CySEC Circular C799: yearly DORA report on the costs and losses of major ICT incidents
Cyprus Securities and Exchange Commission (CySEC)Circular C799Issued
By the ExamPass CY editorial teamPublished
- DORA and ICT risk
- Reporting
Short answer
CySEC Circular C799 of 8 September 2026 asks CIFs and other entities it supervises under DORA that had major ICT-related incidents to report their aggregated annual costs and losses, estimated under the ESAs' Joint Guidelines (JC 2024 34) and their template. Reports go through the CySEC Portal by 30 June after each reference year. The first report, covering 2025, was due by 30 September 2026, a date that has now passed. For firms reporting on calendar years, the next is due by 30 June 2027.
At a glance
- What changes
- CySEC asks for a yearly report, through its Portal, of the gross costs and losses and the financial recoveries of major ICT-related incidents, estimated with the ESAs' Joint Guidelines and template.
- Who is affected
- CIFs, crypto-asset service providers, certain issuers of asset-referenced tokens, CSDs, CCPs, trading venues, AIFMs, management companies and crowdfunding service providers supervised by CySEC. Under DORA, microenterprises do not have to report these estimates.
- Cyprus investment firms (CIFs)
- Crypto-asset service providers and certain issuers of asset-referenced tokens
- AIFMs and management companies
- Central securities depositories, central counterparties, trading venues and crowdfunding service providers
- ICT risk, finance and compliance staff who prepare DORA incident reports
- What to do
- If you had major ICT-related incidents in 2025, check that the report was filed; fix and record your reference-year basis and keep a per-incident record of costs, losses and recoveries linked to your final incident reports.
- By when
- 30 June 2027 for a 2026 calendar reference year; the first deadline, 30 September 2026, has passed
What does CySEC Circular C799 require?
CySEC issued Circular C799 on 8 September 2026. We have not read the circular itself; according to published summaries and a press report, it is addressed to CIFs, crypto-asset service providers, certain issuers of asset-referenced tokens, central securities depositories, central counterparties, trading venues, AIFMs, management companies and crowdfunding service providers. It asks them to estimate and report to CySEC the aggregated annual costs and losses of their major ICT-related incidents, following the ESAs' Joint Guidelines and their template.
Reports are submitted only through the CySEC Portal, under the title 'Estimation of Aggregated Annual Costs and Losses Caused by Major ICT-Related Incidents', by 30 June following the reference year. For 2025 there was a special deadline of 30 September 2026. That date has passed, so firms in scope should check that their report was filed. For a firm that reports on calendar years, the report for 2026 is due by 30 June 2027.
The duty comes from Article 11(10) of DORA (Regulation (EU) 2022/2554): financial entities other than microenterprises must report to their competent authority, on its request, an estimate of the aggregated annual costs and losses caused by major ICT-related incidents. Article 11(11) asked the ESAs (EBA, EIOPA and ESMA) to issue common guidelines on the estimate. They published them on 17 July 2024 (JC 2024 34), and the guidelines apply from 19 May 2025. ESMA's compliance table, updated on 27 August 2026, records that CySEC complies or intends to comply: its Board decided on 5 May 2025 to adopt the guidelines once CySEC was designated as a competent authority under DORA, and that designation has since been completed.
Which incidents and costs go into the estimate?
Each firm chooses its reference year: either the completed calendar year or its completed accounting year for which the financial statements have been finalised. Once chosen, the same basis is used for later estimates; a firm may switch by notifying the competent authority, provided the authority does not object within two months. Costs and losses of incidents that fall before or after the reference year are left out.
The estimate includes every ICT-related incident classified as major under Delegated Regulation (EU) 2024/1772 for which the firm submitted its final incident report under Article 19(4)(c) of DORA in the reference year. It also includes incidents whose final report was submitted in an earlier year but which had a quantifiable financial impact in the reference year. Costs and losses of incidents that were not major are outside the guidelines.
For each incident the firm first estimates the gross costs and losses, using the types listed in Article 7 of Delegated Regulation (EU) 2024/1772: expropriated funds or financial assets, including theft; replacing or relocating software, hardware or infrastructure; staff costs; fees for breaching contracts; redress and compensation to customers; forgone revenues; communication costs; and advisory costs such as legal, forensic and remediation services. Day-to-day costs, such as general maintenance, improvements made after the incident and insurance premiums, are excluded. The firm then estimates the financial recoveries for each incident, as specified in Annex II to Implementing Regulation (EU) 2025/302, and aggregates both figures across incidents. Only gross figures are requested: the ESAs dropped net figures because supervisors can calculate them.
How should the figures be prepared and reported?
The starting point is the costs, losses and recoveries shown in the financial statements of the reference year, such as the profit and loss account, or in supervisory reporting where it applies. Accounting provisions in the financial statements are included. Where accurate data is not available, firms estimate from other available data. Adjustments to an estimate submitted for an earlier year are included in the year in which they are made.
The template in the Annex to the guidelines asks for the firm's name, its Legal Entity Identifier, the start and end dates of its reference year and the currency. It then has one line for each major incident: the date the final incident report was submitted, the incident reference number (the same code as in the final report), and the gross costs and losses and the recoveries in the reference year, in thousands of units, with totals for the year. The breakdown by incident supports the aggregate figures.
In practice, this works best when the incident register and the finance records use the same incident codes and agree on which costs count. According to the same published summaries and press report, only firms that had major ICT-related incidents in the reporting period need to submit the report. For background on how DORA fits into firms' organisational requirements, see our study note on organisational requirements.
In the official wording
“Where accurate data is not available, financial entities should base their estimation on other available data and information to the extent possible.”
When does it apply?
Applies now
- Article 11(10) of DORA, which has applied since 17 January 2025: financial entities other than microenterprises must report to their competent authority, on request, an estimate of the aggregated annual costs and losses of major ICT-related incidents.
- The ESAs' Joint Guidelines JC 2024 34, which apply from 19 May 2025; ESMA's compliance table lists CySEC as complying or intending to comply.
- Circular C799: reports through the CySEC Portal by 30 June following the reference year; the first report, for 2025, was due by 30 September 2026.
Applies later
- Report through the CySEC Portal for a 2026 calendar reference year, by firms that had major ICT-related incidents in that year.
What to do
- If you had major ICT-related incidents in 2025, check that the report for the 2025 reference year was submitted through the CySEC Portal; the special deadline was 30 September 2026.By
- Decide whether to report on a calendar-year or accounting-year basis, record the decision and apply it consistently.No fixed deadline
- For each major ICT-related incident, record the gross costs and losses and the financial recoveries by reference year, using the incident reference code from the final report.No fixed deadline
- Reconcile the figures with the profit and loss account or supervisory reporting, including provisions and adjustments to earlier estimates.No fixed deadline
- If you had major ICT-related incidents in a 2026 calendar reference year, submit the report through the CySEC Portal.By
In the exam
DORA's ICT risk rules sit within the organisational requirements for investment firms, alongside business continuity and the outsourcing of critical functions, in the CySEC Advanced and Basic exams.
Related study notes
Preparing for an exam?
Practise the topics behind this update
Exam-style questions with a hint before you answer and a full explanation after, chapter by chapter.
- CySEC AdvancedSee the CySEC Advanced packsTry the free demo
- CySEC BasicSee the CySEC Basic packsTry the free demo
Sources
- Circular C799: Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (opens in a new tab)
CySECOfficial text
- Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34), Final Report (opens in a new tab)
European Supervisory Authorities (EBA, EIOPA, ESMA)Official text
- Joint Guidelines on estimation of aggregated annual costs and losses caused by major ICT-related incidents (EBA page: status, application date, translations) (opens in a new tab)
EBAOfficial text
- Guidelines compliance table: Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents (ESMA75-1012365701-566) (opens in a new tab)
ESMAOfficial text
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), Article 11(10) and (11) (opens in a new tab)
EUR-LexOfficial text
- Commission Delegated Regulation (EU) 2024/1772 on the classification of ICT-related incidents and cyber threats (Article 7: economic impact) (opens in a new tab)
EUR-LexOfficial text
- Cyprus financial firms face new cyber incident reporting rules (opens in a new tab)
Cyprus MailCommentary
Summary prepared by the ExamPass CY editorial team; it is not the official text. Quotations are reproduced from the source for the purpose of reporting and review.
This document has been drafted using material downloaded from ESMA's website. ESMA does not endorse this publication and in no way is liable for copyright or other intellectual property rights infringements nor for any damages caused to third parties through this publication.
© European Union, https://eur-lex.europa.eu. EU material is reused with credit and has been summarised; only the Official Journal of the European Union is authentic.