ESMA_QA_2604
Topic
Product governance
08/07/2025
Subject Matter
Clarification as regards to Perpetual features
Question
We are writing to request clarification regarding the regulatory treatment of perpetual futures. Specifically, we would like to confirm whether, in cases where a Cyprus Investment Firm (CIF) offers listed futures contracts through a Multilateral Trading Facility (MTF) operating in Europe, the perpetual futures offered by the CIF would fall within the scope of Category 10 – Other Derivatives, as defined in the First Appendix, Part III of Law 87(I)/2017, as amended from time to time.

In addition, we would appreciate your confirmation on whether any leverage restrictions apply to perpetual futures, either under CySEC’s national rules or under EU-level requirements, particularly in the context of investor protection measures.
Level 1 Regulation
Directive 2014/65/EU - Markets in Financial Instruments Directive (MiFID II)
ESMA_QA_2496
Topic
ICT-related incident 
27/03/2025
Subject Matter
Incident report submission format
Question
What is the submission format for the incident reports (initial notification, intermediate and final) that CTPPs and Financial Entities need to submit to the CA?
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2459
Topic
Register of information
11/03/2025
Subject Matter
Fintech company: DORA AND ROI
Question
Hi Team,

Hope you are well!

We are a Spanish Fintech company called Toqio, our company lets you create, customize, and scale unique financial products in our platform.Please find more information below:

https://toqio.co/platform

Could you please confirm that we have to comply with DORA and also we have to send the ROI to the authorities?

Thank you in advance,

Kindest regards,

Ester
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2457
Topic
Other DORA topics
07/03/2025
Subject Matter
Clarification on DORA Audits for Non-European ICT Service Providers
Question
The DORA law states that ICT third-party service providers must fully cooperate during onsite inspections and audits conducted by competent authorities, the Lead Overseer, the financial entity, or an appointed third party.
Will these audits be conducted the same way if the provider is located outside Europe,
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
ESMA_QA_2456
Topic
ICT third-party risk management
07/03/2025
Subject Matter
Clarification on DORA Compliance for Intra-Group providers
Question
Can you confirm our understanding of the DORA law: an intra-group entity providing services to a financial entity is subject to the same obligations as a non-critical third-party provider. This includes requirements related to contractual arrangements, provisions for critical functions, exit strategies and termination conditions, information registry, reporting to competent authorities, and pre-contractual assessments. Additionally, if the services involve critical or important functions, further requirements apply, such as TLPT tests and audits by competent authorities.
Level 1 Regulation
Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)