top of page

Search Results

70 results found with an empty search

  • The PSD3 / PSR Political Agreement: What Was Decided, What Comes Next

    The Political Decision: Why This Agreement Matters Following prolonged negotiations, the European Parliament and the Council of the European Union reached a political agreement on the new Payment Services Regulation (PSR) and the Third Payment Services Directive (PSD3)  package on the basis of the proposal advanced by the European Commission. This agreement is politically significant for three reasons: It represents a strategic shift from minimum harmonisation to direct applicability, via the PSR. It responds to systemic weaknesses in fraud prevention, especially Authorised Push Payment (APP) fraud. It completes the post-PSD2 recalibration of EU payments law, aligning it with the Digital Finance Strategy, DORA, and broader consumer-protection objectives. What Was Agreed: Core Elements of the PSD3 / PSR Package A New Legal Architecture The framework is split deliberately: PSR (Regulation) : directly applicable rules on conduct of business, transparency, fraud liability, and operational requirements. PSD3 (Directive) : institutional and prudential matters (licensing, supervision, passporting, governance). This division aims to reduce national divergence that undermined PSD2’s effectiveness. Stronger Fraud Protection & Liability Rules A key political concession was enhanced consumer protection against fraud: Mandatory reimbursement for certain APP fraud cases, subject to limited exceptions. Reinforced obligations for PSPs on transaction monitoring and customer warnings. Greater emphasis on shared liability across the payment chain. This is one of the most contentious areas and will be heavily scrutinised in implementation. Transparency and Fee Disclosure The agreed text strengthens rules on: Hidden charges and opaque FX mark-ups. Pre-transaction and post-transaction disclosure obligations. Comparability of fees across providers. Open Banking / Open Finance Continuity While not revolutionary, the package: Consolidates access-to-account rules. Seeks to stabilise business models for third-party providers (TPPs). Addresses data-access friction without fully moving into “Open Finance” (reserved for future initiatives). What Happens Next: The Formal and Practical Timeline The political agreement must still pass through: Legal-linguistic finalisation Formal adoption by Parliament and Council Publication in the Official Journal Only then do the clocks start running. Indicatively: PSR : applies directly after a transition period (18–24 months). PSD3 : Member States will have a transposition deadline (typically ~18 months). For firms, the message is clear: Compliance will no longer be defensive. It will be operational, technological, and strategic. Early preparation, legal, compliance, IT, and governance-wise will be the decisive differentiator. The agreed measures must be formally adopted by the European Parliament and the Council of the European Union before they can come into force. The Council and the Parliament will continue working on the technical elements of the package before final adoption by the co-legislators. We anticipate that the final texts will be published in the Official Journal of the European Union in H1 2026.

  • CySEC Signals Major Shift: EU Securities Market Moves to T+1 Settlement Cycle

    The Cyprus Securities and Exchange Commission (CySEC) has issued Circular C741 to regulated market participants, signalling an important evolution in the post-trade landscape of European securities markets. This development aligns Cyprus with broader EU policy aimed at boosting market efficiency, reducing risk, and harmonising settlement practices with global standards. What’s Changing? Under the updated EU framework, specifically Regulation (EU) 2025/2075   amending the Central Securities Depositories Regulation (CSDR), the standard settlement cycle for most securities transactions in the EU will be shortened from T+2 to T+1. That means trades in equities, bonds, and other transferable securities executed on trading venues must be settled no later than one business day after the trade date. This is a significant acceleration compared to the traditional two-day cycle. Transition Timeline Regulation Entry into Force: 3 November 2025 Effective Application Date:  11 October 2027 Why T+1 Matters The move to T+1 settlement is driven by three key objectives : Operational Efficiency:  Shorter settlement cycles reduce the time between trade execution and settlement, streamlining the post-trade process. Risk Reduction:  By cutting the exposure window, market participants face lower counterparty and settlement risk - a major benefit during periods of market stress. Global Alignment : Many leading markets outside the EU, including the United States, already operate on a T+1 basis, and this shift harmonises European practices with international norms. What Transactions Are Covered? The T+1 requirement applies broadly to transferable securities executed on trading venues. However, the regulation clarifies that certain trades remain outside its scope, such as: Privately negotiated trades executed on trading venues Bilateral trades reported to trading venues Initial book-entry transactions under specific conditions Certain securities financing transactions (SFTs) Margin lending (as these are not considered transactions in transferable securities) Practical Implications for Firms Regulated entities, including Cyprus Investment Firms (CIFs), UCITS, AIFs, trading venues, and central securities depositories, are now encouraged to begin their readiness preparations. According to the Circular: Entities are urged to review the potential impact of the transition on internal systems, operational workflows, liquidity and treasury frameworks, client onboarding practices, and cross-border arrangements. This early engagement is especially important, as technological and procedural adjustments will be necessary to comply with the tighter settlement timeline. Industry Collaboration: T+1 Readiness Survey In addition to the regulatory timeline, the EU T+1 Industry Committee has launched a readiness survey to gauge the preparedness of market participants. CySEC’s Circular strongly encourages regulated entities to participate in this exercise in order to help identify challenges and operational bottlenecks ahead of implementation. What’s Next? As the countdown to October 2027 begins, market participants must take proactive steps to adapt: Upgrade systems to support T+1 clearing and settlement processes. Assess liquidity management practices to accommodate faster cash and securities flows. Coordinate across departments to ensure seamless transition. The shift to T+1 is more than a technical tweak; it represents a structural enhancement to EU financial markets that promises greater resilience and efficiency. For Cyprus-based firms under CySEC supervision, early planning and active engagement with the T+1 readiness initiatives will be key to complying with this new chapter in European capital markets.

  • Regulatory Alert: EMIR Data-Collection for Initial Margin Model Validation

    On December 12, 2025, the Cyprus Securities and Exchange Commission (CySEC) published a Circular C740 , addressing the upcoming regulatory requirements under the European Market Infrastructure Regulation (EMIR). This circular sets out precise data-collection expectations for regulated entities in Cyprus that are subject to EMIR’s initial margin model authorisation and validation procedures. Background: EMIR and Initial Margin Models Under Article 11(3) of EMIR (Regulation (EU) No 648/2012), firms that exchange initial margin and use internal margin models—such as the ISDA Standard Initial Margin Model (SIMM)—must seek prior authorisation from their competent authority before implementing or continuing to use such models. Moreover, validation of these models by the European Banking Authority (EBA) is required before they can be adopted across the EU. What is Required The core purpose of Circular C740 is to ensure that regulated entities report the necessary information to CySEC by 16 January 2026 to facilitate: Identification of which entities need to apply for authorization and subsequent EBA validation. Onboarding of these entities to the EBA’s ISDA SIMM Validation System (under development). To this end, the circular instructs entities to send: The standard data set specified in the EBA’s opinion on initial margin model applications. A completed template (titled “EMIR IMM application for authorisation_LEI of Regulated Entity” and referenced as “EMIR IMM validation_LEI of Regulated Entity.xlsx”) — submitted to CySEC via email to emir@cysec.gov.cy . This information will then be transmitted by CySEC to the EBA for validation purposes. 📌 Key Takeaways for Compliance Teams For compliance officers in Cyprus-regulated entities (investment firms, UCITS, AIFs, non-financial counterparties), Circular C740 imposes urgent data submission requirements that must be prioritised to avoid regulatory gaps. Identify whether your entity exceeds EMIR initial margin thresholds. Prepare the required datasets and complete the CySEC/EBA templates. Submit all data to CySEC no later than 16 January 2026. Ensure readiness for the next phase: EBA validation of internal margin models. Deadline Regulated entities must submit their data to CySEC by 16 January 2026 , creating an immediate compliance priority for affected firms. Entities that fail to submit the required data will not be onboarded to the EBA validation system, effectively preventing them from applying for the EBA validation and thereby risking non-compliance with EMIR.

  • Loan-Originating AIFs vs Banks: Same Activity, Different Architecture in the Years Ahead

    In the coming years, loan-originating Alternative Investment Funds (LO-AIFs) will continue to expand their presence across the European credit landscape. Although banks and LO-AIFs will both engage in lending, they will do so under fundamentally different business models, funding structures and regulatory regimes. Understanding these distinctions will become increasingly important for policymakers, investors and market participants as private credit grows into a mainstream financing channel. 1. Business Purpose and Economic Function Banks will remain financial intermediaries serving the wider public. They will continue accepting deposits, safeguarding money, facilitating payments and extending credit that supports the real economy. Their role will remain systemic and central to financial stability. LO-AIFs, meanwhile, will operate as investment funds designed to generate returns for professional investors. They will raise committed capital and deploy it into private lending opportunities without performing any public-intermediation or monetary-system function. Key distinction: Banks will continue serving depositors and the payment system. LO-AIFs will continue serving investors seeking yield. 2. Funding, Liquidity and Redemption Dynamics Banks will keep relying on deposits, wholesale markets, central-bank liquidity and bond funding. Their liabilities will remain short term and payable on demand, meaning that liquidity and funding management will continue to be essential to their resilience. LO-AIFs will operate with committed capital and controlled redemption mechanisms. Investors will continue accepting illiquidity as part of the private-debt strategy. Because LO-AIFs will not take deposits or guarantee instant withdrawals, their liquidity risk will evolve differently from that of banks. Banks will face: deposit withdrawals payment-system liquidity obligations systemic liquidity shocks LO-AIFs will face: liquidity constraints linked to loan portfolios redemption pressures only where the fund is open-ended no systemic run risk 3. Regulatory Frameworks: Prudential vs Investment-Fund Supervision Banks will remain subject to CRR/CRD, Basel III requirements, leverage ratios, supervisory stress testing and resolution planning. These rules will continue to exist because banks will remain “public crisis points,” requiring strong prudential oversight. Under AIFMD II, LO-AIFs will operate under a regulatory framework focused on investor protection and sound fund governance, not systemic risk. Although LO-AIFs will incorporate bank-style credit processes, their oversight will continue reflecting their nature as investment products. The LO-AIF regime will include: leverage limits risk-retention rules lending prohibitions to connected persons enhanced underwriting standards liquidity and redemption governance stress testing for open-ended funds Banks and LO-AIFs will both lend, but the regulatory logic behind each model will remain fundamentally different. 4. Lending Behaviour and Market Focus Banks will continue prioritising standardised, collateralised and low-risk lending, driven by capital requirements and risk-weighted asset considerations. They will maintain strength in relationship banking, retail lending and senior secured credit. LO-AIFs will increasingly focus on specialised, higher-yielding private credit, such as: SME growth finance real-estate mezzanine and development loans infrastructure and project finance distressed and opportunistic credit sponsor-backed private-debt transactions This flexibility will allow LO-AIFs to serve segments where banks will remain constrained by prudential rules or slower credit processes. 5. Risk Profiles and Risk Transmission Banks will continue carrying composite risks — credit, liquidity, systemic and interest-rate mismatch risks. Bank distress will remain capable of transmitting shocks across the financial system due to their public-facing and deposit-taking role. LO-AIF risks will remain contained within a closed group of professional investors. Losses will continue being absorbed by the fund’s capital without affecting depositors or requiring public intervention. While open-ended LO-AIFs will still face liquidity-management challenges, these will be controlled through redemption gates, notice periods and liquidity-management tools. Crucially, LO-AIF failures will not generate systemic contagion in the way bank failures could. 6. Complementarity: A Dual Credit Ecosystem In future years, banks and LO-AIFs will increasingly operate in a complementary  manner rather than competing directly. Banks will: originate senior or low-risk loans that LO-AIFs could acquire or participate in partner with LO-AIFs in syndicated lending use LO-AIFs as an outlet for NPL disposals or balance-sheet optimisation refer borrowers requiring complex or flexible financing LO-AIFs will: provide credit where banks will remain limited by capital rules support SMEs, real estate, infrastructure and transitional finance offer speed and structural flexibility co-lend with banks in multi-layered financing packages The strongest credit markets will be those where both channels operate in parallel. Conclusion: Divergent Structures, Converging Roles Although banks and LO-AIFs will both lend, their functions, incentives and regulatory foundations will remain distinct. Banks will continue to anchor financial stability and public trust. LO-AIFs will increasingly channel institutional capital into specialised private-credit opportunities, without taking on systemic responsibilities. As AIFMD II is implemented, and as private credit continues to evolve, Europe’s financing landscape will likely transition toward a dual-track credit system: one supported by prudentially regulated banks, and one driven by flexible, investor-funded LO-AIFs. The goal will not be to force convergence but to ensure that each model operates within a framework that reflects its risks, responsibilities and contribution to the economy.

  • Regulatory Alert: AML Awareness: EU Adds Russia to “High-Risk Third Countries” List

    Source: European Commission Press Release IP/25/2910 Date: 03 December 2025 On 3 December 2025, the European Commission (the “Commission”) officially added Russia to its list of “high-risk third countries with strategic deficiencies” in their anti-money laundering and counter-terrorist financing (AML/CFT) frameworks. The addition follows a technical assessment mandated by Delegated Regulation (EU) 2025/1393, under the scope of the Fourth Anti‑Money Laundering Directive (4AMLD). The evaluation considered public sources, inputs from Member States’ authorities, and information from the European External Action Service (EEAS). As a result, all entities and financial institutions within the EU that fall under the AML framework are now required to apply “enhanced vigilance / enhanced due diligence (EDD)” when dealing with transactions involving Russia (or counterparties connected to Russia). Find the European Commission - Press release here : https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_25_2910/IP_25_2910_EN.pdf   Next steps: The delegated regulation will enter into force after scrutiny and non-objection of the European Parliament and the Council within a period of one month. This can be prolonged for another month. The Commission will monitor the progress of all listed countries and will continue to follow relevant developments. For more information Directive on anti-money laundering and terrorist funding (AMLD IV) Anti-Money Laundering Authority (AMLA) The Financial Action Taskforce (FATF)

  • Commission launches whistleblower tool for EU Artificial Intelligence Act (AI Act)

    The European Commission has launched today a new whistleblower tool designed to support enforcement of the AI Act. In brief: What is the new whistleblower tool The tool offers a secure and confidential channel  for individuals to report suspected breaches of the AI Act. Reports go directly to the European AI Office. Reports can be submitted in any official EU language , in any format , which aims to maximize accessibility for whistleblowers across the EU. The system uses certified encryption mechanisms  to guarantee confidentiality and data protection. Reporters remain anonymous, yet they can receive secure follow-up communications : updates on the progress of their report and the possibility to answer additional questions from the EI AI Office - all without compromising anonymity. Why this matters The AI Act aims to foster innovation and adoption of artificial intelligence across the EU, while at the same time safeguarding health, safety, fundamental rights, public trust, and the rule of law . Effective enforcement of the AI Act is key to ensuring compliance. The whistleblower tool empowers insiders , employees, collaborators, shareholders, or other stakeholders with knowledge about AI systems to report non-compliance early . This helps the EU AI Office detect and address risks before they escalate. With this tool, the Commission leverages transparency and accountability  as core mechanisms for AI governance, which is especially important in a regulatory environment where full oversight of complex AI systems is technically and practically challenging. Practical points & Current Limitations |Currently, the tool ensures confidentiality and anonymity , but statutory protection against retaliation  (e.g., from employers) under the general EU whistleblower rules -namely the Whistleblower Directive - will only apply to AI Act-related reports from 2 August 2026  onwards. Until then, protections remain based on Commission assurances. Despite those caveats, the tool represents a significant step forward . As noted by independent observers, early detection of AI-related risks (e.g. breaches of safety, privacy, non-discrimination) can meaningfully contribute to “safe, transparent and trustworthy” AI deployment across the EU.

  • The EU’s “Digital Omnibus on AI” - What it means for companies’ AI compliance roadmaps

    The European Commission has proposed the Digital Omnibus on AI , a legislative package designed to adjust and simplify the implementation of the EU AI Act . The goal is to give organisations more flexibility, align compliance deadlines with the availability of technical standards, and ease the burden on companies deploying AI in the EU. Key Changes at a Glance Flexible compliance deadlines: Instead of fixed dates, the obligations for high-risk AI systems would take effect only when the relevant EU standards or guidelines are published. If these are delayed, fallback deadlines will apply from late 2027 to mid-2028. Companies would also get short grace periods to complete compliance work. Transitional support for existing systems: Generative AI models and high-risk AI systems already on the market would benefit from additional time to adjust. “Legacy” high-risk systems can continue to be used or sold if their design remains unchanged. Reduced administrative load: Lower-risk AI systems would no longer need to be listed in the EU AI database. Providers must still conduct risk assessments, but only need to submit them on request. The proposal also broadens the ability to process sensitive data for bias-mitigation, subject to safeguards. More flexibility for GPAI and content-marking: The mandatory element for codes of practice on general-purpose AI and content provenance would be removed. These frameworks would stay as soft-law tools, not binding legal requirements. Support for SMEs and smaller mid-caps: The simplified regime available under the AI Act would be expanded, reducing documentation demands and lowering fines for qualifying companies. What This Means for Organisations Businesses should treat this proposal as an opportunity to recalibrate their AI compliance plans, not as an excuse to delay preparation. The Diogital Omnibus Directivemay offer extra time, but deadlines can still arrive early if EU standards are finalised sooner. Organisations should continue building strong AI governance, documentation and monitoring processes, especially if operating in regulated sectors like financial services. What’s Next? The Digital Omnibus Directive is still under negotiation and may change before adoption. If it is not finalised before August 2026, the original AI Act deadlines will remain in force. Organisations should therefore continue preparing proactively while monitoring legislative developments.

  • Regulatory Alert: CySEC Circular C736 – Key Observations on the Prudential Framework for CIFs

    On 24 October 2025, CySEC issued on 24.10.2025 a Circular  C736 – Key Observations on the Prudential Framework for CIFs , addressed to Cyprus Investment Firms (CIFs), highlighting a series of supervisory observations and recommendations regarding the implementation of the prudential framework under Law 165(I)/2021 (Investment Firms) and Regulation (EU) 2019/2033 (IFR). Why it matters The Circular underscores that CySEC has identified recurring issues in how CIFs apply key prudential rules. These findings reflect both reporting and governance weaknesses, and signal that supervisory scrutiny will increase. Failure to adjust may lead to remedial measures or sanctions. Main Observations In brief: Timely Submission of Prudential Reporting CySEC observed delays in the submission of required prudential reports via the XBRL portal, and the use of outdated templates. Firms are reminded to submit all required reports within deadlines and to check the CySEC and EBA websites for the latest templates. Ongoing Compliance with Prudential Requirements Some CIFs are found to be failing to meet prudential obligations under Articles 9, 11 and 43 of the IFR, and to notify CySEC when they identify deficiencies. CySEC emphasises a proactive approach: monitoring requirements continuously and implementing corrective measures without delay. c Data Consistency Across Reporting Sources Significant inconsistencies were identified between the data reported via XBRL and other sources such as audited financial statements, QST-CIF forms and management accounts. Issues relate to profit/loss figures, retained earnings, own funds, liquid assets and fixed overheads. For example, the figure for “Annual fixed overheads of the previous year after distribution of profits” in the templates must align with audited statements and remain unchanged until the next audit. Remuneration Policies (Class 2 CIFs) The circular finds that some Class 2 CIFs did not comply with requirements such as: at least 50% of variable remuneration being in instruments; at least 40% deferred over a three-to-five-year period; and alignment with Law 165(I)/2021 and the EBA’s guidance. Establishment of Risk & Remuneration Committees CySEC identified CIFs that did not establish required committees (per sections 22 and 27 of Law 165(I)/2021), had committees composed solely of executive directors, single-person committees or lacked gender balance in remuneration committees. Internal Governance and Conflicts of Interest The circular highlights cases where Class 2 CIFs failed to implement conflicts-of-interest policies in loans or other transactions with members of the management body or their related parties, contrary to Law 165(I)/2021 and EBA internal governance guidelines. Liquidity Requirements (Article 43 IFR) CIFs have misclassified certain items as “unencumbered short-term deposits at a credit institution” which do not  meet the definition of liquid assets under Article 43(1) IFR. Examples: funds held with Electronic Money Institutions (EMIs), Payment Service Providers (PSPs), client-fund buffers, or contributions to the Investors Compensation Fund. Prudential Consolidation Supervisory findings include failures in assessing group structures for the purposes of prudential consolidation under the IFR and the new Regulation (EU) 2024/1771. Key issues relate to wrongly identifying whether an entity is a financial institution, union parent investment firm, or correctly applying consolidation requirements after structural changes. Completion of Form 165-03 (Section C) CySEC found that some CIFs did not disclose modified audit opinions or include links to their Pillar III disclosures in Section C of Form 165-03. Next Steps & Supervisory Warning CySEC advises CIFs to undertake a comprehensive review  of their practices across reporting, governance and prudential frameworks to ensure full compliance with Law 165(I)/2021, the IFR, applicable delegated regulations and the EBA’s guidelines. CySEC also states that it will continue its monitoring and will apply appropriate measures , including administrative sanctions or other supervisory actions, in cases of non-compliance. Implications for CIFs For CIFs operating in Cyprus, Circular C736 signals that the regulatory focus is sharpening on prudential discipline and governance. Some practical implications to consider: Reviewing internal processes for timely and accurate XBRL/prudential reporting. Ensuring full alignment and documentation across audited accounts, management accounts and reporting templates. Verifying governance structures, committee operations and remuneration frameworks for compliance. Re-classifying assets/liabilities appropriately under IFR definitions (especially liquid assets). Assessing group structure and consolidation requirements whenever there are changes. Strengthening disclosure practices for audit opinions and Pillar III disclosures. CySEC’s Circular C736 sends a clear supervisory message: accuracy, governance alignment and prudential discipline are now under closer regulatory scrutiny. CIFs are expected to address identified weaknesses promptly and ensure full and ongoing compliance with IFR requirements.

  • ESMA Annual Work Programme 2026 – Overview & Forthcoming Updates You Should Know

    The European Securities and Markets Authority (ESMA) has released itshttps 2026 Annual Work Programme , outlining how it will deliver on its 2023–2028 Strategy and support the EU’s Savings and Investments Union (SIU) agenda. While the plan is broad, several core areas of focus stand out for 2026 — reviews, supervisory convergence, and upcoming regulatory changes that will shape the compliance agenda for EU financial institutions. Key Areas of Focus in 2026 Supervisory Reviews and Convergence Peer reviews will intensify across market abuse (MAR), MiFID II/MiFIR investor protection measures, and fund management risk practices (liquidity, leverage, valuation). Expect Common Supervisory Actions (CSAs) and mystery shopping exercises to test retail investor protection in practice. Direct supervision of credit rating agencies (CRAs), trade repositories (TRs), CCPs, and soon ESG rating providers will expand, reinforcing consistency across the EU. Retail Investor Protection Implementation of the Retail Investment Strategy (RIS) will accelerate, with ESMA focusing on product governance, cost transparency, and suitability. New investor trend monitoring tools and a stronger use of data analytics will guide supervisory priorities. Sustainable Finance & ESG ESMA will review sustainability disclosures to combat greenwashing and align with global reporting standards. New mandates: oversight of ESG rating providers and European Green Bond reviewers begins in 2026. Supervisory convergence on the use of transition finance and monitoring of sustainability claims will be a top priority. Digital & Data Transformation A major review of reporting regimes (MiFIR, EMIR, SFTR, AIFMD/UCITS) will be carried out to reduce overlaps and streamline data collection. Roll-out of the European Single Access Point (ESAP) and further deployment of the ESMA Data Platform will change how data is gathered, shared, and used by supervisors. Crypto-Assets and DLT The first MiCA reviews will kick off, with ESMA setting supervisory expectations on transparency, market abuse monitoring, and reporting. Development of a centralised EU crypto market surveillance system will strengthen oversight of this emerging market. Digital Operational Resilience (DORA) 2026 marks the first full year of joint ESA oversight  of critical ICT third-party providers. ESMA will embed DORA requirements into supervisory convergence, ensuring operational resilience frameworks are tested in practice. Upcoming Changes – What Market Participants Must Prepare For Retail Investment Strategy : stronger requirements on costs, disclosures, and suitability assessments. ESG Ratings & Green Bonds : new supervisory mandates mean higher scrutiny on methodologies, transparency, and independence. Reporting Simplification : expect consultations and technical standards aimed at reducing duplication across MiFIR, EMIR, SFTR, AIFMD/UCITS. Crypto under MiCA : new obligations for issuers, service providers, and trading venues, with direct ESMA involvement. DORA Implementation : oversight of ICT providers will create new expectations for firms’ resilience testing and vendor management. key Takeaway The 2026 ESMA programme is not just about continuity — it introduces new supervisory mandates, fresh peer reviews, and upcoming regulatory shifts that firms must prepare for.The emphasis on convergence, simplification, and sustainability makes 2026 a defining year for EU financial markets, with ESMA taking a stronger role in ensuring coherence, trust, and resilience across the system.

  • Regulatory Alert: CySEC Circular 731 - Annual DORA-Related Fees – What EU Financial Entities Must Know

    🧾 Key Provisions of Circular C731 Scope of Application The Circular applies to all financial entities authorised by CySEC that fall within the DORA framework, including but not limited to: CIFs, Crypto-Asset Service Providers, issuers of asset-referenced tokens (when Cyprus is the home Member State), CSDs, CCPs, trading venues, AIFMs, UCITS management companies, and crowdfunding service providers. Self-categorisation & Fee Calculation Entities must complete a form (fields 1.1 to 1.7) to self-categorise and compute their Annual ICT (information & communications technology) fee  for 2025. Accompanying the Form , the firm must submit: Excerpts from the most recent audited financial statements (turnover, balance sheet) Evidence of the number of employees Submission & Deadlines for 2025 The Form must be submitted via the CySEC Portal (or by email to accounts@cysec.gov.cy  for entities without portal access) by 31 October 2025 . The 2025 fee will be pro-rated: it applies to the period 15 August – 31 December 2025 . Payment to be made by 31 December 2025 . From 2026 onward: Self-categorisation to be submitted between 1–15 September. Fees must be paid by 30 November  of each year. 💶 Fee Bands & Additional Charges CySEC’s prior Directive (DI 73-2009-07) and accompanying policy statements outline annual subscription tiers (based on enterprise size) and extra fees for certain activities. (As you covered in your previous blog on the same topic). In particular: Annual subscription tiers  are divided by enterprise classification (micro, small, medium, large). Additional fee  of €20,000  is imposed for entities that carry out Threat-Led Penetration Testing (TLPT)  under DORA Article 26. These tiers and extra payments can materially affect your bottom line, especially for mid-sized or growing firms. 🛠️ Recommended Next Steps Assess whether your entity falls under DORA  — check scope and existing operations Perform categorisation exercise  (based on turnover, assets, staff) Gather supporting documents  — annual audited statements, employee numbers Prepare and submit the self-categorisation form  by 31 October 2025 Perform the relevant payment  (by 31 December 2025) Evaluate whether TLPT is required  under your DORA obligations

  • Regulatory Alert: CySEC Circular C729 – QST-MC Quarterly Statistics (Q3 2025 Submission)

    Date of Issue: 26 September 2025 Applies to: AIFMs (including Small AIFMs) UCITS Management Companies & Internally Managed UCITS Internally Managed AIFs (including AIFLNPs) Companies managing AIFLNPs 📌 Key Points Form to Submit Latest version of the form QST-MC Version 23 must be completed and submitted via the Transaction Reporting System (TRS). Applies also to entities authorised/appointed as External Managers even if they have not yet used their authorisation. Deadline Submission must be completed by 31 October 2025. CySEC emphasises strict adherence – no reminders will be sent. Validation & Confirmation Submissions are deemed successful only once a NO ERROR feedback file is received from TRS. Entities must review and correct any errors before digitally signing and re-submitting. Counting UCIs & Sub-Funds For reporting purposes, sub-funds count as separate UCIs. Example: 1 UCI with 3 sub-funds = report as 3 UCIs. Technical Notes Reporting must be in EUR (rounded to nearest unit). File naming: USERNAME_20250930_QST-MC.xlsx Only Excel 2007+ versions accepted. Validation tests in all sections (A–M) must show TRUE (green). Support & Queries Content-related queries  to: riskstatistics.fundmgrs@cysec.gov.cy  (by 24 October 2025). Technical queries  to: information.technology@cysec.gov.cy . ⚠️ Implications for Regulated Entities Non-compliance risk : Late or incorrect submission may trigger administrative penalties  under section 37(5) of the CySEC Law. Operational adjustments : Entities should ensure their reporting teams are aligned on the updated version (QST-MC v23) and validate files early to avoid last-minute technical issues. Governance note : Boards and senior management should be aware of the deadlines and internal readiness to prevent regulatory breaches. 🔗 Useful Links TRS User Manual – Digital Signature Guidance QST-MC Form v23 (CySEC Website)

  • The EU Data Act: Shaping Europe’s Data-Driven Future

    Introduction The EU Data Act (Regulation (EU) 2023/2854)  is a landmark regulation in the European Union’s digital agenda. It entered into force on 11 January 2024, and its provisions apply from 12 September 2025. As the second major legislative initiative of the EU Data Strategy (after the Data Governance Act), the Data Act creates a framework for fair access, use, and sharing of data across industries and Member States. According to the European Commission, the Data Act could add €270 billion to EU GDP by 2028, making it not only a regulatory framework but also a strategic economic driver. Objectives of the Data Act Empower users of connected products to access and control the data they generate.- Promote fairness in digital markets, particularly protecting SMEs from abusive practices. Facilitate B2B and B2C data sharing to fuel innovation. Enable public authorities to access data in exceptional circumstances. Support cloud portability and interoperability to reduce vendor lock-in.- Safeguard trade secrets, IP rights, and cybersecurity. Who is Affected? The Data Act is a horizontal regulation, cutting across industries rather than targeting one specific sector. It applies to: Manufacturers of connected devices (cars, wearables, appliances, industrial machines). Providers of digital services linked to connected products. Data holders and data recipients, including SMEs. Public sector bodies requesting data in exceptional circumstances. Cloud and edge service providers operating in the EU. This broad scope reflects the EU’s ambition to ensure that all actors in the data economy operate under fair and transparent rules. Key Provisions 1. User Access to Data from Connected Devices Users of connected products have the right to access and use the data they generate. Manufacturers must ensure such data is available free of charge, easily, and in real time where feasible. Third parties, such as repairers or aftermarket providers, can also access this data with the user’s consent. 2. Fairness in Data Contracts The Act prevents large companies from imposing unfair contractual terms on SMEs. Any unilaterally imposed clause that grossly deviates from good commercial practice is invalid. The European Commission provides model contract clauses to support SMEs. 3. Public Sector Access in Exceptional Need Public authorities may request data in emergencies (e.g., natural disasters, pandemics). Requests must be necessary, proportionate, and fair. Compensation is due except in genuine emergencies, when data must be provided free of charge. 4. Cloud Switching and Interoperability Customers of cloud services have a legal right to switch providers. Providers must remove technical and contractual barriers to switching. The EU is also developing interoperability standards to enable seamless transfer of data and applications. 5. Safeguards for Trade Secrets, IP, and Security Data sharing must respect trade secrets and intellectual property rights. Confidentiality agreements and technical safeguards are required, and cybersecurity must not be compromised. Enforcement and Penalties Each Member State designates competent authorities to supervise compliance. Penalties must be effective, proportionate, and dissuasive. Dispute resolution mechanisms are foreseen, particularly for contractual disagreements. Business Implications Manufacturers & IoT Providers → Must adapt products and contracts. SMEs → Gain protection from unfair terms and more access to data. Cloud Providers → Must enable switching and prepare for interoperability standards. Public Authorities → Gain a legal basis for emergency data requests. Timeline 11 January 2024 → Regulation entered into force. 12 September 2025 → Provisions apply across all EU Member States. Cloud switching obligations → Phased until 2027. Conclusion The EU Data Act is a transformative step in Europe’s digital economy. It empowers individuals, protects SMEs, supports public interest, and promotes fair competition. Businesses should now: Map data flows and assess accessibility. Review contracts for compliance. Prepare for cloud switching requests. Strengthen safeguards for IP and cybersecurity. Those who act early not only comply but also gain a competitive edge in Europe’s new data-driven landscape.

bottom of page