘Circular’), to inform the Regulated Entities that the Anti-Money Laundering Authority (the ‘AMLA’) has launched a public consultation regarding:
Draft Guidelines (the ‘GLs’) under article 26(5) of Regulation (EU) 2026/1624 (the ‘AMLR’) – on ongoing monitoring of a business relationship
The consultation is open to all stakeholders, including obliged entities in the non-financial sector. CySEC urges the Regulated Entities to respond to the consultation paper.
Circular C784: Digital Operational Resilience Act – updated reporting templates
On 10 June 2026, CySEC issued Circular C784 (the ‘Circular’), to inform the Regulated Entities that the following templates under the Digital Operational Resilience Act (‘the DORA‘) have been updated:
(a) Major ICT-related incidents and
(b) Significant cyber threats.
The Circular refers to the Version 1.3 (V1.3) Excel templates, which are available on CySEC’s website and should be used for the submission of the relevant reports.
The Incident Reporting Template V1.3, continues to consist of three separate sections corresponding to the three types of reports, namely Initial Report, Intermediate Report and Final Report. Regulated Entities are required to continue submitting all applicable reports within the deadlines set out in CySEC’s Circular C700.
Regulated Entities are reminded that they should continue to submit the templates using the submission process and file naming convention as set out in Section C in this Circular.
CySEC emphasises that all Regulated Entities are required to transition to the V1.3 templates from the date of this Circular and to ensure timely and accurate submission of the required reporting templates.
Circular C785: Requirements of the Spanish Securities and Exchange Commission regarding the product intervention measures relating to CFDs and other leveraged products to retail investors in Spain
Following the publication of CySEC Circular C602, CySEC issued Circular C785 on 10 June 2026, at the request of the Spanish Securities and Exchange Commission (the ‘CNMV’).
The CNMV maintains the view that Spot Quoted Futures (SQFs) must be treated in Spain as contract for differences (‘CFDs’) for regulatory purposes and consequently considers that SQF are subject to the product intervention measures set out in both the CNMV Resolution of 2019 and the CNMV Resolution of 11 July 2023.
CySEC continues to urge all CIFs that are marketing, distributing and selling CFDs and other leveraged products (including SQFs and perpetual futures, or analogue products) to retail investors in Spain to take all appropriate actions and measures to adhere to the Resolution as interpreted and applied by the CNMV pursuant to its national legal framework.
Circular C786: Frontier Artificial Intelligence Models and Cybersecurity Risks under the Digital Operational Resilience Act (DORA)
On 17 June 2026, CySEC issued Circular C786 (the ‘Circular’), to draw the attention of Regulated Entities to the increasing cybersecurity risks associated with the emergence of frontier Artificial Intelligence (‘AI’) models capable of identifying and exploiting software vulnerabilities at unprecedented speed and scale.
CySEC reminds all Regulated Entities falling within the scope of Regulation (EU) 2022/2554 on Digital Operational Resilience for the financial sector (‘DORA’) that they are obliged to maintain robust ICT risk management frameworks capable of addressing evolving cyber-threats, including those arising from emerging AI technologies.
CySEC expects Regulated Entities, proportionate to their size, nature, scale and complexity, to assess whether their existing ICT risk management arrangements remain adequate and, where necessary, to strengthen relevant controls and processes. In particular, CySEC encourages Regulated Entities to consider the following areas:
- Identification and Vulnerability Management
- Protection and Prevention
- Detection Capabilities
- Response and Recovery
- Governance and Continuous Improvement
For further information, please refer to Section B of the Circular.
In addition, CySEC further reminds that, under DORA, Regulated Entities are required to:
- Protect ICT systems and assets against unauthorised access and malicious activities.
- Detect anomalous activities and ICT-related incidents.
- Maintain robust business continuity, backup and restoration arrangements.
- Conduct appropriate ICT testing and vulnerability assessments.
- Manage ICT third-party risks effectively.
Regulated Entities are urged to remain vigilant and to take proactive measures to ensure that their digital operational resilience frameworks continue to evolve in line with the changing cyber risk environment.
Why Choose Complyport?

Extensive Regulatory Expertise
With over 25 years of experience in the financial services industry, Complyport offers unparalleled expertise in regulatory compliance, ensuring your firm stays ahead of evolving regulations.

Comprehensive Service Offering
From AML audits to risk management and regulatory reporting, Complyport provides a full spectrum of compliance services, allowing you to streamline your compliance processes and focus on your core business activities.

Tailored Compliance Solutions
We provide bespoke compliance solutions that are specifically designed to meet the unique needs of your business, ensuring that all regulatory requirements are met efficiently and effectively.

Client-Centric Approach
We prioritise open and transparent communication, building strong relationships with our clients based on trust and mutual respect. Our commitment to excellence ensures that we deliver high-quality services with courtesy, patience, and flexibility.

Senior-Level Guidance
Our team of seasoned professionals, including former regulators and industry experts, leads all engagements, offering deep insights and practical advice to help you manage compliance risks effectively.

Innovative Fintech, Regtech and AI Solutions
Leveraging cutting-edge fintech, regtech and AI tools, Complyport enhances your compliance processes with advanced technology, ensuring accuracy, efficiency and real-time regulatory updates. Our innovative solutions empower your firm to stay compliant while maximising operational efficiency.
Key Figures
Over 25 Years
Providing Compliance Excellence
Over 1,500
Successful FCA, EU and UAE Authorisations
Over 1,000
Active Firms Receiving
Regulatory Support
8 Lots
FCA/PRA Skilled
Person
&
Consultancy Panel
