**CySEC Issues Deadline Reminder for DORA Compliance Among Financial Entities**
The Cyprus Securities and Exchange Commission (CySEC) has issued a reminder to financial entities under its regulation regarding the submission of a crucial form required for compliance with the European Union's Digital Operational Resilience Act (DORA). Entities have until today, September 15, to submit the necessary documentation through CySEC's online portal.
This announcement follows an earlier communication from CySEC on August 26, which emphasized the importance of submitting a self-categorization form as part of the process to calculate the annual information and communication technology (ICT) fee mandated by DORA. The requirements are outlined in CySEC Directive DIR73-2009-07 and Policy Statement PS-03-2025, which detail the fees applicable to financial entities within the scope of DORA.
To comply, financial entities must accurately complete specific sections of the prescribed form, particularly fields 1.1 to 1.8, which pertain to their self-categorization and fee calculation. The form must be duly signed and submitted alongside supporting documentation, which includes extracts from the entity's most recent audited financial statements. These extracts should illustrate the entity's annual total turnover and balance sheet for the relevant year. Additionally, entities are required to provide confirmation of their employee count, either through their audited financial statements or a signed letter from an independent auditor.
The information collected through this process is essential for determining the applicable annual ICT fee under the DORA framework. Once the form is submitted, CySEC will issue an invoice to the financial entity via email. Entities are expected to settle this invoice promptly upon receipt and no later than November 30, 2026.
DORA represents a significant regulatory framework aimed at enhancing the digital operational resilience of the financial sector across the EU. It establishes requirements for managing information and communication technology risks and disruptions, ensuring that financial entities are equipped with the necessary systems and procedures to effectively withstand, respond to, and recover from technology-related challenges.
As the financial sector in Cyprus becomes increasingly reliant on technology, compliance with DORA's requirements introduces an additional layer of regulatory obligation for firms. Financial entities that fail to submit the required form by the September 15 deadline will face a subsequent deadline of September 15, 2026, for compliance, with any resulting invoices needing to be settled by the November 30 deadline.
CySEC's reminder serves as a critical prompt for financial entities to ensure they meet the regulatory obligations set forth by DORA, thereby contributing to the overall stability and resilience of the financial sector in Cyprus.