On 30 September 2026, the Malta Financial Services Authority (MFSA) issued a circular announcing a number of updates to its cyber reporting framework under the Digital Operational Resilience Act (DORA). The updates cover the Cyber Reporting Management System (CRMS), new FAQs and supporting documentation intended to help Authorised Persons meet their reporting obligations.
The circular applies to Authorised Persons within the scope of Article 2 of DORA and addresses the following three cyber-reporting areas:
- Major ICT-related incident reporting;
- Voluntary notification of significant cyber threats; and
- Notification of participation in, or cessation of membership of, information-sharing arrangements.
What is changing?
The MFSA is introducing several enhancements to the CRMS within the Licence Holder Portal, including:
- A new reclassification functionality, allowing incidents initially reported as major to be reclassified as non-major in accordance with Article 5 of Commission Implementing Regulation (EU) 2025/302. This will replace the existing withdrawal functionality.
- Submission controls preventing access to subsequent reporting stages until preceding steps have been completed.
- Enhanced user access management, including the ability to view incidents submitted by, or on behalf of, the same Authorised Person.
- Other system and portal enhancements intended to improve usability.
The MFSA has also released FAQs covering all three cyber-reporting areas, together with illustrative examples. Further updates to reporting processes and user guidelines are also being made available through the MFSA website.
What should regulated entities consider?
In light of the circular, Authorised Persons should consider:
- Verifying access to the CRMS Project within the MFSA Licence Holder Portal, which the MFSA expressly expects Authorised Persons to have in place.
- Reviewing the newly issued FAQs and illustrative examples against existing incident reporting procedures.
- Ensuring relevant operational teams are aware of the changes to the CRMS workflow, particularly the new reclassification functionality and sequential submission controls.
- Reviewing internal incident management and escalation arrangements to ensure regulatory notifications can continue to be made within the applicable DORA reporting timelines.
The MFSA specifically highlights that failure to submit the required notifications and reports within the applicable timelines may result in regulatory action under S.L. 330.20 and the MFSA Act.
How BDO can help
BDO Malta's Technology Advisory & Assurance team can help regulated entities review their DORA ICT incident management and regulatory reporting arrangements, including readiness assessments, incident classification and escalation processes, and alignment of internal procedures with the updated MFSA reporting framework.
For further information or assistance, please contact our Technology Advisory & Assurance team.
For further information or assistance, please contact our Technology Advisory & Assurance team.

