Skip to main content
News

MFSA Cyber Reporting Updates: What Financial Entities Need to Know

By October 1, 2026No Comments

The Malta Financial Services Authority (MFSA) has issued two circulars, both aimed at financial entities in scope of the Digital Operational Resilience Act (Regulation (EU) 2022/2554). The first, Cyber Reporting Updates (published 30 September 2026), announces new FAQs, enhancements to the Cyber Reporting Management System (CRMS) and revised guidance documents. The second, The Supervisory ICT Risk and Cybersecurity (‘SIRC’) Function’s Webpage and Key Updates (published 1 October 2026), reminds financial entities to the SIRC webpage as the central source for updates on authorisation and supervisory expectations.

The Cyber Reporting Updates circular

This circular references the MFSA’s January 2025 CRMS circular, recalling the three DORA cyber-reporting obligations for Authorised Persons in scope under Article 2 of DORA: mandatory reporting of major ICT-related incidents, voluntary notification of significant cyber threats, and mandatory notification of joining or leaving information-sharing arrangements.

New FAQs. The MFSA has published a separate set of FAQs for each of the three reporting areas.

CRMS enhancements. The CRMS, accessed through the Licence Holder (LH) Portal, will have the following four enhancements:

  • A reclassification function, allowing an incident first reported as major to be reclassified as non-major, in line with Article 5 of Commission Implementing Regulation (EU) 2025/302. It replaces the current withdrawal function, which will be removed.
  • Submission controls that do not allow access and submission until the required reporting steps are completed.
  • Better user access management, including the ability to view incidents submitted by or on behalf of the same Authorised Person.
  • General usability improvements and minor portal adjustments.

Supporting documentation. The MFSA has published illustrative examples of a major ICT-related incident report, a significant cyber threat notification and an information-sharing arrangement notification. 

The SIRC webpage circular

The second circular reminds financial entities that the MFSA’s SIRC Function maintains a dedicated webpage. It covers the digital operational resilience legal framework, the three cyber-reporting areas, Threat-Led Penetration Testing (TLPT) and ICT third-party risk management, including the Register of Information (RoI).

The page is also the central point for SIRC guidance on authorisation and supervisory expectations, such as Dear CEO letters, circulars, user guides and FAQs.