CPMI-IOSCO Cyber Resilience Toolkit: What FMIs Should Review

On 8 September 2026, the Committee on Payments and Market Infrastructures (CPMI) and the International Organization of Securities Commissions (IOSCO) published the CPMI-IOSCO cyber resilience toolkit for public comment. It sets out four voluntary tools and asks central counterparties, central securities depositories, securities settlement systems, payment systems and trade repositories to look hard at how they govern cyber risk, build attack scenarios, plan recovery and run tests. Comments are due by 1 December 2026.

The full title is Cyber resilience toolkit: practical considerations for FMIs, and the word practical is doing real work. The toolkit sits under the 2012 Principles for financial market infrastructures (PFMI) and the 2016 CPMI-IOSCO Guidance on cyber resilience for financial market infrastructures, and it adds no new standard of its own. Its job is to give board members, senior management and the people who run cyber and operational risk a set of concrete considerations they can hold up against their own frameworks.

For a reporting or resilience team inside an FMI, the near-term question is narrow: read the four tools, decide whether anything in them exposes a gap in your current cyber resilience framework, and decide whether to send comments before the window closes. This is a consultation on voluntary material, so 1 December is a comment deadline, not a filing date. It still deserves calendar space, because the final version will reflect what the industry says now.

Related reading: our guide to DORA threat-led penetration testing.

A voluntary cyber resilience toolkit, anchored in the PFMI

The PFMI, published in April 2012, set 24 principles for the design and operation of FMIs and five responsibilities for the authorities that oversee them. In 2016, CPMI-IOSCO added the Cyber Guidance to enhance FMIs’ cyber resilience in the context of five of those principles: governance (Principle 2), the comprehensive management of risks (Principle 3), settlement finality (Principle 8), operational risk (Principle 17) and FMI links (Principle 20). The new toolkit leaves all of that in place, and simply adds supplemental detail on the preparations and measures an FMI might undertake to strengthen the same framework.

The toolkit itself is explicit about its limits, and this is the first thing to get straight internally. It is a set of voluntary, non-binding tools, technology-neutral in design. The practical considerations are voluntary, non-binding and non-exhaustive, and are not intended to impose additional standards on FMIs beyond those set out in the PFMI as informed by the Cyber Guidance. Reading it as a checklist your supervisor will grade you against would be a misread of what CPMI-IOSCO actually built.

The dates worth putting on the wall are short:

  • 8 September 2026: the toolkit and a related discussion paper are published for consultation.
  • 1 December 2026: deadline for comments, sent by email to the CPMI Secretariat (cpmi@bis.org) and the IOSCO Secretariat (cpmi-iosco@iosco.org).
  • After the consultation: CPMI-IOSCO will publish a final version of the report, taking the comments received into account.

Responses will be published on the BIS and IOSCO websites unless a respondent asks otherwise, and sensitive or commercial information should be left out or clearly marked for redaction.

Why the timing: the 2022 Level 3 findings

The toolkit did not appear in a vacuum. Its direct parent is the 2022 CPMI-IOSCO Implementation monitoring of the PFMI: Level 3 assessment on financial market infrastructures’ cyber resilience, which looked at the state of cyber resilience at 37 FMIs across 29 jurisdictions, as of February 2021. That assessment found reasonably high adoption of the 2016 Cyber Guidance overall, then flagged where practice was thin.

The Level 3 assessment raised one serious issue of concern and four issues of concern. The serious issue was that a small number of FMIs had not developed cyber response and recovery plans capable of meeting the two-hour recovery time objective. The four additional issues concerned established plans that could not meet the 2hRTO under extreme cyber-attack scenarios, insufficient testing after significant system changes, a lack of comprehensive scenario-based testing, and inadequate involvement of participants, critical service providers and linked FMIs in testing response, resumption and recovery plans.

CPMI-IOSCO says the toolkit was informed by the Level 3 assessment’s findings. The four tools cover areas that appear across the assessment’s issues of concern and observations: governance and metrics, scenario design, response and recovery planning, and testing and exercising. If your own last cyber assessment surfaced any of those themes, the matching tool is where to start.

Which infrastructures the toolkit is written for

FMI is a precise term here, and widening it is a common error. The PFMI, and therefore the toolkit, apply to systemically important payment systems, central securities depositories, securities settlement systems, central counterparties and trade repositories. A bank, investment firm or fund administrator is not an FMI merely because of its institutional type. Under the PFMI, an FMI is a multilateral system, including its operator, used for clearing, settling or recording financial transactions, and an FMI may be organised as a specialised banking organisation or as part of another legal entity. The intended audience is FMI board members, non-board senior management and staff with operational and cyber risk and resilience responsibilities, together with the authorities that oversee them.

The toolkit is meant to be used with due regard to an FMI’s risk profile and the scale, complexity and nature of its activity. A large multi-currency CCP and a domestic retail payment system will not read the same tool the same way, and CPMI-IOSCO says as much: the four tools can be used individually or in combination, depending on an FMI’s specific needs and priorities. A trade repository worried about data integrity might live mostly in the response and recovery tool, while a CSD mid-migration might care most about testing around system change.

One framing runs through every tool: the ecosystem. CPMI-IOSCO treats an FMI as digitally connected to participants, linked FMIs, internal and third-party service providers, vendors and critical infrastructures, and it asks FMIs to look at cyber risk in both directions, the risk they inherit and the risk they pass on.

Tool 1: governance, board cyber skills and maturity models

Tool 1 targets the governance of an FMI’s cyber resilience framework, which the Cyber Guidance defines as the policies, procedures and controls an FMI has to identify, protect against, detect, respond to and recover from cyber risks. The practical considerations fall into a few groups: appraising the board’s collective cyber skills and its training programme, managing risks that arise from the ecosystem, and using maturity models and metrics to gauge whether the framework is actually working.

Tool 1 addresses governance of cyber risk and resilience, including roles and responsibilities, maturity models and metrics for measuring resilience. CPMI-IOSCO presents these as practical considerations that may assist FMIs in strengthening the governance of their cyber resilience frameworks.

Tool 2: extreme but plausible scenarios

Tool 2 is about building the scenarios an FMI tests itself against. The phrase extreme but plausible has a long history in the PFMI world, where it usually describes the stress conditions a CCP must cover for credit and liquidity risk. Here it is applied to cyber, and the tool sets out a blueprint for constructing scenarios using a risk-based approach, plus considerations for testing and updating them over time.

CPMI-IOSCO describes Tool 2 as providing potential strategies and methodologies for constructing extreme but plausible scenarios using a risk-based approach. The toolkit as a whole is intended to be used with due consideration to an FMI’s risk profile and the scale, complexity and nature of its activity.

The reason scenario quality matters so much is that everything downstream depends on it. A recovery plan tested only against a tidy, single-system outage tells you very little about a data-integrity attack that has quietly corrupted records across the ecosystem. That gap between comfortable scenarios and plausible ones was one of the testing concerns in 2022.

Tool 3: response, resumption and the two-hour objective

Tool 3 carries the most operational weight, and it is where the two-hour objective lives. The Cyber Guidance set the expectation that an FMI’s critical IT systems should be able to resume operations within two hours of a disruption, even under extreme but plausible scenarios. Tool 3 helps FMIs work backwards from that: identify the critical operations and information assets needed to resume within two hours, design the key elements of response, resumption and recovery plans, and put in place infrastructure and data resilience measures that support safe and rapid recovery.

Tool 3 includes practical considerations for identifying critical operations, designing key elements of response, resumption and recovery plans, and handling disconnection and reconnection processes.

Tool 4: testing and exercising, from tabletop to red team

Tool 4 addresses how an FMI proves its framework works. CPMI-IOSCO says Tool 4 covers categories of cyber resilience testing, tailoring test programmes to an FMI’s requirements, conducting red team testing, and learning and evolving from testing and exercising. The 2022 assessment specifically identified a lack of cyber resilience testing after significant system changes as an issue of concern.

For FMIs that already sit inside a supervisory testing framework, the value of Tool 4 is in the connective tissue: the post-change testing habit, the involvement of participants and service providers in exercises, and the feedback loop from findings back into the framework. Those were precisely the gaps the Level 3 assessment named.

The ecosystem lens and the AI overlay

Two themes cut across all four tools. The first is the ecosystem. CPMI-IOSCO asks FMIs to consider the bidirectional interdependencies in every part of their cyber resilience framework, because a vulnerability in a participant, a linked FMI or a third-party provider can become a channel for contagion with cascading effects. Each tool therefore carries its own ecosystem considerations, from ecosystem risk in the governance strategy to disconnection and reconnection in recovery planning.

The second theme is AI. CPMI-IOSCO says recent developments in AI models require firms to consider adapting their defences to the speed, volume and complexity of AI-driven threats, and the toolkit includes AI risks as an overarching element across the four tools.

The ecosystem theme also explains the companion publication. Alongside the toolkit, CPMI-IOSCO put out a discussion paper, FMIs’ reliance on third-party service providers: challenges and risks, on the same 1 December timeline. It is anchored in PFMI Principle 17 on operational risk and Annex F on oversight expectations for critical service providers, and it sets out six categories of challenge: growing ecosystem complexity, concentration among providers, opaque supply chains, exit-planning difficulty, imbalances in bargaining power, and variation in regulatory expectations across jurisdictions. If third-party concentration keeps your risk committee awake, that paper is the one to read next to Tool 3. It draws on wider work including the Basel Committee’s principles for the sound management of third-party risk.

Where the toolkit meets DORA and other binding regimes

DORA is binding EU law, but it does not apply to every FMI merely because it is an FMI. Article 2 expressly includes central securities depositories, central counterparties and trade repositories; payment-system operators and securities settlement systems are not listed as FMI categories, although an operator may fall within DORA if it is separately a financial entity covered by Article 2. DORA carries obligations the toolkit does not, including ICT-related incident reporting and a register of information for ICT third-party arrangements. Advanced testing by means of threat-led penetration testing applies only to financial entities identified by competent authorities under DORA Article 26, rather than to every financial entity within DORA’s Article 2 scope. UK requirements vary by FMI type: the Bank of England regulates recognised UK CCPs, CSDs and recognised payment-system operators, while the FCA registers and supervises trade repositories. Other jurisdictions run their own regimes.

The toolkit does not replace any of that, and adopting it does not discharge a DORA or UK obligation. What it offers a firm already deep in DORA is a common international reference point. A CCP that has stood up DORA testing can use Tool 4 to sanity-check the programme against a global peer view, and use Tool 3’s practical considerations to test whether its two-hour thinking holds. For a group spanning several jurisdictions, the toolkit is a way to talk about cyber resilience in one language across entities that each answer to a different rulebook. The relationship with regional testing regimes is worth watching in the responses, because that is where firms are most likely to ask for alignment. Our coverage of DORA’s threat-led penetration testing regime sets out how the EU version already works in practice.

Responding to the consultation before 1 December

Comments go by email to both secretariats, at cpmi@bis.org and cpmi-iosco@iosco.org, by 1 December 2026. A response does not have to be a line-by-line commentary. Questions worth considering: whether the practical considerations work for an FMI of your type and size; where they conflict with a binding regime you already follow; and what the four tools should cover but do not.

Because CPMI-IOSCO will publish a final version after the consultation, the wording remains open to change in light of the comments received. An FMI that wants Tool 4 to acknowledge existing threat-led testing regimes, or Tool 3 to say more about data-integrity recovery, has a direct channel to say so. Two practical notes: responses are published unless you request otherwise, and commercial or personal detail should be kept out or clearly marked for redaction.

Frequently Asked Questions

Is the toolkit legally binding, and does using it prove we observe the PFMI?

No on both counts. The toolkit is a set of voluntary, non-binding tools, and CPMI-IOSCO states that its practical considerations are not intended to impose additional standards on FMIs beyond those set out in the PFMI as informed by the Cyber Guidance. Any binding obligation depends on the applicable legal or regulatory framework through which the relevant authority implements or applies the PFMI; the toolkit is supplemental to the PFMI and Cyber Guidance.

Do we have to submit a comment by 1 December 2026?

No. The consultation invites comment but does not compel it. If you do respond, send it by email to cpmi@bis.org and cpmi-iosco@iosco.org by 1 December 2026. Your response will be published on the BIS and IOSCO websites unless you ask for confidentiality, so keep sensitive material out or flag it for redaction.

Does the toolkit change our DORA obligations or replace threat-led penetration testing under DORA?

No. DORA remains binding EU law with its own testing, incident-reporting and third-party register requirements. The toolkit is a voluntary international reference that can complement a DORA programme, but adopting it does not satisfy or alter any DORA obligation.

How does the two-hour resumption objective interact with resuming safely?

The two-hour objective, from the 2016 Cyber Guidance, is that critical IT systems should be able to resume within two hours of a disruption even under an extreme but plausible scenario. Tool 3 sets out considerations for identifying critical operations and designing response, resumption and recovery plans, including disconnection and reconnection processes, so the balance between speed and safety is a planned decision.

We are a trade repository, not a CCP. Is any of this relevant to us?

Yes. The PFMI and the toolkit apply to all FMI types, including trade repositories, central securities depositories, securities settlement systems and systemically important payment systems. The toolkit is meant to be used in proportion to your risk profile, scale and complexity, and the four tools can be used individually, so a trade repository can focus on the tools that fit its threat picture.

Is the third-party discussion paper part of the toolkit, and is it on the same deadline?

It is a separate but related publication, issued the same day and open for comment until the same 1 December 2026 date. It is a discussion paper rather than a set of tools, and it explores six categories of third-party risk challenge anchored in PFMI Principle 17 and Annex F. Read it alongside the toolkit if third-party concentration or exit planning is a live concern.

What happens to the toolkit after the consultation closes?

CPMI-IOSCO will review the comments received and publish a final version of the toolkit. The tools may change in response to feedback, which is why the consultation window is the moment to raise anything that does not work for your type of FMI.

Key Takeaways

  • The CPMI-IOSCO cyber resilience toolkit was published on 8 September 2026 for public comment; responses go to cpmi@bis.org and cpmi-iosco@iosco.org by 1 December 2026.
  • CPMI-IOSCO designates the toolkit voluntary, non-binding and technology-neutral; it supplements the existing PFMI framework rather than establishing compliance or liability standards.
  • It applies to the five FMI types under the PFMI: payment systems, CSDs, securities settlement systems, CCPs and trade repositories.
  • The four tools cover governance and metrics, extreme but plausible scenarios, response and recovery planning, and testing and exercising; CPMI-IOSCO says the toolkit was informed by the 2022 Level 3 assessment’s issues and observations.
  • Use Tool 3’s response, resumption and recovery considerations and Tool 1’s maturity-model and metrics material to structure a management gap review.
  • The two-hour resumption objective is a design target that has to be balanced against safe resumption.
  • A companion discussion paper on third-party service providers, with six challenge categories, is open on the same 1 December 2026 timeline.
  • Adopting the toolkit does not satisfy DORA or other binding regional regimes; use it as a common international reference alongside them.

Sources and References

  • CPMI-IOSCO, Cyber resilience toolkit: practical considerations for FMIs (consultative report), September 2026: landing page and full PDF.
  • CPMI-IOSCO, Cover note for consultation on the cyber resilience toolkit, 8 September 2026: PDF.
  • BIS media release, Global standard-setting bodies publish a toolkit for cyber resilience at FMIs and a discussion paper on FMIs’ reliance on third-party service providers, 8 September 2026: press release.
  • CPMI-IOSCO, FMIs’ reliance on third-party service providers: challenges and risks (discussion paper), September 2026: landing page.
  • CPMI-IOSCO, Guidance on cyber resilience for financial market infrastructures, June 2016: d146.
  • CPMI-IOSCO, Principles for financial market infrastructures, April 2012: d101.
  • CPMI-IOSCO, Implementation monitoring of the PFMI: Level 3 assessment on financial market infrastructures’ cyber resilience, 2022: d212.
  • Regulation (EU) 2022/2554 (DORA), Article 2 (scope of application): EUR-Lex.

Your board’s December checkpoint

The toolkit rewards a specific piece of work over a straight read-through. Before 1 December, compare the four tools with your existing cyber resilience framework, map any identified gap to the relevant tool, and decide whether any mismatch with a binding regime you already follow is worth raising in a consultation response. That gives your board a gap list, a set of owners and a decision on whether to respond, using a voluntary toolkit that does not itself impose additional standards or serve as a legal or regulatory compliance assessment.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • ESRS Knowledge Hub: EFRAG’s 2026 Revised Standards, Mapped

    On 28 July 2026, EFRAG placed the 2026 revised European Sustainability Reporting Standards and the new voluntary standard inside the ESRS Knowledge Hub as an interactive document set. The revised standards were adopted by the European Commission as delegated acts on 3 July 2026, and the Hub is where preparers can now read the final…

  • Guarantees as CCP Collateral: What ESMA’s Draft RTS Changes

    On 23 February 2026 ESMA opened a consultation (paper reference ESMA91-1505572268-4513) on the draft regulatory technical standards that set the conditions for using guarantees as CCP collateral at an EU central counterparty. The consultation closed on 30 April 2026. The subject is narrow on paper and wide in practice: the draft RTS amends Commission Delegated…

  • ECB IT Risk Questionnaire: How the ITRQ Feeds Your SREP Score

    The ECB IT Risk Questionnaire (ITRQ) is where a significant institution puts a number on its own ICT risk before its Joint Supervisory Team does. Every bank under direct ECB supervision completes the workbook once a year, scoring its inherent ICT risk and the maturity of the controls that mitigate it. The 2026 questionnaire covers…

  • EBA Revised SREP Guidelines: What EU Banks Must Review in ICAAP, ILAAP and Pillar 2 Capital

    Updated July 2026In this guideWhat actually changed on 26 June 2026The new capital stack and where Pillar 2 sitsPillar 2 and the output floor: the change that matters mostWhat the revised SREP guidelines expect from your ICAAPILAAP and the merged liquidity assessmentP2G, stress testing and the every-second-year optionDORA, ESG and operational resilience folded into the…

  • Basel Committee ICT Risk Management: The Four Root Causes of Incidents

    On 2 June 2026 the Basel Committee on Banking Supervision published a range-of-practices report on information and communication technology (ICT) risk management. It draws on a survey of 16 jurisdictions and centres on how global and domestic systemically important banks handle the technology failures that take critical services offline. The Basel Committee ICT risk management…

  • Basel III Monitoring June 2025: Where the Capital Impact Sits

    On 24 March 2026 the Basel Committee on Banking Supervision published its Basel III monitoring exercise as of 30 June 2025, and the single number a capital planning team should read first is 1.7%. That is how much the fully phased-in final Basel III framework would add to the Tier 1 minimum required capital of…