CY · run world-payments-2026-06-27 v13.3.0
content: ai_generated 97 sources retrieved model claude-opus-4-8 ·

Cyprus

CY schema world-payments-v1 trajectory: not recorded

Last updated · 14 modules · 53 sourced findings · 97 sources in the cumulative register

14Modulesbaseline.modules[]
53Findingsmodules[].findings[]
23Tier-1 sourcesrun_metadata.t1_source_count
Confidence mix (sums to 14 rendered modules; click to filter)

Jurisdiction brief

Lead Signal

Cyprus's crypto-asset regime reached a structural turning point on 1 July 2026, when the national grandfathering pathway that had let Cyprus-based crypto-asset service providers operate under legacy AML-only registration formally closed. The closure followed the Markets in Crypto-Assets Regulation Article 143(3) transition, after a 27 February 2026 application deadline; providers that did not secure full MiCA authorisation by that point now face a mandated wind-down rather than continued market access. This is assessed as the single most structurally significant Cyprus payments-adjacent development this cycle, retiring the last national-registration route for Cyprus crypto firms and materially raising the compliance bar for CY-domiciled CASPs.

14 of 14 modules
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Cyprus payment/e-money regulation runs under PSD2's national transposition (Law 31(I)/2018) and the EMI law, both supervised by the Central Bank of Cyprus (CBC); MiCA now sits alongside as the mandatory CASP/EMT framework, with dual CBC PI/EMI + CySEC CASP authorisation required from March 2026 for EMT-related payment services, and PSD3/PSR is on the horizon to merge the PI/EMI regimes.

Movement — NEWDual CBC PI/EMI + CySEC CASP licensing convergence established for EMT services from March 2026First-time baseline capture of this licensing-convergence development.
Standing sub-brief256 words · last cycle wpm-2026-08-05

Licensing, Authorisation & Market Access

Cyprus operates an EU-harmonised dual PI/EMI authorisation regime supervised by the Central Bank of Cyprus. Payment institutions are authorised under Law 31(I)/2018 (transposing PSD2) and electronic money institutions under Laws 81(I)/2012 & 2018 (transposing EMD2). Authorisation is granted only to legal persons incorporated and headquartered in Cyprus, with at least part of the payment-service business carried out there; account information service providers register under section 34. This is a non-bank PI/EMI authorisation track, distinct from the bank-PSP route, and the incorporation and head-office requirement directly constrains shell-only structures.

Periodic update · new data 2026-08-11 · run wpm-2026-08-05

Licensing, Authorisation & Market Access

Cyprus's payment-institution and electronic-money-institution licensing framework is governed by Law 31(I)/2018, the national transposition of the second Payment Services Directive, with the Central Bank of Cyprus as the competent authority for authorisation and supervision. This baseline governing structure is unchanged this cycle, but the practical licensing landscape around it has shifted materially. From March 2026, Cyprus crypto-asset service providers that offer payment services related to electronic money tokens must hold Central Bank of Cyprus payment-institution or electronic-money-institution authorisation, or partner with an already-authorised payment service provider, in addition to the CySEC CASP authorisation those firms already carry. This dual-licensing convergence, layering a payments-regulatory requirement onto an existing crypto-authorisation track, is assessed as the most commercially significant Cyprus licensing development across 2025 and 2026, because it collapses what were previously two largely separate authorisation tracks — crypto-asset supervision under CySEC and payment-institution supervision under the Central Bank of Cyprus — into a single compliance obligation for a specific, commercially active category of firm.

Looking further out, the EU's proposed Payment Services Directive 3 and accompanying Payment Services Regulation are expected to merge the existing electronic-money-institution and payment-institution licensing categories into a single, unified Payment Institution framework, with the second Electronic Money Directive repealed entirely. Entry into force is expected in late 2027, with a twenty-four-month grandfathering period anticipated for firms already licensed under the current dual-category structure. For Cyprus payment and e-money institutions, this means the current CBC authorisation landscape, and the new EMT-related dual-licensing requirement layered onto it this cycle, should both be understood as transitional rather than final: firms licensed today will need to plan for a further consolidation once PSD3 takes effect, on top of adapting to the March 2026 EMT-related convergence requirement in the near term.

Both developments concern non-bank payment institutions and electronic-money institutions specifically — the CBC-authorised entity class distinct from Cyprus's licensed banks, which access payment services through a separate prudential authorisation channel — and both tighten, rather than loosen, the market-access bar for that non-bank category over the near-to-medium term. The licensing convergence also has direct bank-versus-nonbank significance for market structure: because the requirement specifically targets non-bank crypto-asset service providers seeking to offer EMT-related payment services, it does not alter the position of Cyprus-licensed banks, which already operate under full banking-licence prudential supervision and would not need a separate PI/EMI authorisation to offer equivalent services. The practical effect is to narrow the competitive gap between bank-affiliated and non-bank payment-services providers specifically in the EMT-related payments space, by requiring non-bank CASPs to meet a payments-specific authorisation bar that banks already satisfy through their existing licence.

For market entrants evaluating Cyprus as a base for EMT-related payment services, the practical entry pathway is now twofold rather than singular: securing CySEC CASP authorisation alone is no longer sufficient if the underlying activity involves EMT-related payment services, and the additional PI/EMI authorisation, or a qualifying PSP partnership, must be secured before commercial launch. This raises both the compliance cost and the licensing timeline for prospective entrants relative to the pre-March-2026 baseline. The underlying CBC authorisation framework itself, Law 31(I)/2018, remains the baseline governing instrument for Cyprus PI/EMI authorisation and supervision, and no change to that baseline framework was identified this cycle; the developments described above sit on top of it rather than replacing it, layering a crypto-specific dual-authorisation requirement, and a forthcoming PSD3-driven unification, onto a stable existing statutory base.

Outlook

Watch for the first published PSD3/PSR legislative text, which would clarify the precise mechanics of the unified Payment Institution framework and the terms of its twenty-four-month grandfathering period for firms already licensed under Cyprus's current dual CBC/CySEC structure. Nearer term, watch for how many Cyprus CASPs providing EMT-related payment services have secured CBC PI/EMI authorisation, or a qualifying PSP partnership, ahead of and following the March 2026 convergence requirement, since this cycle's sourcing established the requirement's existence but not its population-level compliance status. Also worth tracking is whether the Central Bank of Cyprus issues any implementing guidance specific to the March 2026 EMT-related convergence requirement, since this cycle's sourcing captured the requirement itself but not any CBC-specific implementing detail beyond the CySEC CASP authorisation dimension.

Sources and findings (5)
  1. T1https://www.centralbank.cy/en/licensing-supervision/payment-institutions/licensing-and-supervision-of-payment-institutions
  2. T1https://www.centralbank.cy/en/licensing-supervision/electronic-money-institutions/licensing-and-supervision-of-electronic-money-institutions
  3. T3https://www.sovereigngroup.com/cyprus/corporate-services/payment-institutions-and-electronic-money-institutions/
  4. T3https://obtained.com/blog/emi-pi-application-cyprus-mica-casp
  5. T3https://thebanks.eu/emis/jcc-payment-systems-355373

#

Safeguarding of user funds (segregation or insurance/guarantee) is mandated under the EMI/PI laws, with CBC adopting EBA safeguarding guidance (EBA/GL/2018/05). In 2025-2026 the CBC issued new directives strengthening EMI/PSP governance, capital and suitability, and the Internal Organisation and Governance of EMIs Directive (incorporating by analogy the Internal Organisation and Governance of Payment Institutions Directive of 2026) moved governance to a structured, board-accountable obligation. Suitability of management body members is assessed under the 2025 Suitability Directive.

Movement — NEWDORA ICT risk management (Jan 2025) and Verification of Payee (Oct 2025) mandates now bind CY PSPs/EMIsFirst-time baseline capture.
Standing sub-brief227 words · last cycle wpm-2026-08-05

Conduct, Safeguarding & Promotions

Safeguarding of user funds — through segregation or insurance/guarantee cover — is mandated under the EMI/PI laws, with the CBC adopting EBA safeguarding guidance (EBA/GL/2018/05) and EBA authorisation guidance (EBA/GL/2017/09) for both application and ongoing supervision. The mechanism applies to non-bank PIs and EMIs, for which deposit protection does not apply; the segregation-versus-insurance choice directly affects operating-account structure and client-trust positioning. This is the bank-PSP versus non-bank PI/EMI distinction in operational form: customer-fund protection here is a prudential and conduct obligation, not a depositor-guarantee backstop.

Periodic update · new data 2026-08-11 · run wpm-2026-08-05

Conduct, Safeguarding & Financial Promotions

Two conduct-and-safeguarding obligations now bind Cyprus payment institutions and electronic-money institutions as a matter of settled requirement rather than pending reform. Since January 2025, every electronic-money-institution application submitted in Cyprus must include a full ICT risk-management framework under the Digital Operational Resilience Act, embedding operational-resilience requirements directly into the authorisation stage rather than leaving them to post-licensing supervision alone. Since October 2025, Cyprus payment service providers have also operated under a Verification of Payee mandate, requiring real-time matching of the payee's IBAN against the payee's name before a transfer completes, as an anti-fraud backstop applicable across the licensed payment-services population.

Both obligations are assessed as elevated-impact developments, and both apply across the bank and non-bank payment-services population differently: the DORA-linked ICT risk-management requirement is scoped specifically to electronic-money-institution applications, meaning it binds the non-bank e-money authorisation track directly, while the Verification of Payee mandate applies more broadly across both bank and non-bank payment service providers offering payee-facing transfer services, since anti-fraud payee verification is a transaction-level control rather than an entity-type-specific one.

Together, the two obligations represent a tightening of the conduct and operational-resilience bar for Cyprus payment institutions at both the pre-licensing and in-life stages: DORA-linked ICT risk management is assessed at the point of application, embedding resilience expectations before a firm is even authorised, while Verification of Payee is a continuous, transaction-level control that must operate correctly for the life of the licence. Neither obligation is Cyprus-specific in origin — both flow from EU-level instruments, DORA and the Instant Payments Regulation's payee-verification requirement respectively — but both now form part of the settled compliance baseline that any Cyprus payment institution or electronic-money institution must satisfy.

The Verification of Payee mandate in particular should be read alongside Cyprus's parallel instant-payments rail development this cycle: as SEPA Instant Credit Transfer volumes grow toward and past the roughly thirty-two-percent-by-volume share reported for Cyprus, the anti-fraud stakes of real-time payee verification rise correspondingly, since a growing share of Cyprus payment volume now moves through rails where a mismatched or fraudulent payee could complete a transfer within seconds rather than the settlement window associated with slower payment rails. For new market entrants, the practical implication of the DORA-linked requirement is that ICT risk-management documentation is now a gating item at the application stage rather than a post-authorisation deliverable, meaning prospective Cyprus electronic-money-institution applicants must have a complete ICT risk-management framework ready before submission, not merely a plan to develop one after authorisation is granted.

Both obligations also carry a documentation and audit-trail dimension: DORA-linked ICT risk-management frameworks and Verification of Payee controls must both be demonstrable to the Central Bank of Cyprus on supervisory request, meaning Cyprus payment institutions should expect both to form part of ordinary supervisory review going forward, rather than being one-off compliance exercises assessed only at authorisation or launch. It is also worth noting that neither obligation was identified as introducing a new financial-promotions or marketing-restriction rule specifically; the conduct tightening identified this cycle is safeguarding- and resilience-focused rather than promotions-focused, and no Cyprus-specific financial-promotions development was located within this module's scope this cycle. Cyprus payment institutions preparing for supervisory review under either obligation should treat the absence of a located enforcement precedent as a reason for caution rather than complacency: both obligations are recent enough, DORA-linked ICT risk management dating to January 2025 and Verification of Payee to October 2025, that a first enforcement or supervisory-finding precedent may simply not yet exist rather than compliance being confirmed adequate across the licensed population.

Outlook

Watch for the first enforcement or supervisory findings under either obligation, since this cycle's sourcing established the existence and effective dates of both requirements but did not surface any Cyprus-specific compliance-testing or enforcement outcome yet. Also worth tracking is whether the Central Bank of Cyprus issues Cyprus-specific implementing guidance on either the DORA-linked ICT risk-management expectations or the Verification of Payee mandate, beyond the EU-level instruments from which both obligations originate. Given both obligations are recent, the coming cycles are likely to be where supervisory testing first surfaces, making this an area to monitor closely rather than treat as settled.

Sources and findings (4)
  1. T3https://cxfinancia.com/what-is-a-payment-services-licence-in-cyprus/
  2. T3https://www.harneys.com/our-blogs/regulatory/the-central-bank-of-cyprus-introduces-new-directives-for-emis-and-psps/
  3. T3https://mnkriskconsulting.com/regulatory-developments/central-bank-of-cyprus-directive-on-the-internal-organisation-and-governance-of-electronic-money-institutions/
  4. T1https://www.centralbank.cy/en/licensing-supervision/electronic-money-institutions/licensing-and-supervision-of-electronic-money-institutions

#

MiCA (Reg (EU) 2023/1114): CBC is competent authority for EMTs (Title IV); CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V). EMT issuance restricted to credit institutions/EMIs. Transitional window to 1 July 2026.

Open gap — wpm-int-3MiCA existing-CASP application-lodgement deadline is ambiguous: research cites a 10 January 2025 compliance-evidence submission deadline while a 2026 source reports a 27 February 2026 application deadline (the 1 July 2026 hard enforcement date is robust). The distinct procedural milestones should be disambiguated.no under-indexing note recorded
Standing sub-brief246 words · last cycle wpm-2026-06-27

Stablecoins & Digital Money

Cyprus applies MiCA (Reg (EU) 2023/1114) with a defined competent-authority split. EMTs (Title IV) are economically assimilated to e-money and excluded from CySEC's mandate, leaving the CBC as the competent authority for EMTs; CySEC supervises ARTs (Title III), other crypto-assets (Title II) and CASPs (Title V), with significant ARTs and EMTs drawing additional EBA supervision. EMT issuance is restricted to credit institutions and EMIs. The practical consequence is structural: a MiCA CASP licence alone is insufficient to launch a stablecoin from Cyprus — an issuer must hold credit-institution or EMI status, a gating constraint that separates crypto-service activity from stablecoin issuance. This carries the bank-versus-non-bank distinction directly into the digital-money layer.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1https://www.cysec.gov.cy/en-GB/mica-regulation-overview/
  2. T3https://www.globallegalinsights.com/practice-areas/fintech-laws-and-regulations/cyprus/
  3. T3https://finance.yahoo.com/news/revolut-secures-mica-license-cyprus-160103192.html
  4. T2https://www.financemagnates.com/cryptocurrency/cysec-outlines-transitional-rules-for-crypto-asset-service-providers-under-mica/

#

Operational resilience is governed by DORA (Regulation (EU) 2022/2554), directly applicable from 17 January 2025, with CySEC and CBC as the supervising authorities for in-scope entities (banks, PIs, EMIs, investment firms, CASPs). DORA mandates ICT risk-management frameworks, incident classification/reporting, digital operational resilience testing (TLPT every three years for significant entities, with proportionality exemptions for smaller PIs/EMIs) and ICT third-party/outsourcing oversight. CySEC issued implementing guidance, including Circular C751 in early 2026.

Standing sub-brief153 words · last cycle wpm-2026-06-27

Operational Resilience & Critical Infra

DORA (Reg (EU) 2022/2554) is directly applicable from 17 January 2025, with CySEC and the CBC supervising in-scope entities including banks, PIs, EMIs, investment firms, CASPs and critical ICT third parties. Non-microenterprise entities must run a digital operational resilience testing programme, with advanced threat-led penetration testing every three years for those carrying significant ICT risk, and exemptions available for PSD2/EMD-exempt PIs and EMIs. CySEC issued Circular C751 in early 2026. The regime applies across both bank-PSP and non-bank PI/EMI populations, imposing a fixed resilience compliance baseline on all Cyprus payments entities while preserving TLPT proportionality relief for smaller PIs and EMIs.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T3https://www.kyprianou.com/digital-operational-resilience-act-dora-key-compliance-considerations-for-cyprus-financial-entities/
  2. T3https://www.harneys.com/our-blogs/regulatory/cysec-publishes-the-main-aspects-of-the-implementation-of-the-digital-operational-resilience-framework-dora/
  3. T3https://www.cyprus-insider.com/cysec-accelerates-dora-implementation-strengthening-cypruss-digital-operational-resilience/

#

Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751) implemented domestically by Cyprus Law N.77(I)/2018, with the CBC, the Commission for the Protection of Competition and the Consumer Protection Service as joint competent authorities. Caps are 0.2% (debit) and 0.3% (credit). Visa, Mastercard, Diners and China UnionPay schemes run through JCC, the domestic acquirer/processor. PCI DSS and 3-D Secure apply at the acquiring layer. SEPA SCT Inst rails operate under the EU Instant Payments Regulation with mandatory Verification of Payee.

Standing sub-brief201 words · last cycle wpm-2026-06-27

Scheme & Network Compliance

Card-scheme economics are governed by the EU Interchange Fee Regulation (EU 2015/751), implemented in Cyprus by Law N.77(I)/2018, with caps of 0.2% on debit and 0.3% on credit. The CBC, the Commission for the Protection of Competition and the Consumer Protection Service are joint competent authorities. Acquirers must individually specify merchant service charges by card category and brand unless blended charging is requested in writing — an unblending requirement that shapes MSC transparency for Cyprus merchants and fixes the acquiring-side cost floor.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1https://www.centralbank.cy/en/financial-market-infrastructures-payments/interchange-fee-regulation
  2. T1https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32015R0751
  3. T3https://www.lightspark.com/knowledge/cyprus-instant-payments
  4. T3https://www.ecommerce-payments.com/en/english-jcc-payment-system.html

#

As a euro-area member, Cyprus's principal corridors are euro-denominated SEPA flows (SCT, SCT Inst, SDD) settled in T2-CY, with non-euro cross-border flows reliant on correspondent networks. The Cyprus SEPA Direct Debit system (CY-SDD) has operated since 2014, settling in T2-CY; TIPS access provides pan-European instant reach across the 36-country SEPA zone. The CBC operates TARGET-CY and stands ready to support local credit institutions accessing TIPS.

Movement — NEWFull SCT Inst implementation 9 Oct 2025; usage ~32% by volumeFirst-time baseline capture.
Standing sub-brief122 words · last cycle wpm-2026-08-05

Payment Corridor Dynamics

As a euro-area member, Cyprus's principal corridors are euro-denominated SEPA flows — SCT, SCT Inst and SDD — settled in T2-CY, with CY-SDD having operated since 2014. TIPS access provides pan-European instant reach across the 36-country SEPA zone. Non-euro cross-border flows, by contrast, rely on correspondent networks. The structural corridor-risk axis for Cyprus operators is the contrast between euro-corridor strength via SEPA and TIPS and the dependence on correspondent banking for non-euro flows.

Periodic update · new data 2026-08-11 · run wpm-2026-08-05

Payment Corridor Dynamics

Cyprus implemented full SEPA Instant Credit Transfer sending capability on 9 October 2025, under the EU Instant Payments Regulation, completing the domestic instant-payments rail buildout for the Cyprus banking sector. This is a High-confidence finding, corroborated by the underlying EU Instant Payments Regulation text itself alongside Cyprus Mail's reporting on the domestic implementation date, and it carries a High impact rating for Cyprus payment-corridor dynamics specifically.

The usage data accompanying the implementation is itself a significant corridor-dynamics finding: instant-payments volume share in Cyprus has grown from under one percent to approximately thirty-two percent of SEPA credit transfers by volume, and approximately nine percent by value, a growth trajectory attributed to the Central Bank of Cyprus, and one that places Cyprus above the euro-area average for instant-payments adoption. The gap between the thirty-two-percent volume share and the nine-percent value share is itself informative about corridor composition: it suggests that instant rails in Cyprus are being used disproportionately for a high number of lower-value transfers relative to the overall SEPA credit-transfer population, rather than uniformly across transfer sizes, consistent with instant rails displacing everyday, lower-value payment activity ahead of higher-value transfers that may still favour other settlement channels.

This corridor development sits within the bank-led payments-infrastructure category specifically: the SCT Inst sending-capability implementation and the usage-growth finding both concern Cyprus's banking-sector payment-corridor infrastructure, as distinct from the non-bank payment-institution and electronic-money-institution licensing developments tracked elsewhere this cycle. The euro-area-average-beating adoption rate is a genuinely distinguishing finding for Cyprus specifically, rather than a generic EU-wide instant-payments development, and should be weighted accordingly as a jurisdiction-specific corridor-dynamics signal.

The full SCT Inst sending-capability milestone also has a direct connection to the Verification of Payee mandate tracked separately this cycle: as an increasing share of Cyprus payment volume shifts onto instant rails, the anti-fraud value of real-time payee verification rises correspondingly, since instant transfers settle within seconds and leave a correspondingly shorter window for post-transfer fraud remediation relative to slower payment rails. For Cyprus banks specifically, the completion of full SCT Inst sending capability represents the closing of what had been an open infrastructure item under the EU Instant Payments Regulation's phased implementation timeline; Cyprus's banking sector has now moved from partial to full sending-side compliance, a distinct and more advanced position than a bank that has implemented receiving capability alone without full sending-side rollout.

The thirty-two-percent volume share is also notable in comparative terms: because the reported figure explicitly surpasses the euro-area average, Cyprus's instant-payments adoption trajectory should be read as a genuine outperformance finding specifically, rather than simply tracking the broader EU-wide adoption curve that the Instant Payments Regulation's implementation timeline is driving across all member states uniformly. This corridor-dynamics finding has no identified read-through to correspondent-banking access or cross-border settlement arrangements specifically this cycle; the growth described here is a domestic SEPA-area instant-payments adoption finding, distinct from any correspondent-banking-access development. Taken together, the full sending-capability milestone and the above-average usage growth position Cyprus as a comparatively advanced SEPA market for instant-payments adoption specifically.

Outlook

Watch for continued volume and value share growth in coming cycles, and for whether the gap between Cyprus's volume-share and value-share growth trajectories narrows or persists, since a persistent gap would reinforce the reading that instant rails in Cyprus remain concentrated in lower-value transfer activity relative to the broader SEPA credit-transfer population. Also worth tracking is whether Cyprus's above-euro-area-average adoption rate continues to outpace the euro-area average as SCT Inst receiving-capability obligations and further Instant Payments Regulation milestones come into force across the wider SEPA area. Comparative benchmarking against other above-average euro-area adopters would also help contextualise whether Cyprus's specific growth trajectory is converging toward a plateau or continuing to accelerate.

Sources and findings (3)
  1. T1https://www.centralbank.cy/en/financial-market-infrastructures-payments/financial-market-infrastructures-instruments/retail-payment-systems
  2. T3https://www.lightspark.com/knowledge/cyprus-instant-payments
  3. T3https://www.transfi.com/blog/cyprus-payment-rails-how-they-work---sepa-jcc-mobile-wallets

#

The Cyprus payments market is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd — a bank-owned consortium (Bank of Cyprus holds a controlling/circa-75% interest; other shareholders include Hellenic Bank, Alpha Bank Cyprus, National Bank of Greece (Cyprus) and AstroBank) acting as the primary card processor. As of 2026 the CBC supervises around 26 EMIs and 11 PIs. Card payments accounted for ~74.5% of cashless transactions in H1 2025, above the euro-area average, and fintechs are emerging as a competitive challenge to incumbent banks.

Open gap — wpm-int-1Supervised PI/EMI population count is contested: research cites 26 EMIs / 11 PIs (T3) while a challenger-identified May-2026 source citing an official CBC statement gives 29 EMIs / 10 PIs. The exact figure should be reconciled to the CBC official statement before publication.no under-indexing note recorded
Standing sub-brief241 words · last cycle wpm-2026-06-27

Industry Structure & Commercial

The Cyprus payments market is bank-led at the acquiring layer, dominated by JCC Payment Systems Ltd, a bank-owned consortium in which Bank of Cyprus holds a controlling interest alongside shareholders including Hellenic Bank, Alpha Bank Cyprus, National Bank of Greece (Cyprus) and AstroBank. JCC is the primary card processor and acquirer for Visa, Mastercard and Diners. The exact controlling percentage varies across sources — one cites approximately 75%, an older source cites a historic 45% pre-resolution — so the controlling-interest characterisation is held at High rather than Confirmed and the specific figure is reported, not asserted. This concentration of domestic card acquiring in a single bank-consortium entity defines the competitive structure and the entry challenge for cross-border acquirers.

No periodic updates recorded against this sub-brief.

Sources and findings (4)
  1. T1https://www.centralbank.cy/en/financial-market-infrastructures-payments/financial-market-infrastructures-instruments/retail-payment-systems
  2. T3https://cy.linkedin.com/company/jcc-payment-systems
  3. T3https://bankmycapital.com/cyprus-payment-agents-secure-banking-high-risk/
  4. T3https://cyprus-mail.com/2026/06/15/cyprus-turns-to-digital-payments-as-fintech-reshapes-banking

Enforcement in the payments-adjacent space is driven by CySEC (CIFs, CASPs, funds) and CBC (credit institutions, PIs, EMIs), plus the National Sanctions Implementation Unit (NSIU). In its 2025 review CySEC reported imposing €2.3 million in fines and ~600 inspections, with thematic inspections in retail FX/CFD and crypto-asset sectors producing administrative fines for sanctions-screening and prudential-reporting deficiencies. The Criminalisation of the Violation of Restrictive Measures Law (2025) empowers the NSIU to impose fines up to €5 million or 10% of annual turnover. CySEC lacks restitution powers; consumer redress runs through the Financial Ombudsman and the District Courts.

Open gap — wpm-int-2Sanctions-criminalisation penalty figures diverge: research cites up to EUR 5m or 10% of annual turnover (T3 Chambers) versus a challenger source citing up to 5% of global turnover or EUR 40m (whichever higher) plus individual imprisonment, with ~1 August 2025 entry into force implementing EU Dir 2024/1226. Penalty ceiling and entry-into-force date need reconciliation.no under-indexing note recorded
Standing sub-brief199 words · last cycle wpm-2026-06-27

Legal & Litigation

In its 2025 review CySEC reported imposing approximately EUR 2.3 million in fines and around 600 inspections across CIFs, asset managers, funds, issuers and market infrastructures, approving 47 new licences including 8 CASPs. Thematic inspections in retail FX/CFD and crypto produced administrative fines for sanctions-screening and prudential-reporting deficiencies. CySEC lacks restitution powers; redress runs via the Financial Ombudsman and District Courts.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T2https://cyprus-mail.com/2026/01/21/cysec-imposes-e2-3-million-in-fines-tightens-aml-and-sanctions-enforcement
  2. T3https://practiceguides.chambers.com/practice-guides/fintech-2026/cyprus/trends-and-developments
  3. T1https://www.cysec.gov.cy/en-GB/investor-protection/how-to-complain/

#

Domestic merchant acquiring is dominated by JCC Payment Systems, the primary card processor and acquirer for Visa, Mastercard, Diners and China UnionPay, providing the JCC Gateway (online card capture and 3-D Secure), JCCsmart (public-sector/biller acceptance), POS terminals, fraud controls, tokenisation, rolling reserves and chargeback handling. Cross-border PSPs (Adyen, Stripe, Mollie, Worldline) compete for EU-footprint merchants. High-risk merchant onboarding is constrained by bank AML/KYC policies, with specialist high-risk providers and PayFac models filling the gap.

Standing sub-brief141 words · last cycle wpm-2026-06-27

Merchant Acquiring & Risk

Domestic merchant acquiring is dominated by JCC, the primary acquirer for Visa, Mastercard, Diners and China UnionPay, providing JCC Gateway with online capture and 3-D Secure, JCCsmart, POS terminals, tokenisation, rolling reserves and chargeback handling, with 47-currency processing and PCI DSS / 3-D Secure compliance. High-risk merchant categories — online casinos, pharma, dating — are typically refused by the domestic bank-PSP acquirer; cross-border PSPs including Adyen, Stripe, Mollie and Worldline compete for EU-footprint merchants. The refusal of high-risk MCCs by the domestic acquirer creates a structural gap filled by specialist and PayFac providers — a recurring, under-indexed merchant-acquiring dynamic.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T3https://www.transfi.com/blog/cyprus-payment-rails-how-they-work---sepa-jcc-mobile-wallets
  2. T3https://payatlas.com/countries/cyprus-cy
  3. T3https://www.ecommerce-payments.com/en/english-jcc-payment-system.html

#

Cyprus's legacy AML-only national CASP registration regime has been fully retired: the MiCA grandfathering window (Article 143(3)) closed on 1 July 2026, after a 27 February 2026 application deadline, moving all CASPs onto full EU MiCA authorisation or a mandated wind-down.

Movement — NEWMiCA CASP grandfathering expired 1 July 2026First-time baseline capture of a structurally material lifecycle event.
Standing sub-brief151 words · last cycle wpm-2026-08-05

Product Innovation & Market Development

Cyprus runs dual innovation infrastructure: the CBC Innovation Hub covering payments and banking fintech and the EMT/stablecoin boundary, and the CySEC Innovation Hub operating since 2018 alongside a full CySEC Regulatory Sandbox launched in 2024 for supervised live testing, typically up to six months. Open-banking cash-flow analysis operates under PSD2; SCT Inst, request-to-pay and mobile wallets (Apple Pay, Google Wallet) are live. The CBC targets readiness for a possible first digital-euro issuance in 2029, subject to EU legislation in 2026. Sandbox and innovation-hub access, together with digital-euro readiness, signal regulatory openness and act as a market-development draw for fintech domiciliation across both bank and non-bank operators.

Periodic update · new data 2026-08-11 · run wpm-2026-08-05

Product Innovation & Market Development

The formal close of the Markets in Crypto-Assets Regulation's national grandfathering window for Cyprus crypto-asset service providers, on 1 July 2026 following a 27 February 2026 application deadline, is this cycle's defining product-innovation-and-market-development finding for Cyprus. This is a High-confidence, Critical-impact finding, anchored by a Tier 1 CySEC press release and corroborated across the source base on both the application-deadline and expiry dates. Unauthorised crypto-asset service providers are required to wind down their Cyprus operations; the prior national AML-only registration pathway, which had functioned as an alternative, lighter-touch route to market for crypto-asset activity, is retired in favour of full MiCA authorisation as the only lawful route to market from this point forward.

From a product-innovation and market-development standpoint specifically, this transition changes the competitive landscape for crypto-asset product development in Cyprus materially: firms building new crypto-asset products or services in or from Cyprus must now design for full MiCA compliance from the outset, rather than being able to rely on a lighter national registration during an initial go-to-market phase. This raises the compliance-design bar for new product launches and should be factored into any market-entry or product-development timeline for Cyprus-based crypto-asset innovation going forward. The transition also connects directly to the dual CBC/CySEC licensing convergence tracked separately this cycle for electronic-money-token-related payment services, since both developments push Cyprus crypto-asset firms toward a more integrated, cross-regulator compliance posture spanning CySEC's CASP authorisation and the Central Bank of Cyprus's payment-institution authorisation regime simultaneously.

The transition also has direct relevance for how Cyprus is positioned relative to other EU member states in the broader MiCA rollout: because the national grandfathering window operated on a standard, EU-wide transitional mechanism under Article 143(3) of the MiCA Regulation, Cyprus's 1 July 2026 expiry date reflects the general MiCA transition timeline rather than a Cyprus-specific acceleration or extension, meaning Cyprus's product-development environment is now converging with the same MiCA baseline applying across the wider European Union crypto-asset market. For product teams evaluating new crypto-asset offerings from a Cyprus base, the practical entry calculus has shifted meaningfully within this single cycle: the comparative advantage that a lighter national AML-only registration might previously have offered relative to full MiCA authorisation elsewhere in the EU no longer exists for Cyprus specifically, since that registration route has now been formally retired.

This should also be read alongside the broader Cyprus licensing-convergence story tracked this cycle: a crypto-asset product now routed through Cyprus for electronic-money-token-related payment functionality may require both full MiCA CASP authorisation and a Central Bank of Cyprus payment-institution or electronic-money-institution authorisation, or a qualifying payment-service-provider partnership, layering two separate compliance regimes onto a single product design rather than one. No merchant-acquiring, high-risk-MCC, or correspondent-banking-access development connects directly to this finding within the scope of this module this cycle; the transition described here is confined to the crypto-asset authorisation and product-development dimension specifically.

Outlook

The practical question for next cycle is the population-level compliance outcome of the transition: how many previously AML-only-registered Cyprus crypto-asset firms have secured full MiCA authorisation, wound down their Cyprus operations, or remain in an unresolved intermediate state past the formal 1 July 2026 deadline. Watch also for the first Cyprus-specific crypto-asset product launches conducted entirely under full MiCA authorisation, which would mark the point at which Cyprus's crypto-asset product-development environment has fully transitioned to the new regulatory baseline. A further open question is whether CySEC issued any Cyprus-specific transitional guidance to firms mid-conversion during the run-up to the 1 July 2026 deadline, which this cycle's sourcing did not surface directly. Overall, this cycle's finding should be treated as the single strongest-sourced Cyprus product-and-market development identified across this module, and subsequent cycles should prioritise closing the population-level compliance gap in the evidence base rather than revisiting the underlying regulatory milestone itself, which is now well established.

Sources and findings (4)
  1. T3https://www.globallegalinsights.com/practice-areas/fintech-laws-and-regulations/cyprus/
  2. T3https://practiceguides.chambers.com/practice-guides/fintech-2026/cyprus/trends-and-developments
  3. T3https://cyprus-mail.com/2026/06/15/cyprus-turns-to-digital-payments-as-fintech-reshapes-banking
  4. T3https://www.transfi.com/blog/cyprus-payment-rails-how-they-work---sepa-jcc-mobile-wallets

#

Consumer protection rests on PSD2-derived conduct rules, transparency/disclosure obligations, and EBA consumer-protection guidance adopted by the CBC. The Office of the Cyprus Financial Commissioner (Financial Ombudsman), established under Law 84(I)/2010, handles consumer complaints against banks, PIs/EMIs and other financial institutions up to €250,000 (€20 fee; decisions binding only if accepted by both parties). For instant-payment fraud, the EU Instant Payments Regulation's mandatory Verification of Payee (payee name/IBAN matching) is the principal APP/misdirection-fraud control; Cyprus does not have a UK-style mandatory APP-fraud reimbursement scheme.

Standing sub-brief141 words · last cycle wpm-2026-06-27

Consumer Protection & APP Fraud

Consumer protection rests on PSD2-derived conduct rules and EBA consumer-protection guidance adopted by the CBC. The Financial Ombudsman, under Law 84(I)/2010, handles complaints against banks, PIs/EMIs and other financial institutions up to EUR 250,000, with a EUR 20 fee and decisions binding only if accepted by both parties. For instant-payment fraud, the EU Instant Payments Regulation's mandatory Verification of Payee is the principal APP and misdirection control. Critically, Cyprus has no UK-style mandatory APP-fraud reimbursement scheme — a material differentiator in consumer-protection liability exposure for PSPs relative to the UK PSR model.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T1https://financialombudsman.org.cy/en/services/complaints-service/
  2. T1https://financialombudsman.org.cy/en/complaints-submission-and-mediation-requests/submission-of-a-complaint-by-legal-entities/
  3. T3https://www.lightspark.com/knowledge/cyprus-instant-payments

#

[Sentinel-fed] Cyprus AML/CFT for the payments context is governed by the AML/CFT Law of 2007 and Sanctions Law of 2016, with sector supervisors CBC (credit institutions, PIs, EMIs), CySEC (CIFs, CASPs, funds), ICPAC and the Cyprus Bar Association; MOKAS is the FIU. CASPs are obliged entities registered with CySEC and subject to Travel Rule (Reg (EU) 2023/1113) obligations and CDD from €1,000. Sentinel.gi position carried; no original WPM illicit-finance analysis performed.

Open gap — wpm-int-5W11 AML/CFT surface is entirely Sentinel-fed on T3 carriers (amlwatcher, centre8education); no primary MOKAS/CBC/CySEC AML-circular anchors were retrieved, so the AML standing position rests at Assessed pending Sentinel/FIM primary-source confirmation.no under-indexing note recorded
Standing sub-brief185 words · last cycle wpm-2026-06-27

AML/CFT & Financial Crime

This surface is sourced from the Sentinel feed (sentinel://cy/aml-cft/framework); the World Payments Monitor carries the framework as provenance and does not conduct original illicit-finance analysis. Per the Sentinel feed, Cyprus AML/CFT for payments is governed by the AML/CFT Law of 2007 and the Sanctions Law of 2016, with sector supervisors CBC (credit institutions, PIs, EMIs), CySEC (CIFs, CASPs, funds), ICPAC and the Cyprus Bar Association; MOKAS is the FIU. CASPs are obliged entities registered with CySEC, subject to the EBA Travel Rule (Reg (EU) 2023/1113) and CDD for occasional transactions of EUR 1,000 and above. Firm-wide sanctions risk assessment is treated as a non-negotiable compliance element. The bank-versus-CASP supervisory split and Travel Rule CDD thresholds frame the AML compliance perimeter for Cyprus payments and crypto operators.

No periodic updates recorded against this sub-brief.

Sources and findings (7)
  1. T3sentinel://cy/aml-cft/sanctions-supervision — centre8education.com/articles/aml-sanction-risk-assesment-cyprus
  2. T?FIM (sentinel.gi) per-JID baseline profile — Cyprus — Cyprus applies the EU AML/CFT acquis via its AML/CFT Law, with MOKAS as FIU, CySEC as securities/CASP supervisor, and CBC as banking supervisor. Assessed by MONEYVAL under FATF standards, Cyprus remains in enhanced follow-up since its 2019 MER, rated partially compliant on non-profit organisations, correspondent banking, new technologies (crypto), and law-enforcement investigative powers. A national sanctions unit (NSIU/MEK), replacing a 2016 sanctions law, was legislated in 2025 after EU-deadline delays.
  3. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-001) — Gap: sourcing-thinness
  4. T1FIM (sentinel.gi) enforcement_action_register (issue FIM-BASE-ENF-003) — Enforcement: MONEYVAL/FATF — Cyprus national AML/CFT framework
  5. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-003) — Gap: enforcement-absence
  6. T2FIM (sentinel.gi) enforcement_action_register (issue FIM-BASE-ENF-004) — Enforcement: Nicosia Criminal Court — Demetris Syllouris (former Parliament President) and Christakis Giovanis (former MP)
  7. T?FIM (sentinel.gi) gaps_register_cumulative (issue FIM-BASE-GAP-004) — Gap: regulatory-failure

#

Settlement via T2-CY (replaced TARGET2 20 Mar 2023); Settlement Finality Law; TIPS + CCBM connectivity; non-euro flows exposed to de-risking.

Standing sub-brief178 words · last cycle wpm-2026-06-27

Correspondent Banking, Settlement & Access

The analytical spine of this module is the bank-versus-non-bank settlement-access asymmetry. Settlement runs through T2-CY, the Cyprus component of the Eurosystem T2 RTGS, which replaced TARGET2 on 20 March 2023; participants are Cyprus credit institutions, the Cyprus Stock Exchange, CY-SDD, the Cyprus Clearing House, JCC Cards and the CBC. Settlement finality is provided by the Settlement Finality Law, and Cyprus is connected to TIPS and the CCBM for collateral mobilisation. Direct euro settlement finality is therefore a bank-PSP privilege.

No periodic updates recorded against this sub-brief.

Sources and findings (3)
  1. T1https://www.centralbank.cy/en/financial-market-infrastructures-payments/financial-market-infrastructures-instruments/target-services
  2. T1https://www.ecb.europa.eu/pub/pdf/other/ccbm201405en.pdf
  3. T1https://www.ecb.europa.eu/pub/pdf/eurosystemoversight/eurosystemoversightreport2020~a1e4fce1d7.en.pdf

#

Trailing-12-month commercial activity is shaped by MiCA-driven crypto re-domiciliation into Cyprus and bank consolidation. Revolut secured a CySEC MiCA CASP licence (October 2025), making Cyprus its EEA crypto hub. Bank of Cyprus (CET1 ~21%) signalled openness to smaller, strategically targeted fintech/insurance acquisitions under its 2026-2028 plan. 2025 saw a significant rise in tech/fintech/financial-services M&A. Earlier CASP registrations included Revolut and eToro; Binance exited the market.

Movement — NEW808 CySEC-supervised entities, EUR 11.4bn AUM, licensing automation projectFirst-time baseline capture.
Open gap — wpm-int-4No discrete funding/investment-round (W13 investment-type) evidence surfaced for Cyprus payments/fintech firms beyond M&A appetite and trend signals; private-company financing signals are under-indexed in this baseline.Private-company and emerging-fintech financing signals (per bias-correction §11) are thin; baseline over-indexes deal-announcement/launch-hype (Revolut, Bank of Cyprus) over granular funding-round data.
Horizon · 2026-01 (±quarter)Cyprus crypto-asset disposal-gains tax (8% flat) takes effectin_force · T3
Standing sub-brief242 words · last cycle wpm-2026-08-05

Commercial Intelligence (M&A, Investment & Product)

Three discrete commercial events anchor this module. First, a completed product release: Revolut formally received a MiCA CASP licence from CySEC in October 2025, allowing regulated crypto services across all 30 EEA countries and making its Cyprus base the centre of its EEA crypto operations — a flagship fintech selecting Cyprus as its EEA MiCA crypto hub and a material market-access signal validating the jurisdiction's CASP regime. The deal value is not publicly disclosed.

Periodic update · new data 2026-08-11 · run wpm-2026-08-05

Commercial Intelligence & Fintech

CySEC approved 47 new Cyprus Investment Firm licences during 2025, bringing the total population of CySEC-supervised entities to 808, with assets under management held in collective investment schemes reaching EUR 11.4 billion. This is an assessed-confidence, dashboard-tier finding reflecting continued growth in Cyprus's CySEC-supervised commercial population rather than a discrete, named commercial event such as an M&A transaction or funding round; no specific deal, investment round, or product-launch event meeting this module's commercial-events threshold was identified for Cyprus this cycle.

Outlook

Watch for named commercial events specifically — mergers, acquisitions, investment rounds, or product launches — involving Cyprus-domiciled payment, e-money, or investment-firm entities in coming cycles, since this cycle's finding was limited to aggregate supervised-population growth rather than a discrete transaction-level development.

Sources and findings (3)
  1. T3https://www.cryptopolitan.com/revolut-eu-mica-license-in-cyprus/
  2. T3https://cyprus-mail.com/2026/03/05/bank-of-cyprus-targets-fintech-and-insurance-for-strategic-deals
  3. T3https://practiceguides.chambers.com/practice-guides/corporate-ma-2026/cyprus/trends-and-developments
No modules match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Cyprus
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: module cards load OPEN; standing positions render in full; sub-briefs and jurisdiction briefs load as a clamped teaser with an explicit “read full” control carrying the true word count; earlier updates stay collapsed behind a counted summary. No text is hidden without disclosing how much of it there is.

Sentinel-fed modules receive no special rendering treatment. sentinel_feed is an attribution chip only: it does not suppress content, does not generate an absence reason code, and does not exclude the module from any count, filter, search index or export on this page.

Family taxonomy is renderer-level presentation config, not a JID field. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; per-module RAG traffic light; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-11. A year-precision row is never promoted into a tighter band.

Orphan deltas: 2 cycle_delta row(s) target non-module objects and are listed in the rail rather than attached to a card.

Envelope: baseline resolved at jurisdiction_json.baseline; 14 module(s), 53 finding(s), 93 source(s) in the cumulative register.