Cyprus / CySEC CIF

Compliance and cybersecurity for CySEC-regulated investment firms.

Built for CIFs, forex brokers and investment firms headquartered in Limassol and across Cyprus: DORA obligations, threat-led penetration testing, incident reporting and the CySEC circulars that decide supervisory conversations.

CIF / FOREX

Most forex brokers in Limassol run on outsourced technology. Regulators now read that stack as your risk, not your vendor's.

A CySEC licence under Law 87(I)/2017 comes with an ICT baseline set by the EBA security risk guidelines, hardened by DORA since January 2025, and sharpened by a steady stream of CySEC circulars on the Register of Information, incident reporting, cloud outsourcing, client assets and identity verification. This page maps those obligations to the way a broker actually operates: the trading platform, the liquidity bridge, the CRM, the PSPs and the client portal. Confirm the current text of every circular on the authority's own website before relying on it.

/ KEY.FACTS
Who this is for
CIFs, forex brokers and investment firms supervised by CySEC
Licence basis
Law 87(I)/2017 transposing MiFID II
ICT baseline
EBA/GL/2019/04 as transmitted by CySEC (C571, updated by C701)
Resilience regime
DORA — Regulation (EU) 2022/2554, applying since 17 Jan 2025
Advanced testing
TLPT — DORA Art. 26 + Delegated Reg. (EU) 2025/1190
Client assets
Directive DI87-01, reinforced by circulars C418 and C458
Board accountability
DORA Art. 5 — the management body carries final responsibility
/ OBLIGATIONS

What a CIF has to evidence, end to end

§ 01

ICT risk framework the board actually owns

A CIF has to hold a documented ICT risk management framework, an ICT control function independent of operations, and an annual board review with minuted decisions. Supervisors in Cyprus read this against the EBA ICT and security risk guidelines transmitted through C571 and amended through C701, layered on top of DORA Articles 5 to 16.

  • Trading, execution and client-money functions mapped to ICT assets
  • Named ICT risk owner reporting outside the IT delivery line
  • Annual review plus framework updates after every major incident
§ 02

Major incident reporting on the CySEC portal

Retail-facing brokers see incidents that bite fast: platform outages during volatile sessions, liquidity-feed failures, client-portal credential stuffing. DORA fixes the clocks — initial notification within 4 hours of classifying an incident as major and no later than 24 hours from becoming aware, intermediate within 72 hours, final within a month of the intermediate.

  • Written classification thresholds tied to client and trade impact
  • Out-of-hours escalation covering non-Cyprus trading hours
  • Portal roles and credentials tested before an incident, not during one
§ 03

Register of Information for the broker stack

The typical Limassol broker runs on outsourced infrastructure: trading platform vendor, liquidity and bridge providers, CRM, PSPs and EMIs, KYC and onboarding tooling, cloud hosting, VPS for client EAs. Each is an ICT third-party arrangement that belongs in the Register of Information, with sub-outsourcing chains for anything supporting a critical or important function.

  • LEI or EUID captured for the firm and each provider
  • Critical or important designation per arrangement, not per vendor
  • Register reconciled to procurement, finance and contract records
§ 04

Threat-led penetration testing (TLPT)

DORA Article 26 requires advanced, threat-led testing for entities designated by the competent authority, with criteria, methodology and tester requirements set by Delegated Regulation (EU) 2025/1190. Even undesignated firms must run a proportionate testing programme: vulnerability assessments, scenario-based tests, and evidenced remediation closure.

  • Scope built from critical and important functions, not from IP ranges
  • Threat intelligence reflecting real broker-sector adversary behaviour
  • Independent testers, purple-team phase and a closure-evidenced remediation plan
§ 05

Outsourcing, cloud and exit

Contracts supporting critical or important functions need audit and access rights, service levels, data location, security requirements, termination triggers and a realistic exit. Entities outside DORA scope follow the ESMA cloud outsourcing guidelines adopted by CySEC through C759, which replaced the older Circular 457.

  • Article 30 clause gap review across the full provider estate
  • Concentration risk view where several functions share one provider
  • Exit plans with a named alternative and a tested transition window
§ 06

Client assets, AML and the ICT overlap

Client-asset safeguarding under DI87-01 and the reconciliation expectations reinforced by C418 and C458 depend on systems that must stay available and accurate. AML and identity-verification duties clarified in C721 sit on the same onboarding and screening platforms, which makes those platforms critical ICT dependencies rather than back-office tooling.

  • Reconciliation and segregation controls evidenced through system records
  • Onboarding, screening and record-keeping platforms in the register
  • Continuity plans covering PSP and EMI dependencies
/ THREAT.LED.TESTING

TLPT for CIFs: from designation to closure

DORA Article 26 and Delegated Regulation (EU) 2025/1190 define how threat-led penetration testing is scoped, executed and closed. Firms not designated by the authority still owe a documented, proportionate testing programme.

01

Preparation

Scope agreement, control-team appointment, provider due diligence and authority engagement where the firm is designated.

02

Threat intelligence

Targeted intelligence on adversaries active against brokers and payment flows, converted into realistic attack scenarios.

03

Red team execution

Live testing against production critical and important functions under strict rules of engagement and risk controls.

04

Closure

Purple-team replay, findings report, remediation plan with owners and dates, and evidence of closure for the supervisory file.

/ FAQ

Questions CySEC-regulated firms ask us

Does DORA apply to a CySEC-licensed forex broker?
Yes. Cyprus Investment Firms are financial entities within the scope of Regulation (EU) 2022/2554, which has applied since 17 January 2025. Microenterprises follow a simplified ICT risk management framework under Article 16, but the management body remains accountable.
What are the DORA incident reporting deadlines for a CIF?
An initial notification within 4 hours of classifying an incident as major and no later than 24 hours from becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report no later than one month after the intermediate report.
Do all CIFs have to run threat-led penetration testing?
No. TLPT under DORA Article 26 applies to entities identified by the competent authority. All other firms still need a proportionate digital operational resilience testing programme with documented remediation.
Which CySEC circulars matter most for ICT and cybersecurity?
C571 and C701 for EBA ICT and security risk guidelines, C639, C668, C700 and C751 for DORA register and incident reporting, C759 for cloud outsourcing outside DORA scope, and C418, C458 and C721 for client assets and identity verification. Always confirm the current version on the CySEC circulars page.
Do you work with brokers based in Limassol?
Yes. Most Cyprus Investment Firms are headquartered in Limassol and we deliver on-site workshops, board sessions and testing engagements there, as well as remotely across Cyprus and the EU.
/ THECYBERCO.SERVICE

Delivery for brokers and investment firms in Limassol and across Cyprus

  • CIF ICT gap assessment. Article-by-article DORA and EBA guideline review mapped to your licence category and business model.
  • Register of Information build. Provider discovery, criticality designation, identifier collection, validation and submission support.
  • Incident reporting readiness. Classification playbooks, escalation trees, portal role testing and reporting dry runs.
  • Threat-led and scenario testing. TLPT-aligned red teaming, penetration testing and purple-team closure for critical functions.
  • Outsourcing and exit review. Article 30 clause gap analysis, concentration risk mapping and tested exit strategies.
  • vCISO for regulated firms. Named senior cover for board reporting, supervisory correspondence and remediation oversight.

Guidance on this page is general information, not legal advice. TheCyberCo is not CySEC and does not administer any regulatory programme; verify obligations with your legal and compliance advisers and the authority's current publications.

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment