Add Fazzaco to desktop

Add Fazzaco to desktop

Access Fazzaco from desktop next time

Add now
English

EU Regulators Advance Third-Party ICT Oversight Under DORA and Reiterate Crypto Warnings

Source: David Tareq Sikder

b225381f9b8df0bb8c3f7b80d84a29e.jpeg

EU supervisory authorities have highlighted cyber resilience, crypto risks, and regulatory simplification in their 2025 annual report. The report maintains indirect relevance for retail trading and CFD markets through its focus on consumer protection, crypto-asset risks, and PRIIPs rules. It does not introduce new CFD or leveraged trading measures but continues to emphasize disclosure standards, fraud prevention, and supervisory convergence across EU retail markets.

The Joint Committee of the European Supervisory Authorities maintained a central coordinating role in 2025, focusing on EU-wide supervisory coordination. A key focus was the Digital Operational Resilience Act (DORA), for which the ESAs delivered all required legal instruments and guidance ahead of its January 2025 application date. They also designated 19 critical third-party ICT providers between April and November 2025.

New cyber coordination tools were introduced, including the Cyber Incident Information Sharing and Threat Intelligence Exchange (CITE). The committee also supported EU efforts to simplify financial rules, including work on PRIIPs Key Information Documents and SFDR reporting adjustments, while cautioning that simplification must not weaken financial stability or consumer protection.

In its risk assessment, the ESAs stated that geopolitical tensions and global conflicts increased uncertainty and market volatility. They warned institutions to strengthen risk management and cyber resilience. The report flagged specific risks from cyber threats, ICT third-party concentration, and digital assets, highlighting limited legal protections for crypto-assets depending on their type.

Consumer protection remained a priority, with the ESAs updating PRIIPs guidance and reporting 12 administrative sanctions across four member states. They also issued warnings on crypto fraud and AI-driven scams. Other initiatives included ESAP development, AMLA cooperation, and Big Tech monitoring. The ESAs concluded that geopolitical risks, cyber threats, and structural market shifts remain key financial stability concerns.

Create Company Page