Cyprus / DORA

DORA compliance for CySEC-regulated firms.

Regulation (EU) 2022/2554 has applied since 17 January 2025. This is what it means in practice for investment firms, fund managers, administrative service providers and crypto-asset service providers supervised in Cyprus — with a free toolkit to check where you stand.

DORA

Two obligations decide most supervisory conversations in Cyprus: the Register of Information and major incident reporting.

Both are submitted through the CySEC portal, both depend on data your firm has to keep current all year, and both are the fastest way for a supervisor to see whether the underlying ICT risk framework is real. The register exposes every provider dependency and how it is contracted; the incident clocks expose whether classification, escalation and out-of-hours cover actually work. Everything else in DORA — testing, continuity, board oversight — is the machinery that keeps those two obligations honest.

/ KEY.FACTS
Legal basis
Regulation (EU) 2022/2554 (DORA)
Applies from
17 January 2025
Cyprus authority
CySEC (financial entities under its supervision)
Accountability
Article 5 — the management body is ultimately responsible
Register of Information
Annual submission of all ICT third-party arrangements
Major incident clocks
Initial 4h/24h · intermediate 72h · final 1 month
Advanced testing
TLPT — Art. 26 + Delegated Reg. (EU) 2025/1190
/ OBLIGATIONS

What DORA requires, in order

§ 01

ICT risk management (Art. 5–16)

A board-approved ICT risk framework, an independent control function, documented asset and dependency mapping, and an annual review with minuted decisions. Article 5 puts final responsibility on the management body — delegation to IT does not transfer accountability.

  • Business function to ICT asset dependency mapping
  • Protection, detection, response and recovery policies
  • Annual review plus post-incident framework updates
§ 02

Major incident reporting (Art. 17–23)

Classify, escalate and report ICT-related incidents against fixed clocks: an initial notification within 4 hours of classifying an incident as major and no later than 24 hours from becoming aware, an intermediate report within 72 hours, and a final report within one month of the intermediate.

  • Written classification procedure with named decision-makers
  • Submission roles and credentials tested before the incident
  • Voluntary notification path for significant cyber threats
§ 03

Register of Information (Art. 28)

Every contractual arrangement with an ICT third-party provider is recorded and submitted to the authority in the prescribed format. CySEC ran a dry run and workshops (C639, C668) before the first live cycles addressed in C700 and C751.

  • LEI or EUID for the entity and every provider
  • Critical or important function designation per arrangement
  • Sub-outsourcing chains for critical services
§ 04

Resilience testing and TLPT (Art. 24–27)

A proportionate annual testing programme for all entities, with threat-led penetration testing for those designated by the authority. Delegated Regulation (EU) 2025/1190 sets the TLPT criteria, methodology and tester requirements.

  • Vulnerability assessments and scenario-based testing
  • Independent testers and evidenced remediation closure
  • TLPT scoping against critical and important functions
§ 05

Third-party contracts and exit (Art. 30)

Contracts for critical or important functions need audit and access rights, service levels, data location, security requirements, termination triggers and realistic exit support. Entities outside DORA scope follow the ESMA cloud outsourcing guidelines adopted by CySEC in C759.

  • Article 30 clause gap review across the provider estate
  • Tested exit strategies with named alternatives
  • Concentration risk view across shared providers
§ 06

Governance evidence CySEC looks for

Supervisory attention is on documentation that proves the framework operates: board minutes, incident logs, test reports, remediation trackers and a register that reconciles to procurement and finance records.

  • Board and committee reporting pack for ICT risk
  • Incident log reconciled to classification decisions
  • Evidence pack ready ahead of each submission window
/ CYPRUS.COMPLIANCE.TOOLKIT

Free toolkit for CySEC-supervised entities

Three working tools: check whether DORA applies to your licence, calculate your major incident reporting deadlines in Cyprus time, and score your Register of Information readiness. Nothing is stored unless you ask us for the written summary.

CIF / investment firm — in scope of DORA since 17 January 2025.
Core obligations
  • ICT risk management framework with documented board approval (Art. 5–16)
  • Classification and reporting of major ICT-related incidents (Art. 17–23)
  • Digital operational resilience testing programme (Art. 24–27)
  • Register of Information covering every ICT third-party arrangement (Art. 28)
  • Contractual clauses and exit strategies for ICT providers (Art. 30)
  • Full ICT risk management framework, independent control function and annual review
  • Threat-led penetration testing may be required if CySEC designates you (Art. 26)
Watch out for
  • EBA ICT and security risk guidelines remain the supervisory yardstick (C571, C701)
  • Client asset safeguarding controls under Directive DI87-01 interact with ICT continuity

Guidance only, not legal advice. TheCyberCo is not CySEC and does not administer any supervisory process — always verify obligations and deadlines against the authority's own published circulars.

/ THECYBERCO.SERVICE

DORA delivery for Cyprus-supervised entities

  • DORA gap assessment mapped article by article to your licence
  • Register of Information build, validation and submission support
  • Incident classification playbooks and reporting dry runs
  • Threat-led and scenario-based resilience testing
  • ICT third-party contract and exit strategy review
  • vCISO cover for board-level ICT risk accountability

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment