The Cyprus Securities and Exchange Commission (CySEC) on Friday published a consultation paper setting out plans for financial entities regulated under DORA to pay an annual ICT oversight fee and undertake enhanced cyber security tests.

According to the commission, certain entities within the scope of the EU Digital Operational Resilience Act (DORA) will be required to perform a Thread Lead Penetration Test or TLPT, “testing their resilience against ever-evolving cyber threats”.

It added that “the proposals include the payment of an annual ICT oversight fee and a fee for the TLPT assessment“.

The deadline for responses to the consultation paper is March 7, 2025.

“The proposal impacts Cyprus investment firms, crypto-asset service providers, central securities depositories, AIF managers, management companies, crowdfunding services providers and others authorised by CySEC that fall under the DORA Regulation,” CySEC said.

“Depending on the entities’ categorisation under the DORA Regulation, annual ICT oversight fees range from €3,000 for microenterprises to €20,000 for large financial entities authorised by CySEC,” it added.

Moreover, CySEC said that “entities subject to a TLPT requirement will be required to pay €50,000 for the assessment of their TLPT test under the proposals”.

Additionally, the commission pointed out that “financial entities will be required to submit a self-categorisation in September each year, based on their most recent financial statement”.

The first ICT oversight fee would be paid in 2025.

DORA is much more than just a compliance requirement; it’s a pathway to financial market resilience,” said CySEC chairman George Theocharides.

“By implementing DORA’s cybersecurity protocols, resilience testing, incident reporting, and third-party risk management, financial institutions can build a culture of proactive risk management,” he added.

“Ultimately”, he continued, “DORA will strengthen the entire financial ecosystem and protect financial entities and their clients against ever-evolving cyber threats.”

Finally, the announcement stated that “market participants and investors are invited to return their responses to the proposed changes in CySEC’s policy by email to [email protected]“.