DORA compliance for CySEC-regulated firms.
Regulation (EU) 2022/2554 has applied since 17 January 2025. This is what it means in practice for investment firms, fund managers, administrative service providers and crypto-asset service providers supervised in Cyprus — with a free toolkit to check where you stand.
Two obligations decide most supervisory conversations in Cyprus: the Register of Information and major incident reporting.
Both are submitted through the CySEC portal, both depend on data your firm has to keep current all year, and both are the fastest way for a supervisor to see whether the underlying ICT risk framework is real. The register exposes every provider dependency and how it is contracted; the incident clocks expose whether classification, escalation and out-of-hours cover actually work. Everything else in DORA — testing, continuity, board oversight — is the machinery that keeps those two obligations honest.
- Legal basis
- Regulation (EU) 2022/2554 (DORA)
- Applies from
- 17 January 2025
- Cyprus authority
- CySEC (financial entities under its supervision)
- Accountability
- Article 5 — the management body is ultimately responsible
- Register of Information
- Annual submission of all ICT third-party arrangements
- Major incident clocks
- Initial 4h/24h · intermediate 72h · final 1 month
- Advanced testing
- TLPT — Art. 26 + Delegated Reg. (EU) 2025/1190
What DORA requires, in order
ICT risk management (Art. 5–16)
A board-approved ICT risk framework, an independent control function, documented asset and dependency mapping, and an annual review with minuted decisions. Article 5 puts final responsibility on the management body — delegation to IT does not transfer accountability.
- ›Business function to ICT asset dependency mapping
- ›Protection, detection, response and recovery policies
- ›Annual review plus post-incident framework updates
Major incident reporting (Art. 17–23)
Classify, escalate and report ICT-related incidents against fixed clocks: an initial notification within 4 hours of classifying an incident as major and no later than 24 hours from becoming aware, an intermediate report within 72 hours, and a final report within one month of the intermediate.
- ›Written classification procedure with named decision-makers
- ›Submission roles and credentials tested before the incident
- ›Voluntary notification path for significant cyber threats
Register of Information (Art. 28)
Every contractual arrangement with an ICT third-party provider is recorded and submitted to the authority in the prescribed format. CySEC ran a dry run and workshops (C639, C668) before the first live cycles addressed in C700 and C751.
- ›LEI or EUID for the entity and every provider
- ›Critical or important function designation per arrangement
- ›Sub-outsourcing chains for critical services
Resilience testing and TLPT (Art. 24–27)
A proportionate annual testing programme for all entities, with threat-led penetration testing for those designated by the authority. Delegated Regulation (EU) 2025/1190 sets the TLPT criteria, methodology and tester requirements.
- ›Vulnerability assessments and scenario-based testing
- ›Independent testers and evidenced remediation closure
- ›TLPT scoping against critical and important functions
Third-party contracts and exit (Art. 30)
Contracts for critical or important functions need audit and access rights, service levels, data location, security requirements, termination triggers and realistic exit support. Entities outside DORA scope follow the ESMA cloud outsourcing guidelines adopted by CySEC in C759.
- ›Article 30 clause gap review across the provider estate
- ›Tested exit strategies with named alternatives
- ›Concentration risk view across shared providers
Governance evidence CySEC looks for
Supervisory attention is on documentation that proves the framework operates: board minutes, incident logs, test reports, remediation trackers and a register that reconciles to procurement and finance records.
- ›Board and committee reporting pack for ICT risk
- ›Incident log reconciled to classification decisions
- ›Evidence pack ready ahead of each submission window
Free toolkit for CySEC-supervised entities
Three working tools: check whether DORA applies to your licence, calculate your major incident reporting deadlines in Cyprus time, and score your Register of Information readiness. Nothing is stored unless you ask us for the written summary.
- ›ICT risk management framework with documented board approval (Art. 5–16)
- ›Classification and reporting of major ICT-related incidents (Art. 17–23)
- ›Digital operational resilience testing programme (Art. 24–27)
- ›Register of Information covering every ICT third-party arrangement (Art. 28)
- ›Contractual clauses and exit strategies for ICT providers (Art. 30)
- ›Full ICT risk management framework, independent control function and annual review
- ›Threat-led penetration testing may be required if CySEC designates you (Art. 26)
- ›EBA ICT and security risk guidelines remain the supervisory yardstick (C571, C701)
- ›Client asset safeguarding controls under Directive DI87-01 interact with ICT continuity
Guidance only, not legal advice. TheCyberCo is not CySEC and does not administer any supervisory process — always verify obligations and deadlines against the authority's own published circulars.
Circulars and instruments to keep on file
Cyprus-specific implementation detail arrives through CySEC circulars. Confirm the current version on the authority's own circulars page before relying on any reference below.
- C63924 Apr 2024 · registerRegister of Information — voluntary dry run exercise
- C66810 Dec 2024 · registerRegister of Information workshop and preparation for DORA application
- C7008 Apr 2025 · incidentICT-related incident reporting and Register of Information submission
- C7019 Apr 2025 · ictEBA Guidelines EBA/GL/2025/02 amending the ICT and security risk guidelines
- C75119 Jan 2026 · governanceDORA reporting, governance expectations and CySEC portal obligations
- C75913 Mar 2026 · outsourcingESMA 2025 cloud outsourcing guidelines (entities outside DORA scope)
- C5712 May 2023 · ictEBA Guidelines EBA/GL/2019/04 on ICT and security risk management for CIFs
- EU 2025/11902025 · testingDelegated Regulation on threat-led penetration testing criteria and methodology
DORA delivery for Cyprus-supervised entities
- DORA gap assessment mapped article by article to your licence
- Register of Information build, validation and submission support
- Incident classification playbooks and reporting dry runs
- Threat-led and scenario-based resilience testing
- ICT third-party contract and exit strategy review
- vCISO cover for board-level ICT risk accountability